Privacy Policy
Last updated: May 11, 2026
Effective date: May 11, 2026. This Privacy Policy (the “Policy”) describes how Huelo.ai (the “Huelo” service, “we,” “us,” or “Huelo”) handles your personal data when you access and use our website, services, software, mobile applications, content, and all products and services we own, control, or provide directly or indirectly (collectively, the “Service”). Huelo.ai is currently operated independently by a solo developer and is not yet incorporated as a legal entity; in this context, under Article 2(7) of Taiwan's Personal Data Protection Act, the solo developer remains the Data Controller and bears the corresponding obligations under Article 4(7) of the GDPR. Huelo values user privacy and is committed to using your personal data only as described in this Policy.
By using the Service, you confirm that you have read, understood, and agreed to be bound by this Policy and the Terms of Service, and that you are at least 18 years old. If you do not agree with this Policy, please do not use, install, or access the Service.
1. What is personal data
In this Policy, “personal data” means any information that can directly identify you, or that combined with other information can identify you. Examples include your name, email, and recording content — all of which may constitute personal data.
Personal data may also include “sensitive personal data” as defined under applicable law (Article 6 of Taiwan's Personal Data Protection Act, Article 9 of the EU GDPR), such as health information, financial details, political opinions, or religious beliefs that may be revealed during recorded conversations.
2. Information we collect
2.1 Information you provide directly:
- Account data: name, email, password, avatar, display name, third-party login (Google / Apple), and other profile information.
- Recording content: audio recorded through Huelo across various scenarios, text from real-time transcription, and AI-generated summaries, highlights, and action items.
- Uploaded files: audio files you choose to upload, images (for slide-fusion analysis), attachments, etc.
- Payment data: processed by Lemon Squeezy; we only receive non-PCI payment metadata (card type, last 4 digits, billing address).
- Usage data: feedback, help requests, preferences, custom vocabularies, and custom analysis templates you provide while using the Service.
- Other: additional information you provide when placing orders, requesting demos, or completing surveys (e.g. company name, job title, phone).
2.2 Information we collect automatically:
- Device information: device type, operating system, browser type, unique device identifiers (e.g. IP address).
- Log data: your IP address, browser type and settings, request times, and how you interact with the Service.
- Usage data: features used, actions performed, time zone, country, access date/time, User Agent version, computer or mobile device type, network connection type, quota usage.
- Network and browsing information: pages viewed, dwell time, clickstream, URLs, ports, session start identifiers.
- Cookies and tracking technologies: see Section 3.
2.3 Processing of sensitive personal data: The Service is a general-purpose recording and transcription platform, designed for meetings, education, and professional discussions. We do not design the Service to collect or process sensitive personal data as defined under GDPR Article 9(1) or Article 6 of Taiwan's Personal Data Protection Act. However, given the open nature of audio recording, recordings processed through the Service may incidentally contain sensitive personal data (such as health, political opinions, religious or philosophical beliefs, trade union membership) when participants voluntarily disclose such information in recorded conversations. We do not knowingly collect, solicit, or encourage the submission of sensitive personal data. Such data appearing in recordings is incidental, originating from participants' own voluntary disclosures.
Our legal basis for processing such incidentally captured sensitive data is: GDPR Article 9(2)(a) — explicit consent. Before each recording starts, the Service displays a clear notice informing you that: (i) the conversation will be recorded and processed by AI systems; (ii) the recording may contain sensitive personal data; (iii) you are responsible for ensuring all participants have been notified and consented. By continuing to record after receiving this notice, you are deemed to have given explicit consent to the processing of sensitive data that may be incidentally captured. You may withdraw consent at any time by deleting the relevant recording under Section 17 of this Policy; withdrawal does not affect the lawfulness of processing before withdrawal.
3. Cookies and similar technologies
We use the following types of cookies:
- Essential cookies: Required for normal operation of the Service, including login session tokens and security cookies (CSRF protection). These cookies do not require your consent.
- Analytics cookies: We use session identifiers to understand how users use the Service and improve the experience. These identifiers are temporary and help us analyze usage patterns. Once you create an account, analytics data may be associated with your account (per this Policy).
We do not use any third-party advertising or tracking cookies, and we do not engage in cross-context behavioral advertising.
EU/EEA/UK users: When you first visit the site, we present a cookie consent mechanism allowing you to accept or reject non-essential cookies before they are placed on your device. Analytics cookies are only placed after you grant consent. You may withdraw consent at any time via cookie preferences.
