Skip to main content
Lonia AI
Pallas by Lonia AI
  • Home
  • About
  • Features
  • Guide
  • Pricing
  • Procurement
  • Resources
  • Contact
  • Free Scan
  • Sign in

LEGAL

Privacy Policy

Last updated: 15 September 2026

This Privacy Policy describes how Lonia AI ("Company", "we", "us") collects, uses, and protects personal information through Pallas by Lonia AI ("Service"). It is written to be read by the people who actually have to read it: procurement reviewers, IT administrators, and the individuals whose data we hold. Every right you have is named in plain English, with the legal reference in brackets, and section 8 tells you exactly how to use it.

Pallas is sold to organizations, not to consumers. If you use Pallas, you belong to at least one organization. That distinction matters for who controls what, and section 1 sets it out.

On this page

  • 1. Who we are, and who controls your data
  • 2. Information we collect
  • 3. How we use your information, and our legal basis
  • 4. Data retention
  • 5. Data security
  • 6. Sub-processors
  • 7. Your rights, by jurisdiction
  • 8. How to exercise your rights
  • 9. International data transfers
  • 10. Representatives, and what we have not appointed
  • 11. Children's privacy
  • 12. Cookies
  • 13. Changes to this policy
  • 14. Contact

1. Who we are, and who controls your data

Two different parties control two different sets of data inside Pallas, and knowing which is which tells you where to send a request.

  • Lonia AI is the data controller for your personal profile data. That is the information identifying you as a person: your name, your email address, your profile photo, your organization memberships, your billing contact details, and the marketing contact record we hold if you gave us an email address for a free scan, a resource download, or the newsletter. Requests about this data come to us at support@lonia.ai.
  • Each customer organization is the data controller for its own scan and compliance data. That is the content the organization puts into Pallas and the records Pallas produces from it: web and document assets, scan results, findings, evidence uploads, reports, exceptions, and the organization's audit trail. For that data Lonia AI acts as a processor on the organization's instructions, governed by our Data Processing Agreement. If your request concerns that data, your organization's administrator is the right first stop, and we assist them as the DPA requires.

If you are not sure which category your request falls into, write to us anyway. We would rather route it for you than have you guess.

1.1 Where to write

  • Privacy requests and data subject rights, general support, Data Processing Agreements, transfer paperwork, and sub-processor change notices: support@lonia.ai. Put "Privacy request" in the subject line for anything in section 7 or section 8.

1.2 Internal privacy contact

We have not appointed a Data Protection Officer. Article 37 of the GDPR requires one only where an organization is a public authority, carries out large-scale systematic monitoring, or processes special categories of data on a large scale, and none of those describe us. We are not going to attach a formal job title to a role we have not created. Privacy requests are handled by our internal privacy contact, reachable at support@lonia.ai. If our processing changes so that a Data Protection Officer becomes mandatory, we will appoint one and publish the contact route here.

2. Information we collect

2.1 Account information

When you create an account via OAuth, we receive your name, email address, and profile photo from your authentication provider (Google or Microsoft), along with your organization name. We do not store passwords.

2.2 Usage data

We collect information about how you use the Service: scans initiated, findings created, and reports generated, as recorded in your organization's audit trail. This data is used to provide the Service.

2.3 Uploaded content and scan targets

You may submit website URLs and upload documents (PDF, DOCX, and PPTX files) for accessibility analysis. Uploaded documents are analyzed and discarded by default. URLs are stored as asset records. Scan results and findings derived from analysis are stored according to your organization's retention policy, which defaults to 365 days for scan data.

2.4 Marketing and free-scan email capture

If you run a free scan, subscribe to updates, or download a resource, we collect the email address you provide and, where applicable, the URL you asked us to scan. We use that address to deliver the item you asked for: the scan report you request, or the file you are downloading. That is a separate thing from our mailing list.

Delivery and marketing are not bundled. Running a scan does not add you to our mailing list, and neither does downloading a resource. Each of those forms carries its own tick box for accessibility-compliance updates, and so does the newsletter form on our home page. The box is unticked when you arrive. On the scan and download forms, ticking it is not required to submit, and on the free-scan page nothing is sent to our mailing-list service at all unless you tick it. On the newsletter form the box is the whole of what you are asking for, so nothing is sent there either unless you tick it. All three forms post to the same service, record the same moment of consent, and are covered by the same unsubscribe. You can unsubscribe at any time using the link in any marketing email, or by writing to support@lonia.ai.

