EntityRise Privacy Policy
Effective date: 30 August 2026 · entityrise.ai/privacy · Controller: Smophy Labs Inc.
1. Who we are
This Privacy Policy explains how Smophy Labs Inc., a Delaware corporation, 16192 Coastal Highway, Lewes, Delaware 19958, United States ("Smophy Labs", "EntityRise", "we", "us"). EIN available on request for invoicing purposes. collects, uses and shares personal data when you visit entityrise.ai (including entityrise.ai/pl), use the EntityRise application, or purchase our services. For the purposes of the EU and UK General Data Protection Regulation (GDPR), Smophy Labs Inc. is the data controller. Contact for privacy matters: contact@entityrise.com.
2. What we collect
- Account data: name, email address, password (stored as a hash) or, if you sign in with Google, the identifier and email provided by Google.
- Business and audit data: the website address, brand name, product or service description, target market, competitors and customer questions you submit when ordering an audit, and the business profile you confirm before the audit runs.
- Public website content: to produce an audit we crawl publicly available pages of the website you submit (typically up to 30 pages) and record their text, metadata and technical signals. We do not access password-protected or otherwise non-public areas.
- Payment data: payments are processed by Stripe. We receive confirmation of payment, the last four digits of the card, the card country and the billing details you enter. We never see or store your full card number.
- Invoicing data: for the Implementation Sprint and the Growth Service, your company name, address, VAT or tax identification number and the name of your contact person.
- Communications: messages you send through our contact form or by email, bookings you make through our scheduling pages (name, email, company, chosen time, notes), and notes from calls.
- Engagement data (Sprint and Growth clients): where you authorise it, data from your Google Search Console, analytics or content management system, accessed only to deliver the services and shown in your monitoring dashboard. You can revoke this access at any time.
- Usage data: IP address, browser and device type, pages visited, referring page and similar technical information collected through server logs and, if you accept them, analytics cookies.
3. How we use data and on what legal basis
- To provide the services - generating audits, delivering reports, running Sprints and Growth engagements, operating the monitoring dashboard and scheduling calls. Legal basis: performance of a contract.
- To process payments and issue invoices, and to keep accounting records. Legal basis: performance of a contract and legal obligation.
- To communicate with you about your orders, deliverables, bookings and support requests. Legal basis: performance of a contract and legitimate interest.
- To send product news and offers by email, only if you have opted in. You can unsubscribe at any time using the link in each message. Legal basis: consent.
- To secure, maintain and improve the services, including analysing usage and improving our measurement methodology using aggregated, de-identified data. Legal basis: legitimate interest.
- To comply with law, respond to lawful requests and enforce our Terms. Legal basis: legal obligation and legitimate interest.
We do not use your personal data for automated decisions that produce legal or similarly significant effects on you.
4. AI providers
To run an audit we send the business information you submitted and the publicly available content of the website concerned to third-party AI model providers - currently OpenAI, Anthropic, Google, xAI and Perplexity - through their business APIs, in order to record how their systems describe, cite and recommend the business. We use these providers under their business terms, under which submitted content is not used to train their public models unless the provider states otherwise. We do not send your account credentials, payment data or non-public documents to AI providers.
5. Who we share data with
We do not sell personal data, and we never share a client's data with that client's competitors. We share data only with:
- Service providers that process data on our behalf: Stripe (payments), our cloud hosting provider, our email delivery provider, our scheduling provider (for booking pages), our analytics provider, and the AI model providers listed in section 4. Each is bound by a contract that limits its use of the data to providing its service to us.
- Professional advisers (accountants, lawyers) where necessary.
- Authorities where required by law or to protect our rights, safety or property.
- A successor in the event of a merger, acquisition or sale of assets, in which case this Policy will continue to apply to your data.
6. International transfers
We are based in the United States, and our providers may process data in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, and we require the same of our providers.
7. Cookies
We use essential cookies that are needed for the website and application to work (for example to keep you signed in and to complete checkout). These cannot be switched off. With your consent we also use analytics cookies to understand how the website is used. When you first visit, a banner lets you accept or decline non-essential cookies; you can change your choice at any time through the cookie settings link in the footer or your browser settings.
8. How long we keep data
- Account, audit and report data: for as long as your account is active, and for up to 12 months after it is closed so that you can retrieve your reports, unless you ask us to delete them sooner.
- Invoicing and payment records: for as long as required by tax and accounting law (generally up to 7 years).
- Crawled website content: for the duration of the audit and up to 12 months afterwards, to allow comparison in a later audit.
- Contact-form messages and booking data: up to 24 months after the last contact.
- Usage and analytics data: up to 26 months, in aggregated form thereafter.
Aggregated data that no longer identifies any person or business may be kept indefinitely.
9. Your rights
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your national supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.
If you are in the United States, you may request access to, correction of or deletion of your personal data, and you may opt out of marketing emails at any time. We honour these requests regardless of whether a specific state privacy law applies to you.
To exercise any of these rights, email contact@entityrise.com. We will respond within 30 days and may ask you to verify your identity first.
10. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit, access controls, hashed passwords and restricted access to production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
11. Children
The Services are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact contact@entityrise.com and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. The current version, with its effective date, is always published at entityrise.ai/privacy. Material changes will be announced by email or in the application before they take effect.
13. Contact
Privacy questions and requests: contact@entityrise.com. Billing: billing@entityrise.ai. Postal address: Smophy Labs Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States.