Users outside EU/EEA/UK: You can control cookies through your browser settings. Disabling essential cookies may impair your ability to use the Service.
4. How we use your information
Huelo uses your data for the following purposes, with the legal basis under GDPR noted:
- Account creation: Using your registration data, device data, and third-party login information (e.g. username, email) to create accounts for using the Service. Legal basis: contract performance and pre-contractual obligations.
- Service provision: Using recording content to provide AI analysis, transcripts, summaries, highlights, action items, and other services. Legal basis: performance of our contract with you.
- Service improvement: Using data we automatically collect or generate from your use of the Service to analyze and improve the Service. Legal basis: legitimate interests in improving and developing the Service.
- AI and machine learning:
- We do not use your identifiable recordings or transcripts to train AI models that benefit other customers; your data stays within your account.
- We may use fully anonymized and aggregated data to improve speech recognition and AI capabilities; such data cannot be traced back to any individual user.
- Our third-party AI service providers (OpenAI, Anthropic, Deepgram) process your data solely to provide transcription and analysis services, and are contractually prohibited from using your data for their own model training. These providers are bound by data processing agreements compliant with GDPR Article 28 and UK GDPR.
- Account management: Used to verify your identity, manage your account, and provide enhanced security features (e.g. 2FA). Legal basis: contract performance and legitimate interests in maintaining account security.
- AI assistant memory feature: In appropriate contexts, AI may use your prior recording content to provide accurate follow-up responses. Legal basis: performance of our contract with you.
- Internal analytics: Analyzing user behavior and usage patterns to optimize service features and user experience. Legal basis: legitimate interests in understanding and improving service usage.
- Fraud prevention and abuse: Ensuring system security and preventing fraud or abuse. Legal basis: legitimate interests in protecting the Service and users; compliance with legal obligations.
- Marketing and communications: With your consent, sending service updates and promotional information. Legal basis: your consent (which you can withdraw at any time).
- Legal compliance: Using or sharing necessary information to comply with legal obligations or respond to law enforcement requests. Legal basis: compliance with legal obligations.
Automated decision-making: The Service's AI systems are used to generate summaries, action items, and recommendations. These automated processes are designed to assist you and do not produce legal or similarly significant effects on you. If you have concerns about automated processing, please contact legal@huelo.ai.
5. Who we share your information with
We only disclose your personal data to the following categories of third parties when necessary and consistent with applicable laws and regulations:
5.1 AI technology service providers (data processors)
To provide the Service's core AI features, we transmit your recordings, transcripts, and related content to the following AI service providers. These providers are all US companies, bound by data processing agreements compliant with GDPR Article 28 and UK GDPR, and contractually prohibited from using your data for their own model training:
- OpenAI, L.L.C. (San Francisco, USA) — audio file transcription (Whisper model gpt-4o-transcribe).
Policy link: https://openai.com/policies/privacy-policy
Data retention: API data is retained for up to 30 days by default for abuse detection, then deleted. - Anthropic, PBC (San Francisco, USA) — Claude language model used for meeting analysis, AI assistant, and smart correction. API calls to Anthropic are routed through Vercel AI Gateway (Vercel Inc., USA) as a technical intermediary; this intermediary does not store your request content and is not used for model training.
Policy links: https://www.anthropic.com/legal/privacy; Vercel Privacy Policy
Data retention: API data is not used for training, retained up to 30 days by default, then deleted. - Deepgram, Inc. (San Francisco, USA) — real-time speech recognition (WebSocket streaming).
Policy link: https://deepgram.com/privacy
Data retention: set per data processing agreement; not used for training.
Huelo does not use any mainland Chinese AI services. Your recordings, transcripts, and related data will not traverse servers governed by China's Data Security Law or National Security Law.
5.2 Infrastructure providers
- Supabase Inc. (USA) — PostgreSQL database, authentication, Row Level Security.
Policy link: https://supabase.com/privacy - Cloudflare, Inc. (USA) — R2 object storage (audio files), CDN.
Policy link: https://www.cloudflare.com/privacypolicy - Upstash, Inc. (USA) — Redis job queue (asynchronous tasks).
Policy link: https://upstash.com/trust/privacy.pdf - Vercel Inc. (USA) — application hosting (Serverless Functions).
Policy link: https://vercel.com/legal/privacy-policy
5.3 Payment processors (data controllers)
- Lemon Squeezy (Affiliate Management, LLC) (USA) — web Merchant of Record handling global payments, tax, and subscription management. Huelo does not directly store your full credit card number, CVV, or financial data.