A boundary worth knowing. Marketing email is a separate system from your Pallas account. Deleting your account in the application does not remove a marketing contact record, because the two are not the same store. Unsubscribe, or write to support@lonia.ai, and we will remove it. We are telling you this because the two look like one system from the outside and they are not.

What unsubscribing actually does. The unsubscribe link at the foot of an email opens a page that asks you to confirm. Confirming removes your address from the mailing list straight away: the enrolment records are deleted rather than flagged, and if you had enrolled from more than one form, every one of those records goes, not just the one the link came from. We ask for the confirming click rather than acting on the link itself because mail security scanners and inbox previews open links on their own, and without that step one of them could unsubscribe you from a message you never opened. Your mail client's own unsubscribe button, where it has one, works in a single action.

What we keep afterwards, and why. After the removal we hold a one-way SHA-256 fingerprint of the address, and not the address itself. It exists for one purpose: to stop a later form submission from putting you back on a list you have just left. It is the only record of you that survives an unsubscribe, it cannot be turned back into your address, and it is not used to contact you or to recognise you anywhere else. If you would rather we did not keep even that, write to support@lonia.ai and ask us to remove it, and know that once it is gone a future form submission carrying your address could enrol you again. If a link does not work, or the address you want removed is not the one you are writing from, tell us at the same place and we will do it by hand.

2.5 How the free scan retrieves a page

The free scan does not fetch the page itself from your browser. The URL you enter is sent to a proxy we operate on Cloudflare's network, which requests the page from the target server and returns the HTML to your browser. For that initial request the target server sees our infrastructure rather than you, and we receive the URL you asked us to scan. The page is then analyzed inside an isolated sandbox in your browser: the page content is not stored on our servers, and only the summary counts and the top issues are sent onward so we can email you the report. Cloudflare is listed as a sub-processor on our sub-processors page.

What the proxy covers. Only the page document is proxied. The sandbox that analyses it carries a Content-Security-Policy that blocks every external image, stylesheet, font, and script the page references, so the servers hosting those resources receive no request from your browser during the scan.

3. How we use your information, and our legal basis

We use your information to: provide and maintain the Service; process scans and generate accessibility reports; manage your account and subscription; send transactional emails (account notifications, billing receipts); send marketing email where you have requested it; and improve the Service based on aggregate usage patterns. We do not use your data to train AI models. We do not sell your data.

Where the EU or UK GDPR applies, we rely on the following legal bases under Article 6: performance of a contract (to provide the Service you have signed up for); legitimate interests (to secure, maintain, and improve the Service, and to prevent abuse), balanced against your rights; and consent (for marketing email and any optional processing), which you may withdraw at any time without affecting the lawfulness of what we did before you withdrew it. Consent here means a specific affirmative act: an unticked box you chose to tick, on whichever of our forms you were using, including the newsletter form. We do not treat the use of a free tool as consent to marketing, and we do not make delivery of anything conditional on agreeing to receive it, which is what Article 7(4) requires of us.

4. Data retention

Uploaded source documents: analyzed and discarded by default. Organizations can configure custom retention policies in the Service. Scan results and findings: retained for the duration of your subscription plus 30 days post-cancellation. Account information: retained for the duration of your subscription plus 30 days post-cancellation. Audit trail entries: retained in accordance with your organization's configured retention policies, subject to a regulatory retention floor that administrators cannot set below. Marketing contacts: retained until you unsubscribe. After you unsubscribe, the address and its enrolment records are deleted, and a one-way SHA-256 fingerprint of the address is kept on a suppression list with no end date, so that a later form submission cannot re-enrol you by accident. That fingerprint is the only thing that outlives an unsubscribe, and section 2.4 explains how to have it removed as well.

5. Data security

We implement the following security measures: OAuth-only authentication (no password storage); TLS encryption for all data in transit and database-level encryption for data at rest, both provided by Supabase and Cloudflare; row-level security (RLS) enforcing organization-level data isolation; a tamper-evident append-only audit log (SHA-256) in which any modification, deletion, or reordering of history is detected; and regular security reviews and dependency updates. The audit trail section of our Trust page sets out how the chain is enforced, how lawful erasures are recorded as redaction entries, and how anchors can be exported for independent verification. Our Trust page also sets out which of these we can demonstrate from a published artifact and which are our assertion about the application, which is a separate system from this website.

