Staging Test environment: this is a demo version, no real data is processed.
Back to Elicitra
Elicitra Workspace

Elicitra legal

Legal terms and privacy notices

Minimum legal framework for opt-in Elicitra pilots operated by Eigensource S.L. VAT ES B55497267. Contact: privacy@eigensource.com.

Current SaaS versions: 2026-07-01. Respondent versions: 2026-06-11. Last updated: 1 July 2026.

This implementation is operational compliance text for pilots, not final legal advice. Counsel/DPO review is required before broader production rollout.

Terms, privacy, and AI interaction notice

When a respondent requests a call, browser call, or text chat, Elicitra processes contact details, campaign context, conversation transcript, recording metadata where recording is enabled, provider events, and model output needed to produce lead summaries and handoff notes. The respondent is told that the interaction is with an AI assistant.

Elicitra uses Telnyx for telephony/browser voice and OpenAI for language processing. Hosting, email, and notification providers may process service metadata. We do not use respondent data for credit approval, regulated decisions, official quotes, or binding offers.

Public respondent terms

Respondents must accept the terms and confirm they have read the applicable notices before Elicitra contacts them or starts a browser call or chat. The service collects information for the named campaign and shares outputs with the platform customer that configured the campaign. A respondent may withdraw optional consent or request access, deletion, or correction by writing to privacy@eigensource.com.

Scenario outputs are informational lead-intake materials only. They are not financial advice, loan approval, eligibility assessment, official rate calculation, vehicle availability confirmation, or binding commercial offer.

SaaS/platform customer terms

Platform customers and admins use Elicitra to configure campaigns, scenarios, fields, questions, follow-up policies, and respondent flows. As deployers under the EU AI Act, they are responsible for the intended purpose of each scenario, for having a valid legal basis for each campaign, for accurate landing copy, and for avoiding regulated decisions or sensitive-data probing unless a separate reviewed basis exists. Eigensource S.L. provides the platform; customers own scenario content and what their agent asks.

Customers must keep account credentials confidential, respect cross-organization access boundaries, and use Elicitra only for opt-in callbacks or respondent-initiated sessions. Cold outbound marketing is outside this MVP scope.

SaaS billing, credits, and subscriptions

Free has no paid Checkout flow. Pro and Growth are monthly self-serve subscriptions processed by Stripe for the active organization. Scale is manual, invoice-led, and provisioned by Elicitra operators.

Included credits and purchased credit packs roll over unless a written customer agreement says otherwise. Extra credit packs, auto-replenish where enabled, and subscription changes take effect only after payment confirmation and ledger processing.

Prices may exclude taxes. Billing addresses, tax IDs, card details, invoices, refunds, cancellations, and payment-method changes are handled through Stripe or agreed manual Scale terms. Cancelling stops future subscription renewals but does not turn Elicitra outputs into financial proposals, approvals, official quotes, or binding offers.

Platform account privacy notice

Eigensource S.L. is controller for SaaS account data, authentication, organization membership, support, billing or billing preparation, product operations, security logs, and demo analytics. Account data may include name, email, organization, role, preferences, login metadata, support messages, and usage events.

Stripe may process billing contact details, tax information, payment metadata, invoice history, and subscription status for Pro and Growth self-serve billing. Elicitra stores only the Stripe customer/subscription references and billing state needed to operate the account.

Cookie notice

Cookie notice updated: 8 August 2026

Elicitra pages use the cookies listed below for language preferences, protected access, authentication, security, support context, and aggregate first-party campaign measurement.

We do not use profiling cookies or third-party advertising or analytics trackers on Elicitra pages.

For public immediate phone-call starts, Elicitra loads Cloudflare Turnstile as a mandatory security service to distinguish human visitors from bots and prevent abuse. Cloudflare processes client-side security signals including IP address, TLS fingerprint, User-Agent, site key, and associated page origin. Cloudflare acts as a processor for website protection and as an independent controller when using those signals to improve Turnstile's bot-detection capabilities. Elicitra does not send the optional remoteip field to Siteverify, and pre-clearance is disabled, so Elicitra does not configure Turnstile to issue a cf_clearance cookie. The check is required for this action: if it cannot be completed, the phone call does not start and no call credit is reserved. Customer pages embedding this flow remain responsible for disclosing the processing in their own notice and CMP treatment where applicable. Cloudflare Turnstile Privacy Addendum.

Cookies emitted by the current Elicitra production configuration
Production cookiePurposeDurationNature
PARAGLIDE_LOCALEStores the chosen interface language.400 daysTechnical/preference
elicitra_demoProtects access to Elicitra demo and marketing surfaces.8 hoursTechnical/security
elicitra_campaign_access_*Maintains password or invite access to one hashed campaign identifier; it cannot unlock another campaign.8 hoursTechnical/security, campaign-scoped
__Secure-better-auth.session_tokenMaintains an authenticated platform session.Up to 7 daysTechnical/authentication
__Secure-better-auth.stateProtects the Google OAuth flow against CSRF attacks.5 minutesTechnical/security, conditional
__Secure-better-auth.two_factorCompletes two-factor authentication.10 minutesTechnical/security, conditional
__Secure-better-auth.trust_deviceRemembers a device only when the platform operator chooses to trust it.30 daysTechnical/security, optional
__Secure-better-auth.admin_sessionRestores the superadmin session securely after impersonation.Up to 7 daysTechnical/security, conditional
elicitra_platform_orgKeeps organization context during superadmin support.8 hoursTechnical/functional, conditional
elicitra_funnel_visitorCounts aggregate campaign views and conversions; the UUID is retained only as a server-side hash.180 daysFirst-party aggregate measurement, non-profiling

Better Auth cookies use the __Secure- prefix on HTTPS production surfaces. The prefix may be absent during local development.

Inside a third-party iframe embed, elicitra_funnel_visitor and any elicitra_campaign_access_* session are set as Partitioned CHIPS cookies so the browser isolates them by the top-level site.

Elicitra pages, campaign consent, and external pages

External pages operated by platform customers remain under that customer's cookie notice and consent management platform (CMP). Elicitra does not control or inventory the tags those pages load and may receive only the resulting consent flags.

Optional campaign consents authorize later processing by the platform customer as controller; they do not inject tags into Elicitra pages.

Gate for future non-technical tags

Any future non-technical tag on Elicitra pages is blocked until a CMP is implemented with the applicable IAB TCF, Google Consent Mode v2, and Meta consent signals. The notice and consent choices must be updated before the tag is enabled.

Data Processing Addendum template

For customer campaign respondent data, the platform customer is the controller and Eigensource S.L. acts as processor. The DPA covers processing instructions, confidentiality, subprocessors, security measures, breach notification, assistance with data-subject requests, deletion/return at termination, and international transfer safeguards where applicable.

Subprocessors and vendors

Current core processors include Telnyx for telephony and AI voice infrastructure, OpenAI for language model processing, Cloudflare Turnstile for bot protection on public immediate phone-call starts, Stripe for payment processing, hosting/database infrastructure, transactional email, and notification services where enabled. The detailed vendor register is maintained in docs/legal/vendor-register.md.

Data retention

Raw data defaults to 90 days: transcripts, provider events, recording metadata, raw model output, and debug payloads. Business outputs default to 12 months: lead cards, handoff notes, scores, missing fields, contact fields, and campaign snapshots. After deletion or anonymization, only aggregate anonymous metrics should remain.