Policy link: https://www.lemonsqueezy.com/privacy - Apple Inc. (USA) — Merchant of Record for iOS App in-app subscriptions and add-on purchases; handles payment, tax, refunds, and subscription renewals. Huelo does not access your Apple ID payment data and only receives subscription status from Apple.
Policy link: https://www.apple.com/legal/privacy - RevenueCat, Inc. (USA) — iOS subscription infrastructure provider; helps Huelo sync Apple subscription status, unlock quota, and handle webhooks. Does not access financial data, only handles subscription identifiers and status.
Policy link: https://www.revenuecat.com/privacy
Lemon Squeezy and Apple act as independent data controllers when processing your payment data and may use it for their own purposes per their privacy policies; RevenueCat acts as a data processor, contractually bound to process subscription identification data only on Huelo's instructions.
5.4 Other disclosures
- Public authorities: When required by law or necessary to protect our or third parties' rights, we may disclose information to law enforcement, courts, or other competent authorities.
- Other users: Information you choose to share through the Service (e.g. username, shared meeting records) will be visible to your designated recipients.
- Corporate reorganization: In a merger, acquisition, reorganization, bankruptcy, or sale of substantially all assets, your personal data may be transferred as part of the assets to the subsequent owner or operator, subject to this Policy.
We do not sell or rent your recording content to third parties, and we do not use your data for ad targeting. We enforce strict contracts and data processing agreements with all third parties to ensure they only use data for our designated specific purposes and protect your data.
6. External links
The Service sometimes links to external websites. These sites may contain third-party offers and promotions. We provide these links solely to help you find potentially useful or interesting information, products, or services. We are not responsible for the content of these sites or the products or services they offer. Third-party site terms and privacy policies will explain how to use those sites; you use sites operated by others at your own risk.
7. Data storage location and international transfers
7.1 Data storage location. Your data is primarily stored at the following locations:
- Supabase: PostgreSQL database and authentication, stored in their US or European data centers by default depending on your region.
- Cloudflare R2: audio files stored on Cloudflare's global distributed network with automatic edge caching.
- Upstash: job queue temporary data, stored in US, European, or Asia-Pacific regions depending on configuration.
7.2 International data transfers. Because our AI services and infrastructure providers (OpenAI, Anthropic, Deepgram, Supabase, Cloudflare, Upstash, Vercel, Lemon Squeezy) are all located in the United States, your personal data will be transferred, stored, and processed in the US and other countries where these providers operate.
Data protection laws in these countries may differ from those in your country of residence. To ensure your personal data is properly protected during international transfers, we rely on the following safeguards:
- EU Standard Contractual Clauses (SCCs): For transfers governed by the GDPR, we adopt the Standard Contractual Clauses passed by the European Commission's Implementing Decision (EU) 2021/914 of June 4, 2021.
- UK Addendum / IDTA: For transfers governed by UK GDPR, we adopt the UK Addendum (version B1.0) issued by the UK ICO under section 119A(1) of the Data Protection Act 2018, or the International Data Transfer Agreement.
- Supplemental measures: Encrypted transmission, access controls, and confidentiality obligations are implemented as necessary supplements.
For further information about the transfer safeguards we adopt, please contact legal@huelo.ai.
8. Data retention
We retain your personal data for the following periods:
- Account data: Retained while your account is active. Permanently removed within 30 days after account deletion.
- Meeting recordings and transcripts: Retained until you actively delete them or your account is deleted. Permanently removed within 30 days after deletion (content in Trash may be retained until Trash retention expires).
- AI-generated content: Summaries, action items, notes, etc. are retained alongside the associated recording and deleted together when the recording is deleted.
- Payment records: Retained for 7 years as required by tax and accounting regulations. We do not store full credit card numbers.
- Server logs: Retained for 90 days for security and troubleshooting purposes.
- Backup copies: Deleted data may remain in encrypted backups for up to 90 days.
- Usage statistics: Retained anonymized for up to 12 months for service improvement.
After the retention period, we will securely delete or anonymize your personal data, unless longer retention is required by law.
9. Security measures
We implement commercially reasonable technical, administrative, and organizational measures to protect personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction. These measures include but are not limited to:
- Encryption in transit (TLS): All communications between you and the Service over the internet use HTTPS encrypted connections.
- Encryption at rest: Stored user content and passwords are encrypted using industry-standard algorithms.
