Privacy Policy
LAST UPDATED: 18 JULY 2026
This Privacy Policy describes how JHELY GLOBAL SL ("JHELY", "John CEO", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the John CEO service (the "Service"). JHELY is a company incorporated in Spain with registered office at Paseo de la Sierra 29, 29018 Málaga, Spain (CIF B67973388). We are the controller of the personal information described in this Policy, except where we act as a processor as set out in Section 5.
John CEO provisions a private, dedicated AI agent that runs on isolated cloud infrastructure and acts on your behalf across the messaging channels and business tools you connect. The Service is offered for professional and business use. By using it, you agree to this Policy.
1. Information We Collect
Account and identity information. Information you provide when you register and create an agent, such as your name, email address, account identifiers, dashboard preferences, and the persona and response style you configure. For messaging channels you link, the identifiers needed to operate the integration, such as your Slack or Telegram user or workspace identifiers used for access control.
Connection credentials. Credentials needed to maintain the integrations you enable, such as OAuth tokens, scopes, expiry metadata, and your messaging bot or app tokens. Credentials are encrypted and held in our control plane, and are made available to your agent only as needed. Your connections are private to your own agent.
Content inside your agent. Conversation threads and messages between you and your agent, the agent's outputs and record of tool calls, files your agent creates or that you upload, approval and rejection records, and scheduled-task configurations, stored on your agent's private volume.
Messaging content. When you interact with your agent over a connected channel (today Slack and Telegram), we process the message content to carry out your requests and maintain context. Slack data is handled as described in Section 7. Voice messages, where enabled, are transcribed to text and may be converted back to speech for replies.
Data from connected tools. When you authorize an integration, the agent accesses the data permitted by the scopes you grant, to perform the tasks you request. This may include personal data of third parties contained in those tools. You are responsible for ensuring you have the right to authorize that access.
Usage and log data. Service, audit, and security logs (timestamps, error reports, request and response metadata), and usage and metering data (for example tasks executed, approvals granted, and AI and tool spend per period).
Automatically collected information. When you visit our website or dashboard, we may collect IP address, device and browser characteristics, operating system, referring URLs, approximate location derived from IP, and interaction events, through cookies and similar technologies, primarily for security, operation, and analytics.
Payment data. If you purchase a subscription or add Work Credits (top-ups), payment is handled by Stripe. We receive limited billing and transaction metadata (including tax IDs and business details you provide at checkout); full payment instrument details are handled by Stripe.
Referral program data. When you participate in the referral program, we process redemption records, reward status, payment status signals from Stripe, and anti-fraud signals (such as device and network indicators) to administer the program and prevent abuse, on the basis of contract performance and our legitimate interests.
We do not intentionally collect special categories of personal information for our own purposes. Your agent may encounter such data inside the tools you connect, as part of the content you direct it to process. Our Terms of Service restrict the submission of special categories of personal data and certain other sensitive data to the Service.
2. How We Use Information
We use the information above to: provide, operate, and maintain the Service, authenticate you, provision and run your agent, and execute the tasks you request; process content through AI systems to generate outputs at your direction (see Section 6); secure the Service and detect and prevent fraud, abuse, and unauthorized access; understand usage and improve reliability, using aggregated or de-identified data where possible; communicate with you, including service, security, and billing messages, and support; and comply with legal obligations and enforce our Terms.
We do not use your messaging content or the data your agent accesses from connected tools for advertising, and we do not sell your personal information.
3. Legal Bases
We rely on the following legal bases under the GDPR: performance of our contract with you, to provide and administer the Service; our legitimate interests in operating, securing, and improving the Service; your consent, for non-essential cookies, marketing, and the optional use of your content described in Section 6, which you may withdraw at any time; and compliance with legal obligations.
4. How We Share Information
We share information only as needed to provide and support the Service, with the following categories of third parties.
Service providers (subprocessors). Vendors that host and operate the Service under contracts that limit their use of the data to providing services to us. Current providers include:
- Hetzner (cloud hosting: per-customer agent VM and persistent volume), Hetzner datacenters.