6. Sub-processors

We use vetted sub-processors to operate the Service. The current list, including each sub-processor's purpose, data categories, and location, is published on our Sub-processor page. We notify customers before adding a new sub-processor, as described there.

7. Your rights, by jurisdiction

The rights you hold depend on where you are. Below, each jurisdiction gets its own list, every right is named, and every entry says how you use it: a self-service control in the application, or an email to us. Where there is no self-service control, we say so rather than pointing you at a button that does not exist.

Two controls are referenced throughout, and both live in the Pallas application under Settings, then Data Privacy:

  • Export your data. Produces a machine-readable JSON download of the data we hold that is associated with your account. Nothing is deleted by exporting.
  • Delete your account. Permanently and immediately deletes your account. The erasure entry below sets out what it removes, what it does not, and the one case in which it will refuse.

Exercising any right is free. We do not charge a fee, and we do not treat you differently for asking.

7.1 European Union and United Kingdom (GDPR and UK GDPR)

If you are in the EU, we process your personal data under the General Data Protection Regulation (Regulation (EU) 2016/679). If you are in the UK, we process it under the UK GDPR and the Data Protection Act 2018. The rights are the same in substance; the supervisory authority differs.

  • Right of access [Article 15]. You can ask what personal data we hold about you, why we hold it, who we share it with, and how long we keep it. How: use Export your data in the application, or email support@lonia.ai if you would rather we compiled it for you.
  • Right to rectification [Article 16]. You can correct personal data about you that is wrong or incomplete. How: edit your profile in the application, or email support@lonia.ai for anything you cannot edit yourself.
  • Right to erasure, also called the right to be forgotten [Article 17]. You can have your personal data deleted. How: use Delete your account in the application, or email support@lonia.ai. The limits are set out immediately after this list, and we would rather you read them before you press the button than after.
  • Right to data portability [Article 20]. You can receive your data in a structured, commonly used, machine-readable format and move it elsewhere. How: use Export your data in the application. The export is JSON.
  • Right to restriction of processing [Article 18]. You can ask us to keep your data but stop using it, for example while a dispute about accuracy is resolved. How: email support@lonia.ai. There is no self-service control for this one. It is rarely requested and it needs a person to agree the scope before we apply it, so we would rather handle it properly by email than ship a button that does something approximate.
  • Right to object [Article 21]. You can object to processing we carry out on the basis of legitimate interests, and you can object to direct marketing at any time with no reason required. How, for marketing: use the unsubscribe link in any marketing email we have sent you, or email support@lonia.ai. We stop, and we do not ask you to justify it. How, for anything else: email the same address and tell us what you are objecting to.
  • Right to withdraw consent [Article 7(3)]. Where we rely on your consent, you can withdraw it at any time, and it is as easy to withdraw as it was to give. In practice we rely on consent only for marketing email. How: unsubscribe from any marketing email, or email support@lonia.ai. Withdrawing consent does not make our earlier processing unlawful, and it does not affect the contract-based processing that runs your account.
  • Right not to be subject to automated decision-making [Article 22]. Pallas makes no automated decisions that produce legal effects concerning you or that similarly significantly affect you. Scans, findings, severity ratings, and compliance readiness scores are advisory outputs about a website or a document. They are not decisions about a person, they gate access to nothing, and no profiling of you feeds them. There is nothing here to opt out of, and we would rather say that plainly than leave the section blank.
  • Right to lodge a complaint [Article 77]. You can complain to your data protection authority, and you can do it without contacting us first. In the EU: the European Data Protection Board publishes a directory of every member state authority at edpb.europa.eu ↗ (opens in a new tab). In the UK: the Information Commissioner's Office at ico.org.uk ↗ (opens in a new tab). We would like the chance to fix it first, but that is a preference of ours, not a precondition on you.

Limits on erasure, stated plainly

The right to erasure is not absolute. Here is exactly where its edges are.