- Access controls: User authentication via password or Google / Apple login; 2FA supported; web cookies authenticate logged-in users.
- Data isolation: We logically isolate customer personal data via Supabase Row Level Security, ensuring customers can only access their own data and not other customers' personal data.
- Support access restrictions: To resolve customer issues, the Huelo support team must obtain customer explicit permission and system administrator approval to access specific user content related to a reported issue. All such access requests are logged.
- Data backups: We back up the database daily, with user content stored in persistent storage.
- Physical access controls: User content is hosted on Cloudflare R2 and Supabase; these providers' data centers have security controls to prevent unauthorized physical access.
- AI system security: We implement appropriate measures to secure the AI systems used by the Service, including secure handling of audio data, encryption of AI Outputs, and access controls for AI model interactions. Third-party AI service providers are bound by data processing agreements containing security requirements consistent with this Annex.
- Regular assessments: Regular security assessments and staff data protection training.
However, no internet or email transmission is completely secure or error-free. You should therefore be cautious when deciding what information to send to the Service. Additionally, we are not responsible for any attempt to circumvent the privacy settings or security measures of the Service or third-party sites.
10. Your rights
Under applicable law in your location (including Taiwan's Personal Data Protection Act, the EU GDPR, and the UK GDPR), you have the following rights regarding the personal data we hold about you:
- Right to inquire and access: You have the right to request access to the personal data we hold about you, and to receive information about how we use it and with whom we share it.
- Right to rectification: You have the right to request correction of inaccurate or incomplete personal data we hold about you.
- Right to erasure (right to be forgotten): You have the right to request deletion or removal of your personal data, except for data we are required by law to retain.
- Right to object to processing: You have the right to object when we process your personal data based on legitimate interests or for direct marketing purposes.
- Right to restrict processing: In certain situations, you have the right to restrict our processing of your personal data (except for storage).
- Right to data portability: You have the right to obtain a copy of your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
- Right to withdraw consent: For data we process based on your consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right not to be subject to automated decisions: The Service uses AI to generate summaries, action items, and recommendations. These automated processes are designed to assist you and do not produce legal or similarly significant effects on you.
- Right to lodge a complaint with a regulatory authority: If you are located in the EEA, you may lodge a complaint with your local data protection authority; if you are in the UK, you may complain to the Information Commissioner's Office (ICO); if you are in Taiwan, you may complain to the National Development Council (the central authority for the Personal Data Protection Act) or your local competent authority.
Exercising your rights: To exercise these rights, contact support@huelo.ai. To protect your privacy and data security, we will verify your identity before responding. We may need additional information (e.g. the reason you believe data is incorrect), and there may be lawful reasons to decline a request (in which case we will inform you).
11. Additional rights for California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA, as amended by the California Privacy Rights Act, CPRA) gives you the following rights:
- Right to know / access: You have the right to request that we disclose the categories of personal information we collect, sources, business purposes for collection or sale, categories of third parties with whom data is shared, and specific personal information we have collected. You may make two requests per 12-month period.
- Right to delete: You have the right to request deletion of your personal information collected, subject to legal exceptions.
- Right to correct: You have the right to request correction of inaccurate personal information we hold.
- Right to limit use of sensitive personal information: To the extent we collect sensitive personal information as defined by CPRA, you have the right to limit us to using and disclosing such data only as necessary to provide the Service. Because the Service involves audio recording that may contain sensitive topics, we use such information only to provide the transcription and analysis services you request.
- Right against discrimination: You will not be discriminated against for exercising your California privacy rights. We will not deny service, charge different prices, or provide different quality or level of service for your exercise of rights.
Sale and sharing: Huelo does not sell California residents' personal information (as defined under CCPA / CPRA). We also do not engage in cross-context behavioral advertising sharing.
Authorized agents: You may designate an authorized agent to submit requests on your behalf. The agent must provide your written authorization, and we may require you to verify your identity directly.
How to submit a request: Through support@huelo.ai with “Personal Information Request” in the subject line. We will confirm receipt within 10 days and respond within 45 days (extendable to 90 days when necessary, with notification of the reason).
Under California Civil Code section 1798.83, if you are a California resident, you may complain to the California Department of Consumer Affairs: 1625 N. Market Blvd, Suite S-202, Sacramento, CA 95834; phone (800) 952-5210.
12. EU AI Act compliance
Huelo is committed to compliance with EU Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act, “AI Act”), which establishes a unified legal framework for the development and use of AI systems within the EU.
