Privacy Policy
Last updated: September 15, 2026
1. Who is responsible
Eas Era Inc, operating Maya AI, is responsible for the personal data it processes for its own business purposes. Our address is 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Contact us at team@withmaya.ai with "Privacy" in the subject line.
This notice covers our website visitors, account users, business contacts, prospects, and individuals whose information we process as a controller. It also explains how customer workspaces and integrations affect personal data. It does not itself constitute consent, a waiver of your rights, or a contract authorizing unrelated processing.
When a business customer determines why and how personal data is processed through a workspace, Maya generally acts as that customer's processor or service provider for that processing. The customer's notice and the applicable data processing agreement govern that relationship. Maya separately acts as controller for its own account administration, billing, security, and business communications. If your request concerns data controlled by a customer, we will direct it to that customer or assist under our agreement and applicable law.
2. Information and sources
The information involved depends on the features you use. We obtain it from you, your organization and authorized users, connected services you authorize, your device's interactions with Maya, and sources used in the requested analysis.
- Account and professional information: name, email, organization, role, profile information, workspace membership, invitations, and account preferences. Sign-in may involve a one-time email code or an identity provider such as Google. We receive authentication and session information needed to provide access.
- Billing and transaction information: billing contact, address, tax information where relevant, plan, invoices, payment status, and payment-provider references. Payment details are submitted through the applicable payment provider; the information Maya receives depends on the checkout method.
- Customer Content: prompts, brand information, uploaded materials, website URLs, documents, project settings, generated drafts, reports, AI answers, and communications submitted to the Services. These can contain personal data even when intended as business information.
- Connected-service information: data and permissions you authorize from analytics, search-console, website, commerce, publishing, and other integrations; connection identifiers and tokens needed to maintain the connection. A connector does not automatically authorize unrestricted access to all information in the external account.
- Technical and usage information: IP address, browser and device information, requested pages, timestamps, service events, error records, authentication events, and API or MCP activity. Security and operational logs can contain personal data.
- Customer-site analytics: where a customer enables traffic or visitor analytics, event information may include session identifiers, page URLs, referrers, timestamps, device/browser information, and event attributes. The customer determines the deployment and must provide its own notice and any required consent. This is separate from measuring AI-generated responses or filtered crawler traffic.
- Support and business communications: messages, attachments, meeting or demonstration details you provide, request history, and communication preferences.
- Public-source and AI-response information: public web pages, source links, business information, and AI responses gathered for the requested analysis. Public availability does not remove applicable privacy obligations. Contact us if information about you is inaccurate or should not be processed.
- Optional measurement information: when authorized, analytics and advertising tools may process online identifiers, page interactions, attribution information, and conversion events. See Section 7.
We do not request special-category data, government identifiers, full financial-account credentials, children's data, or other highly sensitive personal information for ordinary use. Do not place these in prompts or uploads unless a specifically agreed service lawfully supports that processing. If unnecessary sensitive data is submitted, we may restrict or remove it and work with the customer to address it.
3. Purposes and legal grounds
We use information only for the relevant service and business purposes. Where GDPR or similar laws apply, the applicable ground depends on the activity and our relationship with the individual:
- To create accounts, authenticate users, deliver requested analytics and outputs, and support customers: performance of a contract where the individual is a party, or legitimate interests in delivering the customer's business service where the individual acts for an organization.
- To manage subscriptions, collect authorized payments, handle refunds, and keep records: contract performance, compliance with applicable accounting and tax obligations, or legitimate interests in business administration as appropriate.
- To secure accounts, investigate misuse, diagnose failures, and maintain reliability: legitimate interests in protecting the Services and users, and applicable legal obligations. Those interests must be balanced against individuals' rights.
- To respond to inquiries and manage business relationships: steps requested before a contract, contract performance, or legitimate interests in handling business communications.
- To evaluate and improve functionality: legitimate interests in maintaining useful, reliable Services, using minimized data. This purpose does not authorize training AI models on Customer Content.
- To send promotional communications or operate optional tracking: consent where required, or another lawful ground only where the specific activity is permitted without consent. You may unsubscribe from promotional email; necessary service, security, and billing messages are separate.
- To establish or defend legal claims, respond to valid legal demands, and meet applicable duties: legal obligations or legitimate interests in protecting legal rights, as appropriate.
Where consent is the basis, you may withdraw it without affecting the lawfulness of earlier processing. Withholding information necessary for an account, payment, or requested feature can prevent us from supplying that feature. Optional marketing permission is not a condition of using the core service.
4. AI processing and model training
We do not use customer data, including Customer Content, to train AI models. Running prompts through models to deliver an analysis, answer, or generated draft is inference, not model training.
The features you request may require sending relevant prompts, content, or context to AI service providers. Do not include personal or confidential information that is unnecessary for the task. An AI provider's identity, processing location, retention settings, and contractual restrictions depend on the service arrangement. A no-training commitment does not mean that no provider receives data, that all processing stays in one country, or that all providers offer zero retention.
Maya's no-training commitment is not permission for a provider to train on your Customer Content. Provider arrangements must support the agreed use and applicable data-protection obligations. Request details about the providers and safeguards relevant to your workspace before submitting information subject to special contractual restrictions.
