Skip to content
Eniteo
  • Monitoring See which AI answers name you Content Articles grounded in verified facts Distribution Publish, then watch for drift Talk to a specialist Scope a programme with a human
  • Pricing
  • Insurance 8 subsectors Finance 6 subsectors Legal 7 subsectors Healthcare 6 subsectors Technology 6 subsectors Professional services 5 subsectors Manufacturing 6 subsectors
  • Blog Research and practice Methodology Our scoring rubric, published in full EU AI Act What the regulation actually requires AI instructions Canonical facts for AI assistants
  • Security How we protect your data Status Live system status Work with us Partners and collaboration Contact Talk to the team
  • 🇮🇹 IT
  • 🇬🇧 EN
  • 🇪🇸 ES
  • 🇫🇷 FR
  • 🇵🇹 PT
Log in Try free
  • Product
  • Monitoring
  • Content
  • Distribution
  • Talk to a specialist
  • Sectors
  • Insurance
  • Finance
  • Legal
  • Healthcare
  • Technology
  • Professional services
  • Manufacturing
  • Resources
  • Blog
  • Methodology
  • EU AI Act
  • AI instructions
  • Company
  • Security
  • Status
  • Work with us
  • Contact
  • Pricing
Log in
🇮🇹 🇬🇧 🇪🇸 🇫🇷 🇵🇹

Privacy Policy

Version: 3.0  |  Last updated: April 2026  |  Controller: Eniteo AI  |  Contact: [email protected]

In brief: We collect only the data necessary to provide the service. We do not sell data to third parties. You use Claude (Anthropic) and GPT-4o-mini (OpenAI) to generate content — you gave explicit consent. You can export or delete your data at any time.

1. Data Controller

Note on company incorporation: Eniteo AI is in the process of being incorporated as an Estonian company (OÜ — Osaühing). Full company details (registered name, Estonian registration number, registered office in Tallinn) will be updated once registration is complete.

Eniteo AI OÜ (company being incorporated in Estonia)
Legal form: OÜ (Osaühing) — Estonian law
Email: [email protected]

The service is intended exclusively for legal entities and professionals acting in the course of their business activity (B2B). It is not intended for private consumers.

2. Categories of Personal Data Processed

CategorySpecific dataSource
Identification dataName, business emailProvided by user at registration
Authentication dataPassword (bcrypt hashing), 2FA tokens and recovery codes (encrypted)Generated by user
Company dataCompany name, industry, business model, geography, domain, description, target audience, products/services, competitors, tone of voiceProvided during onboarding and profile setup
Consent dataDate/time of acceptance of Privacy Policy and Terms, IP address at time of consentRecorded automatically at registration
Technical dataIP address, user agent, session logs, login attempt logsCollected automatically
Generated contentArticles, answers, questions, entities, knowledge base claimsGenerated by AI from user input
Billing dataStripe customer ID, card type, last 4 digits, subscription planStripe — full card data is never processed by Eniteo

We do not collect special categories of personal data under Art. 9 GDPR (health, religious, political, biometric data, etc.).

3. Purposes and Legal Bases

PurposeLegal basis (Art. 6 GDPR)
Service delivery (AEO/GEO content generation, AI citation monitoring, onboarding)Art. 6.1.b — contract performance
Account authentication and securityArt. 6.1.b — contract performance; Art. 6.1.f — legitimate interest (fraud prevention)
Transmission of company data to AI sub-processors (Anthropic, OpenAI) for content generationArt. 6.1.a — explicit consent (revocable at any time)
Billing and subscription managementArt. 6.1.b — contract performance; Art. 6.1.c — legal obligations
Transactional emails (email verification, service notifications, weekly digest)Art. 6.1.b — contract performance
Aggregated, anonymised analytics for product improvementArt. 6.1.f — Eniteo's legitimate interest
Compliance with legal and fiscal obligationsArt. 6.1.c — legal obligation