- Cloudflare (control plane, edge, security, AI gateway), global edge.
- OpenRouter (routing of AI requests to the model providers you select).
- Composio (execution of the third-party integrations you authorize).
- Slack and Telegram (messaging channel delivery).
- Payment processors. Card payments are processed by Stripe. Cryptocurrency processors may be added later.
- EmailLabs (emaillabs.io) (transactional email delivery).
- Google Analytics (website and product analytics).
- Microsoft Clarity (website analytics and session insights).
The tools you connect (for example email, calendar, or CRM) and the AI model providers you select are not our subprocessors in respect of your choices; they are independent services you authorize or select, governed by their own terms.
Business transfers. We may share or transfer information in connection with a restructuring, merger, acquisition, financing, or sale of assets, including a change of the operating entity for John CEO.
Affiliates. We may share information with entities under common control with us, which will honor this Policy.
Legal and protection. We may disclose information where we believe it necessary to comply with law or legal process, enforce our Terms, prevent fraud or abuse, or protect the rights, safety, and property of our users, the public, or us.
5. Controller and Processor Roles
For your account data (registration, billing, settings), JHELY is the controller. For the personal data your agent accesses within the tools you connect, including any third-party personal data, you are the controller and JHELY acts as a processor, processing that data only on your instructions to provide the Service; where you require a data processing agreement under Article 28 GDPR, we will make one available on request.
6. Artificial Intelligence and Optional Use of Your Content
The Service uses artificial intelligence. Through our routing provider (currently OpenRouter), you select the large language model or models used to process your requests, from a range that may change over time. By selecting a model, you choose which AI provider processes your content and accept that provider's terms and policies. Depending on the model and routing you choose, inference may take place outside your country, including outside the European Economic Area.
AI transparency. When you interact with your agent, you are interacting with an artificial intelligence system, and its replies and outputs are AI-generated. Where required by Article 50 of Regulation (EU) 2024/1689 (the EU AI Act), the Service informs persons interacting with the agent that they are interacting with an AI system and identifies AI-generated content as such. If you deploy the agent toward your own staff, clients, or other recipients, you are responsible for any additional transparency obligations that apply to that use, as set out in our Terms of Service.
By default, we do not use your conversations, prompts, or the agent's replies to train or improve our models or services beyond what is necessary to operate the Service for you, and we require our providers, where contractually available, not to use your content to train their general models.
Optional improvement and human review. If you expressly opt in (for example through a setting in your dashboard), you agree that we may use your conversations, prompts, and the agent's replies to develop, evaluate, and improve the Service, including by means of human review of those conversations by authorized personnel. You may withdraw this consent at any time, which stops future use of your content for this purpose but does not affect activities already carried out. This optional use does not apply to data received through the Slack API (see Section 7).
7. Slack
When you install and use John CEO in Slack, we access and process Slack data through Slack OAuth and the Events API, limited to what is needed to operate the agent and carry out the requests made in Slack.
Slack data we access. Through OAuth we receive workspace and team identifiers, the bot token needed to operate the integration, and (on install) a user token for Slack MCP tools granted by the installer in the same authorization step. Through the Events API we receive channel identifiers, user identifiers, and the text of messages, direct messages, and thread replies in channels or conversations where you add or mention the agent, plus files you ask the agent to process.
Permission-aware search. When the agent needs broader workspace context, we call Slack's assistant.search.context API. Where Slack provides an action_token with the event, we include it so search results respect your existing Slack permissions and never surface content you could not otherwise see. Results are injected as ephemeral context into your organization's private agent VM for the current task and are not stored long-term on the control-plane bridge.
Storage and isolation. Message processing occurs on your private agent VM. Our control plane does not retain your Slack chat transcripts. Per-workspace bot and installer user tokens are encrypted at rest (AES-256-GCM). Slack workspace credentials, Composio connection credentials, and Slack MCP credentials are scoped per user and per organization (workspace); they are not shared across customers.