  • If you are the sole administrator of an organization, we cannot delete your account until you either promote another administrator or delete the organization itself. This prevents orphaned organizations that no one can manage. The application refuses the deletion and tells you which of those two steps to take. Nothing is deleted in the meantime, and you can come straight back to it once the organization has another administrator.
  • Audit records survive. Audit events recording actions you took against an organization are not deleted with your account. They are retained to the regulatory retention floor and then purged. That is deliberate: an audit trail a departing user can erase is not an audit trail, and the moment someone most wants those records gone is the moment an administrator most needs them. This is the Article 17(3)(b) and 17(3)(e) carve-out, for compliance with a legal obligation and for the establishment or defence of legal claims.
  • Billing records survive. Invoices and payment records are retained for the period tax and accounting law requires.
  • Marketing contact records are separate. As described in section 2.4, deleting your account does not remove a marketing contact record. Unsubscribe, or ask us, and we will remove it.

Deleting your account is permanent and immediate. It cannot be undone, and we cannot restore an account or its contents afterwards. If you want a copy of your data, run Export your data first.

Our other GDPR commitments

We provide the information required by Articles 13 and 14 through this policy. In the event of a personal data breach we notify the competent supervisory authority in line with Article 33 (within 72 hours where we are the controller) and we support controllers in meeting their own Article 33 and Article 34 obligations. Where we act as a processor for your organization, we assist that organization with data subject requests as described in our Data Processing Agreement. Cross-border transfers rely on the European Commission's 2021 Standard Contractual Clauses, together with supplementary measures. Section 9 has the detail.

7.2 Ireland

Ireland is an EU member state, so everything in section 7.1 applies to you in full: access, rectification, erasure, portability, restriction, objection, withdrawal of consent, freedom from automated decisions with legal effect, and the right to complain. Nothing is reduced.

Your supervisory authority is the Data Protection Commission, at dataprotection.ie ↗ (opens in a new tab). Because Ireland is our EU reference point, the Data Protection Commission is the authority we engage with first on EU data protection matters. If you are in another member state you may still complain to your own authority instead.

7.3 California (CCPA as amended by the CPRA)

If you are a California resident, you have the rights below. We do not charge for exercising them, and you do not need an account to make a request.

  • Right to know and right to access. You can ask what categories of personal information we have collected about you, where it came from, why we collected it, and who we disclosed it to, and you can request the specific pieces. How: use Export your data in the application, or email support@lonia.ai.
  • Right to delete. You can ask us to delete the personal information we collected from you, subject to the statutory exceptions such as records we must keep for tax purposes or to defend a legal claim. How: use Delete your account in the application, or email support@lonia.ai. The limits in section 7.1 apply here too.
  • Right to correct. You can have inaccurate personal information corrected. How: edit your profile in the application, or email support@lonia.ai.
  • Right to opt out of the sale or sharing of personal information. Pallas does not sell personal information, and does not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We have never done so and we have built no mechanism that could. There is therefore nothing for you to opt out of, and you will not find a "Do Not Sell or Share My Personal Information" link on this site because there is no sale or sharing to stop. If that ever changes, we will publish the link and the notice the law requires before it takes effect, not after.
  • Right to limit the use of sensitive personal information. Pallas does not use or disclose sensitive personal information for any purpose beyond the ones the law permits without a right to limit, which here means providing the Service you asked for, keeping it secure, and preventing fraud. We do not use it to infer characteristics about you and we do not use it for advertising. There is no secondary use for you to limit.
  • Right to non-discrimination. We will not deny you the Service, charge you a different price, give you a lower quality of service, or penalize you in any other way for exercising any of these rights. There is no financial incentive program attached to your data.
  • Authorized agents. You may use an authorized agent to make a request on your behalf. We will ask for written proof of the agent's authority and, where the law permits, ask you to verify your identity directly.

7.4 Other United States residents

There is no single comprehensive federal privacy law in the United States, so your rights depend on your state of residence. Residents of states with comprehensive privacy laws, including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, and other laws as they take effect, have rights closely comparable to the California list above: to confirm processing and access their data, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and certain profiling. We do not sell personal data, we do not carry out targeted advertising, and we do not profile individuals for decisions producing legal or similarly significant effects, so those opt-outs have nothing to act on here. Several of these laws also give you a right to appeal a refused request. If we refuse a request, we will tell you why and tell you how to appeal.