4. Processors and Sub-Processors

Eniteo uses the following processors pursuant to Art. 28 GDPR:

Sub-processorCountryProcessingSafeguard
Anthropic PBCUSAAI content generation (Claude API)SCCs Art. 46 GDPR
OpenAI LLCUSAQuestion generation, embeddingsSCCs Art. 46 GDPR
Stripe Inc. / Stripe Payments Europe Ltd.USA / Ireland (EU)Payment processingSCCs; Stripe Europe under Central Bank of Ireland supervision
Resend Inc.USATransactional emailsSCCs Art. 46 GDPR
Hetzner Online GmbHGermany (EU)Hosting, database, storageNo extra-EU transfer

Company data transmitted to AI providers is limited to Knowledge Base content and company profile. No personal identification data (name, email) is transmitted to AI models. Updated list available on request at [email protected].

5. Retention Periods

CategoryRetentionReason
Account and company dataDuration of contract + 7 yearsFiscal and accounting obligations (Estonian Accounting Act — Raamatupidamise seadus, § 12)
Consent dataDuration of contract + 7 yearsProof of consent under Art. 7.1 GDPR
Access and login attempt logs90 daysSecurity and prevention of unauthorised access
Generated contentDuration of contract; deleted on account closureService delivery
Billing data (Stripe)7 years from transactionAccounting obligations (Estonian Accounting Act, § 12)

6. Data Subject Rights (Arts. 15–22 GDPR)

  • Access (Art. 15): Request a copy of your data from Settings → Export data or by writing to [email protected].
  • Rectification (Art. 16): Update inaccurate data from the dashboard or contact [email protected].
  • Erasure / Right to be forgotten (Art. 17): Use Settings → Delete account. Data is anonymised immediately; final deletion within 5 years subject to legal obligations.
  • Restriction (Art. 18): Request suspension of processing by writing to [email protected].
  • Portability (Art. 20): Download all your data in structured JSON format from Settings → Export data.
  • Objection (Art. 21): You may object to processing based on legitimate interest by writing to [email protected].
  • Withdrawal of consent (Art. 7.3): Consent for AI processing is revocable at any time from Settings → Account. Withdrawal does not affect the lawfulness of prior processing.
  • Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority. As an Estonian-registered company, our primary authority is the Andmekaitse Inspektsioon (aki.ee). You may also contact the supervisory authority of your member state of residence.

We respond to requests within 30 days (Art. 12.3 GDPR). To exercise your rights visit our dedicated page or write to [email protected].

7. Security Measures (Art. 32 GDPR)

  • Encryption in transit with TLS 1.3 (HTTPS enforced on all endpoints).
  • Passwords stored with bcrypt hashing (cost 12).
  • Two-factor authentication (TOTP 2FA) available for all accounts.
  • Least-privilege access principle (RBAC).
  • Daily encrypted backups (AES-256).
  • Audit logs for data access and modifications.
  • Rate limiting on all public and authenticated endpoints.
  • Periodic penetration testing and automated dependency scanning.

8. Cookies

For detailed information see the Cookie Policy. Strictly necessary technical cookies require no consent; analytics cookies are activated only with explicit consent.

9. Changes

Material changes will be communicated by email with at least 15 days' notice. The current version is always available on this page.

10. Contact

Eniteo AI OÜ (company being incorporated in Estonia)
Email: [email protected]
GDPR rights: eniteo.ai/en/data-rights

Eniteo

GEO & AEO for companies in regulated industries.

[email protected]
© 2026 Eniteo AI OÜ Eniteo AI OÜ — Estonia
[email protected]
Product
Monitoring Content Distribution Pricing Sectors Talk to a specialist FAQ Blog Methodology EU AI Act AI instructions
Company
Status Security Work with us
Legal
Privacy Policy Cookie Policy Terms of Service DPA GDPR Rights Contact

We use cookies

We use technical cookies necessary for the site to work and, with your consent, analytics cookies to improve your experience. Read our Cookie Policy and Privacy Policy.