Legal

Privacy Policy

Agyl AI, Inc. d.b.a. EKOM AI  ·  Last updated: June 2026

Agyl AI, Inc. d.b.a. Ekom AI and its affiliates ("Ekom," "We," "Us," "Our") respect Your ("You" or "Your") privacy rights. We collect, process, use, and disclose Personal Data in a manner consistent with applicable law and uphold the highest ethical standards in Our business practices.

If You need this Policy in an alternative format, please contact privacy@ekom.ai.

Capitalized terms not defined in this Policy have the meaning given in the Terms of Service.

Section 1
Scope and Applicability

This Policy applies to https://www.ekom.ai (the "Site") and all Services owned and operated by Ekom, including Ekom's platform offerings (the "Services").

By accessing or using the Site or Services, You acknowledge and consent that We will collect, use, and share Your information as outlined in this Policy.

This Policy does not apply to:

  • Third-party applications or software that integrate with the Services
  • Any third-party products, services, or businesses
Section 2
Definitions

Personal Data — Any information that directly or indirectly identifies an individual. This includes: name, address, location data, identifiers; physical, physiological, genetic, mental, economic, cultural, or social identity factors; information referred to under applicable law as "personally identifiable information" or "personal information."

Aggregate Data — De-identified data, learnings, logs, or grouped information that cannot be used to identify an individual. Personal Data does not include Aggregate Data or publicly available information not combined with non-public Personal Data.

Section 3
Ekom's Role as Data Controller and Data Processor

Data Controller — Ekom acts as a data controller when We determine the purposes and means of processing Personal Data (e.g., customer feedback, product improvement).

Data Processor — Ekom acts as a processor when providing Services to Clients and processes Personal Data only under Client instructions, the Terms of Service, and this Policy.

Section 4
Information We Collect From You

We collect information You provide directly through the Site or when registering for and using the Services.

Identity or Contact Information — Collected when creating an Account, including name, address, credentials, email, date of birth, or similar identifiers.

Transaction Information — Payment details, subscription information, transaction history, and payment card information.

Content Data Information — User-generated content including uploads, posts, comments, preferences, metadata, and Generated Content used to improve Services.

Marketing & Communications Information — Marketing preferences, communication settings, and messages sent to Us.

Behavioral & Usage Information — Traffic data, logs, location data, interactions, and activity on the Platform. May include automatically collected or inferred behavioral data across online services.

Technical Information — IP address, location, time zone, device identifiers, OS, browser type, and similar data collected via cookies, logs, and web beacons.

Aggregated Data — Statistical or demographic data derived from Personal Data but not identifying on its own. If combined with Personal Data, it is treated as Personal Data.

Sensitive Data — Ekom does not generally collect sensitive Personal Data (e.g., race, religion, health, biometrics). If required, We will request Your explicit consent.

Section 5
Information From Third-Party Sources

We may receive information from: third-party integrations, linked websites, ad networks, analytics providers, and content providers, and tracking technologies used by third parties.

Third-party practices are governed solely by their policies.

Cookies, tracking pixels, web beacons, and related technology may also be used to collect Personal Data or activity data across sites.

We use analytics technologies — Google Analytics, Microsoft Clarity, and the LinkedIn Insight Tag — that load only after you select “Accept all.” Apollo.io identifies the company associated with your visit at a firmographic level (organization, not an individual) and, as a disclosed exception, loads before consent — suppressed on internal devices and when your browser sends a Global Privacy Control signal; processed per Apollo's privacy policy, and RB2B performs person-level identification — routing your visit through third-party identity/enrichment providers (including LiveIntent and IP-geolocation), and may return your name, business email (or a fallback personal email), LinkedIn profile, job title and company, and approximate location; it also sets persistent first-party identity cookies. RB2B and its providers process this data per RB2B's privacy policy. Choosing “Essential only” prevents the optional analytics (GA4, Clarity, LinkedIn) from loading, but does not stop Apollo or RB2B — those load before consent and are suppressed only by Global Privacy Control or an internal-device flag.

Section 6
Cookie and Tracking Technologies

We use cookies for functionality, analytics, personalization, and advertising.

Type Purpose
Essential Cookies Required for core functionality such as login and content loading.
Functionality Cookies Remember preferences like login info and user settings.
Analytics & Performance Cookies
GA4: _ga, _ga_*, _gid
Measure traffic, usage patterns, and performance data via Google Analytics 4; data is pseudonymous and subject to Google's privacy policy. Only set with your consent.
B2B Company Identification
Apollo Reveal: aps_uid
Used to identify the company associated with your visit at a firmographic level (organization name, industry, size). This identifies the company, not an individual. Set before consent as a disclosed exception; suppressed on internal devices and when Global Privacy Control is enabled. Processed per Apollo's privacy policy.
Person-Level Identification
RB2B + identity providers
Identifies individual business visitors (person-level) to support outreach, using RB2B together with third-party identity/enrichment providers (e.g. LiveIntent, IP-geolocation). Loaded before consent as a disclosed exception. May return name, business (or fallback personal) email, LinkedIn profile, job title/company, and approximate location, and sets persistent first-party identity cookies. Suppressed on internal devices and when Global Privacy Control is enabled. Processed per RB2B's privacy policy and those of its providers.
Targeted & Advertising Cookies Track browsing habits to deliver interest-based ads via the LinkedIn Insight Tag. Only set with your consent.

Log Data — Automatically collected browser requests including IP, URLs visited, clicks, pages viewed, and similar information.