12.1 Classification of our AI systems
The Service uses AI systems for the following functions:
- Automatic speech recognition (ASR) and audio transcription
- Real-time speech-to-text
- Content summarization and highlight extraction
- Action item generation
- Contextual follow-up responses by the AI meeting assistant
- AI recommendations
Under the AI Act's risk-based classification framework, our AI features fall under limited-risk AI systems, subject only to Article 50 transparency obligations. We confirm:
- We do not operate any AI systems falling under the prohibited practices in AI Act Article 5 (including social scoring, subliminal manipulation, exploitation of vulnerable groups, or unauthorized real-time remote biometric identification).
- Our AI systems do not fall under the high-risk classification in AI Act Annex III (not used for biometric identification, critical infrastructure management, education assessment, employment decisions, access to essential services, law enforcement, migration management, or administration of justice).
- We do not deploy AI systems that generate deep fakes of real persons or synthetic audio or video.
12.2 Transparency obligations (under AI Act Article 50)
- AI interaction disclosure: We clearly inform you in the user interface that you are interacting with AI, including: labeling AI-generated summaries, transcripts, action items, and recommendations as AI-generated; providing clear notification when AI features (e.g. AI recommendations, AI assistant) are activated.
- AI-generated content marking: AI Act Article 50(2) requires providers of AI systems generating synthetic content to ensure their output is marked in machine-readable formats. As a deployer of third-party AI models:
- Visible disclosure: AI-generated content is clearly identified in the user interface through visible labels and indicators.
- Machine-readable marking: We rely on our upstream AI service providers (listed in Section 5) to implement machine-readable marking per their obligations under Article 50(2); we do not remove, alter, or suppress any machine-readable markings applied by these providers.
- Continuous monitoring: We monitor AI service providers' compliance with Article 50(2), including adoption of emerging standards such as C2PA (Coalition for Content Provenance and Authenticity).
- User obligations: Users agree not to remove, alter, or obscure any AI-generated content labels or markings applied by the Service (see Section 10 of the Terms of Service).
- Human oversight and control: You retain full control over all AI Outputs. AI-generated content is presented as suggestions or assistance for you to review, edit, accept, or delete. The Service's AI systems do not make automated decisions that produce legal or similarly significant effects without meaningful human intervention.
12.3 AI data practices
- No use of your identifiable data for training: We do not use your identifiable recordings, transcripts, or User Content to train AI models that benefit other customers or third parties. Your data stays within your account.
- Anonymized data use: We may use fully anonymized and aggregated data (not traceable to any individual user) to improve speech recognition and AI capabilities.
- Third-party AI provider restrictions: Our third-party AI service providers (OpenAI, Anthropic, Deepgram) process your data solely to provide the Service and are contractually prohibited from using your data for their own model training. These providers are bound by data processing agreements compliant with GDPR Article 28 and UK GDPR.
12.4 AI literacy
Under AI Act Article 4 (applicable from February 2, 2025), we take the following steps to ensure:
- Personnel involved in AI system development, deployment, operation, and oversight have sufficient AI literacy, including understanding of AI capabilities, limitations, risks, and ethical considerations.
- Internal training materials are developed and maintained, supporting the team's ongoing AI literacy.
- Users receive clear information about how our AI features work, their intended purposes, and known limitations.
12.5 General-purpose AI models (GPAI)
The Service integrates third-party general-purpose AI models. As deployers of these models, we ensure use complies with applicable AI Act requirements and expect GPAI model providers to comply with their obligations under the AI Act (including Article 53 transparency requirements, technical documentation, and copyright compliance obligations).
12.6 Ongoing compliance
We continuously monitor regulatory developments under the AI Act, including delegated acts, implementing acts, harmonized standards, and European AI Office guidance, and update our practices as new obligations come into effect (including GPAI model obligations from August 2, 2025, and full applicability of high-risk AI systems from August 2, 2026).
For questions about our AI Act compliance, contact legal@huelo.ai.
13. Minors' privacy
The Service is only for users who are at least 18 years old. We do not knowingly collect, retain, or use personal data of children or adolescents under 18, and no part of the Service is designed for children.
If you are a parent or guardian and find that your child has provided personal data to us, please contact us to delete the data. We encourage parents and legal guardians to monitor their children's internet usage and help enforce this Privacy Policy by instructing their children not to provide personal information on this site or Service without permission.
