OOllily

Privacy Policy

Version 1.0 · Effective 19 August 2026

Plain summary. We hold your account details, your contacts and your campaigns, because that is what the product is. We do not sell any of it. You can export or delete it whenever you like. Two things outlive deletion — a record that somebody agreed to our terms, and a list of addresses that must never be emailed again — and both are explained below.

1. Who we are

Ollily operates the email marketing service at ollily.com. For data you put into the product about your contacts, you are the controller and we are the processor — you decide what to collect and why, and we handle it on your instructions. For your own account data, we are the controller.

Contact for anything on this page: privacy@ollily.com

2. What we hold, and why

Your account

Security records

What you put in

We process this to run the service for you. We do not read your campaigns or your contact lists except where we must — to diagnose a fault you have reported, to investigate abuse, or to meet a legal obligation.

3. Our lawful basis

4. Who we share it with

We do not sell your data, and we do not share it for advertising. We use a small number of processors to run the service:

Each is bound to process data only on our instructions. Some operate outside your country; where data moves internationally it is covered by the safeguards that apply to that transfer.

We may disclose data where legally compelled. Where we are permitted to tell you, we will.

5. How long we keep it

WhatHow long
Account and workspace dataUntil you delete the account
Contacts and campaignsUntil you delete them, or the account
Sessions and devicesUntil they expire or you revoke them
Audit logRetained as a security record
Consent recordsKept after deletion — see below
Suppression listKept permanently — see below

6. Two things that outlive deletion

When you delete your account we remove your data. Two records deliberately survive, and it is fairer to say so than to bury it.

Consent records. We keep the fact that somebody agreed to a specific version of our Terms and Privacy Policy, on a specific date, from a specific address. The link to your account is removed and only a one-way hash of the email address remains — enough to answer “did this address agree?”, useless for identifying you. Evidence of consent that vanishes exactly when it is disputed is evidence of nothing. (GDPR Article 17(3)(e) — retention necessary for legal claims.)

Suppression list. If an address hard-bounces or reports a message as spam, it is recorded as one that must never be emailed again — stored as a one-way hash. Deleting this would mean emailing people who have already told us to stop.

7. Your rights

Depending on where you live you may have the right to:

Write to privacy@ollily.com and we will respond within 30 days. We do not charge for this.

If you are somebody’s contact rather than our customer — you received an email sent through Ollily and want your data removed — contact the sender, who controls that list. If you cannot reach them, write to us and we will help.

8. Security

No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority within the time the law requires.

9. Cookies

We use a session cookie to keep you signed in, and a device cookie to remember browsers you have verified so you are not challenged on every sign-in. Both are strictly necessary and there is no way to use the product without them. We do not use advertising or third-party tracking cookies.

10. Children

Ollily is a business tool and is not intended for anyone under 16. We do not knowingly collect their data; if you believe we have, tell us and we will remove it.

11. Changes

We may update this policy. Material changes are notified by email before they take effect. Every version is numbered and dated at the top, and we record which version each account accepted.

12. Contact

Privacy and data requests: privacy@ollily.com
Anything else: hello@ollily.com

Note. This describes what the product actually does, written to be read rather than to be defensible. Before Ollily handles a substantial customer’s data, have a qualified privacy practitioner review it — particularly the controller and processor split, and international transfers.