No use of Slack data for model training. We do not use Slack data to develop, improve, or train any generalized artificial-intelligence or machine-learning models, and we do not use Slack data for advertising. For content received through Slack, we use AI providers under terms that do not permit them to train on or retain your content. The optional improvement and human review described in Section 6 does not apply to Slack data.
Revoking access. You can uninstall John CEO or revoke its access at any time from Slack (App Management or your workspace admin). After revocation, we stop collecting new Slack data and invalidate the associated bot token; previously stored data is deleted in accordance with Section 10.
8. Cookies and Tracking
We use cookies and similar technologies for security, operation, preferences, and analytics, including the analytics tools listed in Section 4. Most browsers let you remove or reject cookies; doing so may affect some features. We do not currently respond to "Do Not Track" signals.
Email tracking. Our service and marketing emails may contain a small tracking pixel and tracked links that tell us whether you opened a message or clicked a link, so we can measure deliverability and engagement. Where required, we rely on your consent for this and you can object at any time using the unsubscribe link or by contacting us. Messages opened in plain-text or image-blocking clients will not be tracked.
9. International Data Transfers
We are established in Spain. Your private agent VM and the data on its persistent volume are hosted in Hetzner datacenters. Some processing occurs outside the European Economic Area: this includes your agent workload and AI inference through the model provider and routing you select, which may take place in the United States or other regions, and certain vendors may process limited data outside the EEA. Where we transfer personal data to a country without an EU adequacy decision, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses. Some transfers result from your own choice of AI model: where you select a model or routing under which inference takes place outside the EEA, including in a country without an adequacy decision, we inform you of this in the product where practicable, and your selection constitutes your documented instruction to route the relevant content to that provider for processing, for data for which you act as controller and we act as your processor. Slack data is handled as described in Section 7.
10. Data Retention
We keep personal information only as long as needed to provide the Service, meet our legal and contractual obligations, and resolve disputes. When you close your account or make a valid deletion request, we delete your content and agent volume from active production systems, typically within approximately 30 days. Encrypted backups age out on their normal rotation (currently approximately 35 days). Where deletion is not immediately possible, we isolate the information from further processing until deletion occurs. Account and billing records may be retained for the period required by applicable law.
11. Security
Each active agent runs on its own isolated cloud computer with its own persistent volume, rather than in a shared runtime where customer data mixes. We use encryption in transit and at rest, role-based access controls, and a control-plane model in which sensitive platform credentials are not stored on your agent and your agent receives only scoped credentials for your account. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your own account and credentials secure.
12. Minors
The Service is intended for business use by adults. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will deactivate the account and delete the data. Contact us if you believe a minor has provided personal information.
13. Your Privacy Rights
Depending on where you live, you may have rights to request access to, correction of, or deletion of your personal information, to restrict or object to certain processing, to data portability, and to withdraw consent. To exercise any of these, contact us at [email protected]. We will act on requests in accordance with applicable law.
For information the agent accesses from your connected tools, requests from the underlying individuals (for example your own contacts or clients) should be directed to you, since you control that data and authorized its access; we will assist you as reasonably required.
Supervisory authority. In Spain, the lead supervisory authority is the Agencia Española de Protección de Datos (AEPD, www.aepd.es). If you are located elsewhere in the EEA, you may lodge a complaint with your local supervisory authority.
Marketing. You can opt out of marketing messages at any time via unsubscribe links or by contacting us. You will still receive essential service messages.
14. Updates to this Policy; Severability
We may update this Policy from time to time. The "Last Updated" date reflects the most recent revision. For material changes, we will provide notice by appropriate means. Continued use after the changes take effect indicates acceptance.
If any provision of this Policy is held invalid, illegal, or unenforceable, that provision will be applied to the greatest extent permitted by applicable law or, where that is not possible, treated as severed. This does not invalidate this Policy as a whole, and the remaining provisions continue in full force and effect. Nothing in this Policy limits any rights you have under mandatory applicable law, including the GDPR.
15. Contact
JHELY GLOBAL SL
Paseo de la Sierra 29, 29018 Málaga, Spain
CIF: B67973388
Email: [email protected]