If you discover that a child under 18 has provided personal data to us in violation of this Policy, please notify us at support@huelo.ai. We will take reasonable steps to delete such data as soon as possible.
14. Recording and third-party consent
When using the Service's recording features, you are responsible for ensuring that all participants in any recorded meeting have been notified and have consented to the recording per applicable law. Many jurisdictions require all-party consent before recording.
Huelo provides in-app notification features (recording indicators) to help you alert meeting participants that recording is in progress. However, failure to obtain appropriate recording consent may violate applicable laws, and Huelo is not responsible for your obligations to comply with such requirements. For detailed rules, see Terms of Service Section 4.
15. Payment information
Huelo uses third-party payment processors to handle payments for the Service.
For all paid transactions, we use Lemon Squeezy as the Merchant of Record to securely process payments. When you make a payment through the website or App, you will be directed to Lemon Squeezy's payment gateway, and your payment details are processed directly by Lemon Squeezy. Huelo only sees the payment card type, last four digits of the credit or debit card number, and billing address. See Lemon Squeezy's Privacy Policy for how they use and store your personal information.
16. Deleting your account
You can delete your Huelo account at any time from account settings. If you stop using the Service but do not actively delete your account, your account and associated personal data will be retained.
Upon receipt of an account deletion request, we will make commercially reasonable efforts to delete your records and personal data within 30 days, but cannot guarantee completion within this timeframe. If applicable law requires us to retain the data, we will handle per Section 8 and take steps to anonymize it.
17. User controls and privacy management
Huelo offers multiple ways for you to manage your privacy rights:
- Access and modify information: You can access, update, or delete your account data and personal information through account settings, or contact us to request deletion or updates.
- Recording management: You can delete past recordings and derived analyses.
- Privacy requests: You can submit access, deletion, or restriction requests by contacting us.
- Consent management: For data we process based on your consent (e.g. marketing communications, cookies), you can withdraw consent at any time through account settings or by contacting support@huelo.ai. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Data export: Pro and Max plan users can download recordings and transcripts; export formats include TXT, PDF, and JSON.
18. EU and UK representatives
Because Huelo is not established in the European Economic Area or the UK, we may be required to designate representatives under the following regulations:
- GDPR Article 27: The point of contact for EU/EEA data subjects and regulators on data protection matters.
- AI Act Article 54: The point of contact for national competent authorities and EU bodies on AI regulatory compliance matters.
- UK GDPR Article 27: The point of contact for UK data subjects and the UK ICO on data protection matters.
We acknowledge the obligation to designate representatives under the above regulations and are currently in the process of designating them; we will update this section with contact information once completed. In the meantime, please direct data protection inquiries to support@huelo.ai.
19. Data Protection Impact Assessment (DPIA)
Given that the Service involves audio recording processing, real-time transcription, and AI analysis, we conduct Data Protection Impact Assessments (DPIAs) as required by GDPR Article 35 and UK GDPR to identify and mitigate risks associated with high-risk processing activities. These assessments are reviewed and updated periodically or when significant changes occur in data processing practices.
20. Data protection contact
Under GDPR Article 37, we have assessed our processing activities and determined that we are currently not required to designate a Data Protection Officer (DPO). We will reassess this decision periodically and as our processing activities evolve.
For all data protection inquiries, including exercising your rights under applicable data protection laws, contact support@huelo.ai.
21. Changes to this policy
We periodically review and enhance our privacy and security policies. As the Service updates and expands, this Policy may change. For material changes, we will notify you at least 30 days before the effective date via email or prominent in-app notification. We also encourage you to review this Policy periodically.
Continued use of the Service after any changes to this Policy indicates your acceptance of those changes. If you do not agree to the changes, please stop using the Service before the effective date.
22. Contact us
Please contact the appropriate channel based on the nature of your inquiry:
- Data access / correction / deletion / export / account operations: support@huelo.ai
- Privacy complaints / GDPR / CCPA exercise of other statutory rights / AI Act compliance / regulatory correspondence: legal@huelo.ai
Please indicate the category in your email subject (e.g. “Data access request,” “Deletion request,” “Data portability request,” “GDPR Article 15 request”) for prioritized handling. If unsure which channel to use, email support@huelo.ai and we will route accordingly.
EU and UK representatives: see Section 18. Before representative designation is complete, EEA / UK users' GDPR requests should be sent to legal@huelo.ai.
Thank you for reading this Policy. Huelo is committed to handling your data transparently and honestly and to continuously strengthening our privacy and security practices.