1. Controller and contact
Locli is responsible for the personal data described in this notice.
Stockholm, Sweden [email protected]Contact us at this address for privacy questions or to exercise a data protection right.
2. Personal data we collect
We collect only the information needed to provide, secure, and improve Locli. Depending on how you use the service, this can include:
- Account and identity data: name, email address, authentication records, and a verified Google profile identifier, name, email, or profile image when you choose Google sign-in. Locli does not store Google access or refresh tokens.
- Waitlist and invitation data: email address and any optional name, business name, location, language, invitation status, or onboarding details you submit.
- Approximate location data: city and country inferred from network headers supplied by our hosting or content-delivery infrastructure, where available, to prefill onboarding. You can review and change the location before submitting it.
- Business and website data: business name, location, contact details, source website, services, opening hours, content instructions, generated drafts, published content, and edit history.
- Public business information: information from official websites and other publicly accessible business sources used to understand the business and prepare a draft.
- Voice and support data: recordings you deliberately submit, their transcripts, typed requests, clarification messages, and resulting edit proposals. Successful transcription deletes the raw recording immediately; failed or abandoned recordings are scheduled for deletion after a configurable window that defaults to 24 hours.
- Provider-usage data: the external service, operation, model, status, timing, bounded error details, usage counts, and estimated cost associated with an account, business, or project where applicable. These operational records do not contain raw prompts, provider responses, transcripts, or recordings.
- Technical and security data: IP address, browser and device information, timestamps, session identifiers, request logs, error details, and operational usage records.
Required account, authentication, and business fields are identified when collected. If you do not provide them, Locli may be unable to create an account, generate a website, or complete the requested action. Optional fields can be left blank.
3. How and why we use personal data
Provide the service and take requested steps
To create and secure accounts, maintain waitlist and invitation flows, understand a business, generate and edit website drafts, publish approved content, and provide support. The legal basis is performance of a contract or steps you request before entering one.
Operate a reliable and secure product
To prevent abuse, troubleshoot failures, monitor availability, preserve draft history, and improve product quality. The legal basis is our legitimate interest in providing a safe, dependable service, balanced against your rights.
Meet legal obligations
To maintain records, respond to lawful requests, establish or defend legal claims, and comply with applicable law. The legal basis is a legal obligation or our legitimate interest in protecting legal rights.
Use optional features you choose
Where the law requires consent, we ask before the processing begins. You can withdraw consent at any time, without affecting processing that was lawful before withdrawal.
Locli uses AI systems to help understand business information and prepare text, images, transcripts, and edit proposals. These systems support the service; they are not used to make decisions about you that produce legal or similarly significant effects.
4. Who receives personal data
We do not sell personal data or use it for third-party advertising. We share limited data with service providers when needed to operate Locli, including:
- hosting, database, storage, content delivery, and security providers;
- email delivery and authentication providers, including Google when you choose Google sign-in;
- AI, image-generation, and transcription providers used for the action you request;
- business discovery and website retrieval providers used to locate public business information;
- professional advisers, authorities, or counterparties when required by law or necessary to protect legal rights.
Providers may process data only for the contracted service and under appropriate data-protection obligations. Publicly published website content is available to anyone who visits that website.
5. International transfers
Some providers may process personal data outside the EU or EEA. Where required, we rely on a European Commission adequacy decision, approved Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. Contact us to ask about the safeguards relevant to your data.
6. How long we keep data
We retain personal data only for as long as needed for the purpose for which it was collected, including:
- account, project, generated website, and edit data while the account or project remains active, followed by a limited period needed for deletion, backups, security, or legal obligations;
- waitlist data until access is granted, the request is withdrawn, or it is no longer reasonably needed to administer early access;
- raw voice recordings only until successful transcription, or for the configured short failure and abandonment window;
- technical, security, and provider-usage records for a bounded operational period based on troubleshooting, abuse prevention, accounting, and legal needs.
When data is no longer needed, it is deleted or anonymised. Backup copies may remain until they rotate out under normal backup schedules.
8. Your data protection rights
Subject to applicable law, you may ask us to:
- provide access to and a copy of your personal data;
- correct inaccurate or incomplete data;
- delete data or restrict how it is used;
- provide data you supplied in a portable format;
- stop processing based on consent, or object to processing based on legitimate interests.
Some rights have legal exceptions. We may need to verify your identity before acting on a request. You may also lodge a complaint with the data protection authority where you live or work. In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY). The European Data Protection Board maintains a list of EU and EEA supervisory authorities.
9. Security, children, and policy updates
We use organisational and technical safeguards designed to protect personal data. No online service can guarantee absolute security, so please use a strong password and contact us if you suspect unauthorised account access.
Locli is a business service and is not directed to children. You must be legally able to use the service on your own behalf or for the business you represent.
We may update this notice when the service or applicable law changes. The effective date at the top identifies the current version. Material changes will be communicated through an appropriate channel.
Questions or requests can be sent to [email protected].