AI-generated analysis may contain errors or inferences about a person. We provide business analysis and content tools; the ordinary Services are not intended to make solely automated decisions producing legal or similarly significant effects about individuals. Customers must not use them for such decisions without an appropriate, separately assessed lawful basis and safeguards.
5. Who receives information
Access and disclosure are limited to relevant purposes:
- Authorized colleagues, administrators, and client users can access workspace information within their permissions. Shared links, exports, and publishing actions can disclose information to recipients you select.
- Hosting, database, storage, delivery, security, email, support, and payment providers process information necessary for their functions. AI and data-analysis providers receive information necessary for requested features. Providers acting on our instructions must be subject to appropriate confidentiality, security, and processing restrictions.
- An integration, assistant, or MCP client you connect receives information within the permissions and actions you authorize. That provider may act independently under its own notice once it receives the information.
- Professional advisers, auditors, and insurers may receive information as needed under appropriate duties of confidentiality.
- Authorities or other parties may receive information when required by law or reasonably necessary to investigate unlawful conduct, protect safety, or establish or defend legal rights. We assess the scope and legitimacy of requests.
- A potential or actual acquirer or successor may receive relevant information during a business transaction, subject to safeguards and applicable notice obligations.
A payment provider or identity provider may act as an independent controller for some functions, such as compliance and fraud prevention. Referring to its own privacy notice does not remove Maya's responsibility for Maya's disclosures.
Contact us for the current providers, processing locations, and applicable DPA for your service. The public names of AI platforms we monitor are not, by themselves, a complete list of subprocessors: a monitoring target and a vendor processing your information can be different entities.
6. International processing
Maya is operated by a United States company. Personal data may be processed in the United States and in other countries where authorized personnel and service providers operate. The applicable countries and protections must be assessed for the relevant service and any agreed residency restrictions. We do not make a blanket promise that all Maya data stays in Türkiye or any other single country.
Where a transfer is subject to GDPR, UK GDPR, KVKK, or another transfer restriction, a legally valid transfer mechanism must be in place before that transfer. Depending on the circumstances, this may involve an applicable adequacy decision, the relevant standard contractual clauses and transfer assessment, a UK transfer instrument, or another lawful mechanism. This notice and your continued use are not substitutes for those safeguards and do not constitute blanket transfer consent.
You may ask us which countries and safeguards apply to your data and request a copy or explanation of relevant safeguards, subject to necessary redaction. EU standard clauses do not, by themselves, satisfy separate KVKK transfer requirements. Any contractual commitment to a particular hosting location must be documented expressly and supported by the actual processing arrangements.
7. Cookies, analytics, advertising, and choices
We use necessary cookies or similar storage for authentication, security, and remembering privacy choices. Optional analytics and advertising measurement are separate purposes. The website contains integrations for Google measurement tools and, where configured, OpenAI advertising measurement. Optional tools must be enabled only in accordance with the choices you make and applicable law.
Use the cookie banner to accept or reject optional purposes. To change your choice later, use Manage cookie preferences on the Cookie Policy page. Declining optional tracking does not prevent use of the core service. Clearing browser storage may remove your saved choice. Blocking all cookies in your browser can interfere with sign-in and other requested features. See the Cookie Policy.
Advertising identifiers and activity disclosed for cross-context advertising may qualify as "sale", "sharing", or targeted advertising under certain US privacy laws, even if no money is exchanged. We therefore do not equate a no-cash-sale practice with a blanket assurance that no legally defined sharing occurs. Where these laws apply, you may opt out through the Cookie Policy’s preference control or contact us to apply a request to identifiable account-related processing. We treat a recognized Global Privacy Control signal as an opt-out of browser-based advertising sharing. We do not interpret a general Do Not Track signal as affirmative consent.
Cookie choices must also be respected by related server-side measurement. Information collected for billing or security is not automatically authorized for advertising. A customer deploying Maya analytics on its own site must configure its own consent mechanism and notices for that deployment.
8. Retention, deletion, and security
Retention depends on the information, purpose, customer instructions, applicable law, and dispute or security needs:
- Account and workspace information is retained while needed to provide the account, historical reports, and requested functions; after closure it is assessed for deletion or restricted retention.
- Customer-controlled content is returned or deleted under the relevant instructions and DPA, subject to lawful exceptions.
- Billing records are retained for applicable tax, accounting, and legal periods, which depend on the transaction and jurisdiction.
- Security logs and support records are retained for the period reasonably needed to investigate issues, maintain security, resolve requests, and protect legal rights.
- Marketing records are retained while the relationship or permission remains relevant; a minimal suppression record may be retained to honor an opt-out.
- Backups are removed through the applicable backup lifecycle; retained copies must remain protected and must not be restored for ordinary use after a valid deletion request without reapplying the deletion.
We review whether continued retention remains necessary. Legal holds and mandatory duties can justify retaining limited information after a deletion request, with access and use restricted to that purpose. We do not promise an unverified universal 24-hour deletion period or 30-day backup expiry. Contact us for retention criteria or the applicable contractual schedule.
