Legal
Privacy Policy
Last updated: 23 July 2026
This policy explains what personal data Tallyrun collects, why we process it, who we share it with, and the rights you have. Tallyrun (“we”, “us”) is an AI automation studio operated by Mihail Kenarov, based in Eindhoven, the Netherlands. For anything in this policy, contact mihail@tallyrun.ai.
Who we are and our role
For this website, our own communications, and our outreach, Tallyrun is the data controller. When we build and run an automation for a client, we act as a data processoron that client’s behalf, and their privacy notice and our data processing agreement with them govern that work.
What we collect
- Information you give us. When you book a call, email us, or otherwise get in touch: your name, email address, the times you select, and anything you choose to write to us.
- The interactive demo. If you use the live agent on this site, the messages you type are sent to Anthropic’s Claude API to generate a response, and the conversation is stored in our database so the demo can keep context and so we can review quality. Anthropic does not train its models on data processed through its API. We do not use your demo messages to train any AI model either. Please do not enter real client, medical, or otherwise sensitive information into the demo — it is an illustration, not a production intake system.
- Business contact data for outreach. We may collect business contact details (name, role, firm, business email, public firm information) from public sources in order to contact firms that fit who we serve.
- Technical data. Our hosting and infrastructure providers automatically log standard technical information such as IP address, browser type, and pages requested, for security and reliability.
Why we process it, and our legal basis
- To respond to you and to provide our services — on the basis of performing a contract or taking steps at your request (GDPR Art. 6(1)(b)).
- To contact firms about services relevant to their business, and to run the demo — on the basis of our legitimate interests in growing the business, balanced against your rights (Art. 6(1)(f)).
- To keep the site secure and operational — on the basis of our legitimate interests (Art. 6(1)(f)).
- To comply with legal obligations where they apply (Art. 6(1)(c)).
Who we share data with
We do not sell personal data. We share it only with service providers (sub-processors) who help us run Tallyrun, under contracts that require them to protect it. These currently include:
- Hosting and delivery of this site (Vercel).
- Website analytics and session replay on our public marketing pages (Microsoft Clarity).
- Cookieless website analytics on our public marketing pages (Ahrefs).
- AI model providers that process demo and automation content (Anthropic, and other model providers we may use). Anthropic does not train its models on API data.
- Database hosting for demo and agent conversations (Neon).
- Email and productivity (Google Workspace; Resend for transactional email; Instantly for outreach email delivery).
- Scheduling (Cal.com).
- Automation and data storage (n8n hosted on Railway; Airtable).
- Operational notifications (Telegram).
- SMS delivery to a law firm’s own staff, where that firm has enabled it (Twilio). These alerts carry the enquiry outcome and the enquirer’s contact details, never injury or treatment details.
Separately from the providers above, when a law firm uses Tallyrun on its own website, we deliver each completed enquiry into the systems that firm has chosen — for example its Clio Grow lead inbox, its Slack workspace, or an address it gives us for its own case-management software. Those systems belong to the law firm, not to us, and once an enquiry reaches them it is handled under that firm’s own privacy policy. We only send to destinations the firm has configured.
We may also disclose data if required by law, or to protect our rights, safety, or property.
International transfers
Some of these providers are based outside the European Economic Area, including in the United States. Where data is transferred outside the EEA, it is protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
How long we keep it
We keep personal data only as long as needed for the purpose it was collected, and then delete or anonymise it. Our standard retention periods per category:
- Enquiries and correspondence: up to 2 years after our last exchange, in case the conversation resumes.
- Outreach contact data: removed promptly if you object or unsubscribe, and otherwise no later than 12 months after our last contact if there has been no response.
- Opt-out records: kept for as long as we conduct outreach, because we need them to honour your opt-out.
- Demo conversations: deleted or anonymised no later than 12 months after the conversation ends. Demo messages are never used to train AI models.
- Technical logs: retained by our infrastructure providers on short rolling windows, typically 30–90 days.
Your rights
Under the GDPR you have the right to access, correct, delete, or restrict processing of your personal data, to object to processing based on legitimate interests (including outreach), to data portability, and to withdraw consent where processing relies on it. To exercise any of these, email mihail@tallyrun.ai. You also have the right to lodge a complaint with your local supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
Security
We use reputable providers and reasonable technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, but we work to protect your information and to address issues promptly.
Cookies and analytics
This site uses what is necessary to function, plus three measurement tools:
- Vercel Web Analytics — a privacy-friendly, cookieless measurement tool that does not track you across sites or store identifiers on your device.
- Ahrefs Web Analytics — a privacy-friendly, cookieless measurement tool that counts visits to our public pages without tracking you across sites or storing identifiers on your device.
- Microsoft Clarity — shows us how visitors use our public pages, including anonymised recordings of page interactions such as clicks, scrolling and mouse movement. Anything you type into a form field or drop-down is masked in your browser and is never uploaded to Clarity.
Clarity runs only on our public marketing pages. It is deliberately switched off on the intake widget, the client dashboard and the admin area, so conversations and case details submitted through a law firm’s intake agent are never recorded by it. Microsoft explains its own use of this data in the Microsoft Privacy Statement.
Clarity runs in consent mode for visitors from the European Economic Area, the United Kingdom and Switzerland, which means it stores no cookies on your device unless you have consented to them. Elsewhere it stores first-party cookies that let it recognise a returning session. We do not use advertising or cross-site tracking cookies, and you can block or delete cookies in your browser settings. If our use of cookies changes, we will update this policy and, if required, ask for your consent.
Children
Tallyrun is a service for businesses and is not directed to children. We do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed. Material changes will be reflected here.
Contact
Tallyrun — Mihail Kenarov, Vestdijk 7, Eindhoven, the Netherlands. mihail@tallyrun.ai