This policy explains how Srileo and Elily process personal data when you use our website or message a business that uses Elily on WhatsApp.
1. Who we are
SRILEO TECHNOLOGIES (OPC) PRIVATE LIMITED (“Srileo”) operates Elily, an AI receptionist that answers WhatsApp messages on behalf of the businesses—clinics and other small and medium-sized businesses—that subscribe to it.
For messages you send to one of those businesses, that business is the data controller; Srileo processes the data on its behalf. For data you submit on srileo.com itself, Srileo is the controller.
2. What we collect via WhatsApp
When you message a business served by Elily, we process:
- your WhatsApp phone number and profile name;
- the text of your messages;
- details you provide in the conversation, including your name, chosen service, and appointment date and time;
- message delivery and read status; and
- your language preference.
Files, photos, voice notes and locations you send are not stored by Elily. They are forwarded to the business's staff via WhatsApp. Elily retains only a reference identifier, never the file content.
3. How we use your data
We use this data to reply to your messages, book, reschedule or cancel appointments, send appointment reminders and confirmations, and let the business's staff follow up.
No advertising, no profiling and no sale of personal data—ever.
4. Who processes it with us
- Meta Platforms (WhatsApp Business Platform) carries the messages. Meta's own privacy policy also applies to WhatsApp.
- OpenAI processes message text through its API to generate replies. Under OpenAI's API terms, this data is not used to train its models.
- Google (Google Calendar) receives appointment details—name, phone number, service and time—which are written into the business's own calendar.
- Ezerhost hosts our servers in India, where conversation and booking records are stored in an access-controlled database, isolated per business, with credentials encrypted at rest.
4A. Google user data
When a business connects its Google Calendar to Elily, we access Google Calendar data through the Google Calendar API. This includes the list of calendars on the account and the events needed to check availability and to create, update or cancel appointment bookings.
We use this data solely to provide appointment booking for that business. We do not use it for advertising, and we do not sell it.
Elily's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs adheres to these Limited Use restrictions: such data is not used to create, train, or improve any machine learning or artificial intelligence models.
Google user data is available to the business whose calendar it is within its Elily service and to Ezerhost, our infrastructure provider in India, which stores data on our behalf. OpenAI processes booking-conversation data through its API to generate replies; when needed for a booking, this may include calendar availability information. Under OpenAI's API terms, API data is not used to train its models. We may also disclose Google user data to authorities where required by law. We do not disclose Google user data to any other third party.
4B. How we protect Google user data
Google user data is encrypted in transit using TLS. Google OAuth tokens are encrypted at rest using AES-256-GCM. Conversation and booking records are stored in an access-controlled database that is isolated per business, and access is restricted to people and providers who need it to operate or support Elily.
We retain Google user data only while it is needed to provide the calendar connection or meet legal obligations. A business may ask us to disconnect its calendar and delete the Google user data we retain, or may request deletion when it closes its account, by emailing contact@srileo.com. We process deletion requests within 30 days and confirm when deletion is complete.
4C. Website visitors
This website sets no analytics cookies. We use Vercel Web Analytics to understand anonymous, aggregated website usage; we do not use session recordings or cross-site tracking, and we do not build profiles of visitors.
Vercel Web Analytics records page views and limited technical context such as the page path, referring website, approximate location, device type, operating system and browser. Vercel Speed Insights also records anonymous page-performance measurements, including Core Web Vitals and loading responsiveness. These services do not associate analytics events with a name, email address or stored IP address. The daily Analytics visitor identifier is derived from the request and discarded after 24 hours.
If you arrive through a Google ad, srileo.com temporarily stores Google's opaque click identifier and the campaign labels from the landing-page URL in session storage. When you follow a link to app.srileo.com, the portal stores the same limited attribution in a secure, HTTP-only first-party cookie for up to 90 days and associates it with the Elily tenant created during signup. These records contain no name, email address, phone number, payment instrument, WhatsApp message or appointment detail.
After the first successful paid subscription charge, our server sends Google only the click identifier, conversion time, subscription value and currency, and a unique invoice-derived transaction identifier. We use this information solely to measure whether an ad resulted in a paying customer and to optimise our own Google Ads campaign. Renewals are not reported as new-customer conversions.
Your light or dark theme preference is also stored on your device when you choose it. You may remove locally stored attribution by clearing site data for srileo.com and app.srileo.com. Server-side attribution is retained only as long as needed for conversion measurement, troubleshooting and compliance.
No third-party advertising script, font, embed or content delivery network is loaded. Google Ads attribution is handled first-party by srileo.com, app.srileo.com and our server; the analytics script is delivered from srileo.com through Vercel's hosting infrastructure.
Vercel, our hosting and analytics provider, also processes standard request data—including IP address, browser user agent and the page requested—to deliver the site, produce aggregate statistics and protect it from abuse. Vercel's privacy and compliance terms apply to that processing.
Questions about any of this can go to contact@srileo.com.
5. Retention
We keep different records for the following periods:
- conversation logs and appointment records are kept for as long as the business subscribes, as its business record;
- technical debugging traces and message-ingress logs are deleted automatically after 30 days;
- delivery-queue records are deleted after 7 days; and
- conversation session state is deleted after about 3 days.
6. Your rights and data deletion
You can have your personal data erased at any time in either of these ways:
- In WhatsApp: send the message delete me to the business's WhatsApp number. Elily immediately and automatically erases your stored personal data for that business—chat identity, conversation records and customer records—and sends you a confirmation. The deletion is audit-logged.
- By email: write to contact@srileo.com with the phone number you used. We will delete your personal data within 30 days and confirm when this is complete.
You can also request a copy of your data at contact@srileo.com.
To stop proactive messages such as reminders without deleting your data, reply STOP. Reply START to resume.
7. Grievance and contact
SRILEO TECHNOLOGIES (OPC) PRIVATE LIMITED
contact@srileo.com
8. Changes to this policy
We may update this policy as our service, providers or legal obligations change. We will post changes here and update the effective date shown above.
9. Google user data (Google Calendar)
When a business connects Google Calendar, we access the list of its calendars, the free/busy times on the calendar it selects, and the ability to create, update and delete the booking events our service makes.
We use this data solely to show available slots and manage that business's appointments.
Google user data is never sold, never used for advertising, and never used to create, train or improve AI or machine-learning models. It is disclosed only to the subprocessors required to operate the service: Ezerhost in India for hosting, and OpenAI, L.L.C. in the United States only insofar as conversation text being processed may reference appointment details. No other third party receives it.
Disconnecting Google Calendar in the dashboard or revoking access at myaccount.google.com immediately ends our access. Stored tokens are deleted when the calendar is disconnected or the account is deleted.
10. How we protect sensitive data
All data in transit is encrypted with TLS. Google OAuth tokens and other credentials are encrypted at rest using AES-256-GCM, with access to decryption keys restricted to production systems.
Each business's data is isolated per tenant, enforced at the database layer. Access follows the principle of least privilege: staff access to production data is restricted and permitted only to operate the service.
Data is deleted when an account is closed or on request, as described in Your rights and data deletion.
11. Limited Use disclosure
Srileo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements, and such data is not used to create, train or improve foundational or generalized AI/ML models.