We use technical and organizational measures appropriate to the processing risk, including access restrictions, credential controls, and protection of data in transmission and storage. No service can guarantee absolute security. We investigate personal-data incidents and provide notifications required by law and applicable customer agreements. This notice does not claim an independent certification or audit that has not been obtained.
9. How to exercise privacy rights
Depending on applicable law, you may have rights to obtain information and access, correct inaccurate data, request deletion, restrict or object to processing, receive a portable copy, withdraw consent, and opt out of certain advertising or other processing. Rights are subject to lawful conditions and exceptions, not to our unrestricted discretion.
Email team@withmaya.ai or write to our postal address. Describe the request and the email or workspace relevant to it. Do not send passwords or unnecessary identity documents. We may take proportionate steps to verify identity or an authorized agent's authority. An ordinary browser-based advertising opt-out does not require account registration.
Where GDPR applies, we respond without undue delay and normally within one month; a permitted extension of up to two further months requires notice and reasons within the initial month. You may complain to your competent supervisory authority, including the authority where you live, work, or believe an infringement occurred. You need not first obtain our permission.
Where applicable US state privacy laws apply, rights may include knowing the categories and specific personal information collected, sources, purposes and recipient categories; deletion and correction; portability; opting out of sale, sharing, targeted advertising, or certain profiling; and limits on specified sensitive-data uses. We will not unlawfully discriminate for exercising a right. Where applicable, we respond within 45 days and explain any permitted extension. You may appeal a denial by replying with "Privacy appeal"; we will follow the applicable appeal deadline and provide any required authority contact. California requests follow the applicable acknowledgment and response rules, including a 10-business-day acknowledgment where required. These provisions do not assert that every state law applies to Maya or every request.
10. Türkiye: KVKK information and rights
KVKK'nın uygulandığı işleme faaliyetlerinde veri sorumlusu, yukarıda adresi belirtilen Eas Era Inc (Maya AI) şirketidir. İletişim: team@withmaya.ai. Veriler; hesap ve iletişim formları, hizmet kullanımı, çerezler, yetkilendirdiğiniz entegrasyonlar, kuruluşunuz ve ilgili açık kaynaklar aracılığıyla elektronik ortamda, ayrıca bize ilettiğiniz yazışmalar yoluyla toplanır.
Kimlik/iletişim ve hesap verileri hizmet ve ilişki yönetimi; işlem ve fatura bilgileri ödeme ve yasal kayıtlar; kullanım ve güvenlik kayıtları hizmet güvenliği; talep ve içerikler ilgili analiz ve destek; isteğe bağlı pazarlama bilgileri izin verilen iletişim ve ölçüm amaçlarıyla işlenir. Somut faaliyete göre KVKK m.5 kapsamında sözleşmenin kurulması veya ifası için gereklilik, hukuki yükümlülük, bir hakkın tesisi/kullanılması/korunması veya temel haklara zarar vermeyen meşru menfaat şartlarından uygun olanına dayanılır. Açık rıza gereken isteğe bağlı faaliyetlerde rıza ayrıca alınır; aydınlatma metnini okumak rıza sayılmaz.
Veriler yukarıda açıklanan amaçlarla yetkili çalışma alanı kullanıcılarına, ilgili teknoloji/ödeme/destek hizmet sağlayıcılarına, danışmanlara ve hukuken yetkili makamlara aktarılabilir. Yurt dışı aktarımda KVKK m.9'daki geçerli şartlar ayrıca sağlanmalıdır; bu metin tek başına aktarım güvencesi değildir.
KVKK m.11 kapsamında verilerinizin işlenip işlenmediğini öğrenme, işlenmişse bilgi isteme, işleme amacını ve amaca uygun kullanımını öğrenme, yurt içi/yurt dışı alıcıları bilme, eksik veya yanlış verileri düzelttirme, kanuni şartlarla silinmesini veya yok edilmesini isteme ve bu işlemlerin alıcılara bildirilmesini talep etme, yalnızca otomatik analiz sonucu aleyhinize doğan sonuca itiraz etme ve kanuna aykırı işleme nedeniyle zararın giderilmesini isteme haklarınız bulunur.
Başvurunuzu yürürlükteki başvuru usullerine uygun şekilde, sistemimizde kayıtlı e-posta adresinizden yukarıdaki adrese veya yazılı olarak posta adresimize iletebilirsiniz. Başvurular en geç 30 gün içinde sonuçlandırılır. Ret, yetersiz cevap veya süresinde cevap verilmemesi halinde, cevabı öğrenmeden itibaren 30 ve her durumda başvurudan itibaren 60 gün içinde Kurula şikâyet hakkınız ilgili kanuni şartlarla saklıdır.
11. Children and changes
Maya is intended for adults using a business service, not children under 18. If you believe a child has supplied personal data, contact us so we can investigate and take appropriate action. We do not knowingly authorize sale or advertising sharing of children's personal information.
We update this notice when our practices or legal obligations change. The revision date appears above. For material changes, we provide an appropriate prominent notice and direct notification where required. If a new purpose requires consent, we obtain that consent before the relevant processing. A revised notice does not retrospectively authorize an incompatible use of previously collected information.