At the federal level, the Federal Trade Commission has authority to act against unfair or deceptive data practices under Section 5 of the FTC Act. You may also contact your state Attorney General. To exercise a right, use the self-service controls or email support@lonia.ai.

7.5 Australia (Privacy Act 1988 and the Australian Privacy Principles)

If you are in Australia, we handle personal information under the Privacy Act 1988 and the Australian Privacy Principles.

  • Right to access your personal information [APP 12]. You can ask for the personal information we hold about you. How: use Export your data in the application, or email support@lonia.ai. Related to this, under APP 6 we use and disclose your personal information only for the purposes described in this policy or as APP 6 otherwise permits.
  • Right to correct your personal information [APP 13]. You can have personal information corrected where it is inaccurate, out of date, incomplete, irrelevant, or misleading. How: edit your profile in the application, or email support@lonia.ai. If we decline to correct something, we will tell you why in writing, and you may ask us to attach a statement recording that you consider it inaccurate.
  • Right to opt out of direct marketing [APP 7]. You can ask us to stop using or disclosing your personal information for direct marketing, and you can ask us where we got your information from. How: use the unsubscribe link in any marketing email, or email support@lonia.ai. We act on the request without charge and confirm when it is done. We send marketing email only where you have opted in, by ticking the box on a scan, download, or newsletter form, and never as a by-product of using the free scan.
  • Right to complain. Complain to us first at support@lonia.ai. If you are not satisfied with how we handle it, complain to the Office of the Australian Information Commissioner at oaic.gov.au ↗ (opens in a new tab).

Our other commitments under the Australian Privacy Principles: we are transparent about how we handle personal information (APP 1); we notify you of collection and its purposes (APP 5); before disclosing personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the APPs, including through Standard Contractual Clauses (APP 8); and we secure personal information and destroy or de-identify it when it is no longer needed (APP 11). We participate in the Notifiable Data Breaches scheme. Assessment and notification are two separate steps with two separate clocks: where we suspect an eligible data breach we complete our assessment within 30 days of becoming aware, and where that assessment leads us to believe an eligible data breach has occurred we notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, which for customer data means within the 72 hours stated on our Trust page rather than at the end of the assessment window. Nothing in our terms excludes, restricts, or modifies any non-excludable guarantee, right, or remedy you have under the Australian Consumer Law.

7.6 Canada (PIPEDA), including Quebec

If you are in Canada, we handle personal information under the Personal Information Protection and Electronic Documents Act.

  • Right to access [PIPEDA Principle 9, Individual Access]. You can ask what personal information we hold about you, how it has been used, and to whom it has been disclosed. How: use Export your data in the application, or email support@lonia.ai.
  • Right to challenge accuracy [PIPEDA Principle 9]. You can challenge the accuracy and completeness of the personal information we hold and have it amended where it is wrong. How: edit your profile in the application, or email support@lonia.ai. If we do not agree with your challenge, we record the substance of the unresolved challenge alongside the information.
  • Right to withdraw consent [PIPEDA Principle 3, Consent]. You can withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. In practice this applies to marketing email. How: unsubscribe from any marketing email, or email support@lonia.ai. We will tell you what withdrawing consent means for the Service before we act on it.
  • Right to challenge our compliance [PIPEDA Principle 10]. You can challenge our compliance with these principles by writing to our internal privacy contact at support@lonia.ai, and you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca ↗ (opens in a new tab).

We do not currently serve Quebec customers. This section is preserved for when we do. Quebec residents who reach us should email support@lonia.ai; we will honor requests on a best-effort basis in English.

A limit we will state rather than let you discover. Pallas, this policy, and the application are currently published in English only. French-language versions are not yet available. We say so here because language affects both Quebec's requirements and whether a policy is genuinely readable by the person it governs, and we would rather you knew that before signing than after.

7.7 Everywhere else

If you are somewhere not named above, we process your personal data to standards consistent with the GDPR as a global baseline, and we will honor an access, correction, deletion, or portability request on the same terms and in the same timeframe. Write to support@lonia.ai. If your local law gives you a right this policy does not name, tell us which one and we will honor it and add it here.

8. How to exercise your rights

Two routes, depending on whether you have an account. Both end in the same place.