Do Not Track — We currently do not respond to browser DNT signals.

Global Privacy Control — We honor GPC as an opt-out signal: when your browser sends GPC, pre-consent visitor identification (Apollo and RB2B) is suppressed. The optional analytics (GA4, Clarity, LinkedIn) load only after you select “Accept all.”

Section 7
How We Use Your Personal Data

We use Personal Data to:

  • Provide, operate, improve, and personalize the Services
  • Personalize and improve your own results over time. We may use your Content — including your product catalogs, your responses and feedback, and information you choose to provide about your catalog — to generate and help refine the Generated Content and results we deliver to you on an ongoing basis. This benefits your account only; we do not use one client's non-public Content, or anything derived from it, to inform results for any other client.
  • Improve and develop the Services generally. We may use de-identified and aggregated learnings derived from providing the Services — which contain no identifiable client content and cannot reasonably be used to identify any client, customer, or individual — to operate, secure, evaluate, and improve the Services and build new features. We do not use the substance of one client's identifiable non-public Content for the benefit of any other client, and we do not use your Content to train or fine-tune any AI model.
  • Contact You with marketing content and administrative notices
  • Administer Your account and provide documentation
  • Collect feedback and improve Services
  • Communicate onboarding, support, and updates
  • Evaluate employment applications
  • Conduct testing, research, analytics, and product development
  • Fulfill any purpose disclosed at the time of collection

We do not sell your Personal Data for monetary payment. Some tools may be considered a “sale” or “sharing” for cross-context behavioral advertising under certain U.S. state privacy laws: the LinkedIn Insight Tag (loads only after “Accept all”) and RB2B (person-level identification that loads before consent, resolving identity through third-party providers such as LiveIntent). LinkedIn is avoided by choosing “Essential only”; RB2B is suppressed by Global Privacy Control or an internal-device flag. A dedicated “Do Not Sell or Share My Personal Information” control is planned; in the meantime, email privacy@ekom.ai to exercise opt-out rights.

All AI analysis is performed in real time at the moment of each request. The third-party foundation models we rely on operate under a zero-data-retention arrangement and do not use your Content to train their models. We do not use your Content to build, train, or fine-tune any general-purpose or cross-client AI model, and we never use or share one client's non-public Content for the benefit of any other client.

Section 8
How We Share Personal Data

Service Providers — For hosting, analytics, CRM, email, and operations — under strict confidentiality and security obligations.

Third-Party AI Providers — Your product catalog content is sent to third-party AI providers for inference (real-time analysis and recommendation generation). This content is processed only as needed to deliver the Services to you. Our AI providers operate under a zero-data-retention arrangement and do not use your content to train their models. Our current subprocessors, including AI providers, are identified in our Security & Compliance Overview, available on request.

Compliance with Law — Required disclosures to comply with regulations, court orders, law enforcement, fraud prevention, or safety risks.

Corporate Affiliates — Shared with subsidiaries, parent companies, or affiliates.

Business Transitions — Mergers, acquisitions, or asset sales. You will be notified of material changes.

With Your Consent — Or for any purpose disclosed at the time of collection.

Section 9
Global Operations & International Data Transfers

We may transfer and store Personal Data in countries outside Your residence, including the U.S.

Standard Contractual Clauses — Used for EEA/UK/Swiss transfers. For data-protection terms or transfer-mechanism questions, contact: privacy@ekom.ai

Section 10
GDPR Rights (EU, UK, EEA)

You have the right to: access, correct, delete, or port Your Personal Data; object to processing or withdraw consent; restrict processing; and file complaints with supervisory authorities.

Requests may require identity verification.

Section 12
U.S. Resident Rights (CCPA, CPRA, etc.)

Depending on Your state, You may have rights to: access and disclosure, correction, deletion, data portability, opt-out of sale/sharing/targeted advertising, revoke consent, and non-discrimination.

Opt-out tools are provided in the Cookie Consent Manager.

Nevada users may email privacy@ekom.ai to opt out of sale (though Ekom does not sell Personal Data under Nevada law).

Section 13
Sensitive Personal Data

We do not collect or use Sensitive Personal Data except as legally permitted and required for the Services.

Section 14
Exercising Your Rights

Email requests to: privacy@ekom.ai

We may need information to verify Your identity. Responses are provided within the legal timeframe (typically 45 days).

Section 15
Children's Privacy

We do not knowingly collect Personal Data from children under 16. To report concerns: privacy@ekom.ai

Section 16
Security

We use industry-standard security measures including encryption in transit and at rest, role-based access controls, and audit logging. EKOM is SOC 2 certified. We use Stripe for payment processing. While We take reasonable precautions, no system is fully secure.

Data Breach Notification. In the event of a security incident involving your Personal Data, We will notify you without undue delay and, where required by applicable law, within 72 hours of becoming aware of the breach. The notification will describe the nature of the incident, the categories of data affected, and the steps We are taking to address it.

Section 17
Data Retention

We retain Personal Data as long as needed for: Services usage, legal obligations, dispute resolution, and business needs. Upon termination, client data is deleted or returned within 30 days, with written certification available on request, as set out in the engagement agreement.

Section 18
Changes to this Privacy Policy

We may update this Policy periodically. Material changes will be communicated via email or posted notice.

Section 19
Contact Our Data Protection Officer

Agyl AI, Inc.
Attn: Legal
1033 Demonbreun St., Suite 300
Nashville, TN 37203
Email: privacy@ekom.ai