8.1 If you have a Pallas account

  1. Sign in at app.pallas.lonia.ai.
  2. Go to Settings, then Data Privacy.
  3. For an access or portability request, use Export your data. You get a machine-readable JSON download of the data associated with your account. Nothing is deleted by exporting.
  4. For an erasure request, use Delete your account. This is permanent and immediate: it cannot be undone, and we cannot restore the account afterwards. Export first if you want a copy. If you are the sole administrator of an organization, the deletion will refuse and tell you to promote another administrator or delete the organization first.
  5. To correct your profile information, edit it in Settings.
  6. For anything else, including restriction of processing, an objection, a complaint, or a request you would rather a person handled, email support@lonia.ai.

No support ticket is required for the self-service controls, and there is no waiting period on them. The buttons are inside the app.

8.2 If you do not have an account but we hold your data

This covers a free scan you ran, a resource you downloaded, or a newsletter you subscribed to.

  1. Email support@lonia.ai from, or naming, the email address you used with us, and describe what you want: a copy of your data, a correction, deletion, or removal from marketing.
  2. We may ask a question or two to confirm the request really comes from you. We will not ask for a government identity document to service a record that is only an email address, because collecting more personal data in order to honor a privacy request is the wrong trade.
  3. We respond within 30 days of a verified request.

8.3 How long we take

We respond to a verified request within 30 days. If your request is complex, or you have made a number of requests, we may extend that by up to two further months, which is three months in total, or roughly 90 days. If we need the extension we will tell you inside the first month and explain why, which is what Article 12(3) of the GDPR requires and what we will do in every jurisdiction rather than only in the one that mandates it. If we refuse a request, we will tell you why, how to appeal to us, and how to complain to your supervisory authority.

Every right on this page is enforceable end to end.

The Delete your account button in the application is the same right you would email us to invoke. We have not listed a right here that we cannot deliver, and where a right has no self-service control we have written "email us" rather than implying a button that is not there.

9. International data transfers

The Service is currently hosted in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States and other countries where our sub-processors operate. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, together with supplementary measures consistent with the Schrems II decision. Where the UK-EU adequacy decision is in force we may additionally rely on it for transfers between the UK and the EEA, but we do not rely on it alone: the Standard Contractual Clauses stand on their own and are unaffected by that decision's renewal schedule. You may request a copy of the relevant transfer mechanism by contacting support@lonia.ai.

One distinction worth keeping in mind: data residency means your data is stored on servers in a stated region, while data sovereignty means it is subject only to that region's law. Because Lonia AI is a US-registered company, US legal process may apply to our records regardless of storage region. Our Trust page sets out the residency options in full.

10. Representatives, and what we have not appointed

We have not appointed an EU representative under Article 27 of the GDPR, a UK representative under Article 27 of the UK GDPR, or an Australian representative. We are not going to name one we do not have. Data subjects and supervisory authorities can reach us directly at support@lonia.ai, and we answer.

Article 27 requires a representative where a controller or processor outside the EU offers goods or services to people in the EU or monitors their behaviour, and it exempts processing that is occasional, does not involve large-scale processing of special category data, and is unlikely to result in a risk to people's rights and freedoms. Whether that exemption covers us is a judgment that turns on how our processing develops, and we would rather describe the position than assert a conclusion in our own favour on a public legal page. Our position today: no representative is appointed, we keep the requirement under review, and we will appoint one and publish the name and address here when our processing crosses the threshold or when a customer contract requires it. If a representative appointment is a condition of your procurement sign-off, raise it at support@lonia.ai and we will address it in the agreement rather than leave you to infer our position from silence.

11. Children's privacy

The Service is not directed to children under 18. We do not knowingly collect information from children under 18.

12. Cookies

Our use of cookies and similar technologies is described in our Cookie Policy. The marketing site sets no advertising or analytics cookies.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 30 days before they take effect. The date at the top of this page is the date of the version you are reading.

14. Contact

Privacy inquiries and data subject requests, general support, accessibility-related concerns, and Data Processing Agreement, Standard Contractual Clauses, and transfer paperwork: support@lonia.ai. This is also the address for our internal privacy contact. For accessibility, see also our Accessibility Statement.

A full directory of our published addresses, and what each one is for, is on our contact page.

Pallas by Lonia AI From scan to resolution.
  • Features
  • Pricing
  • Procurement
  • Compliance Guide
  • About
  • Contact

© 2026 Lonia AI