Privacy Policy
In brief: We collect only the data necessary to provide the service. We do not sell data to third parties. You use Claude (Anthropic) and GPT-4o-mini (OpenAI) to generate content — you gave explicit consent. You can export or delete your data at any time.
1. Data Controller
Note on company incorporation: Eniteo AI is in the process of being incorporated as an Estonian company (OÜ — Osaühing). Full company details (registered name, Estonian registration number, registered office in Tallinn) will be updated once registration is complete.
Eniteo AI OÜ (company being incorporated in Estonia)
Legal form: OÜ (Osaühing) — Estonian law
Email: [email protected]
The service is intended exclusively for legal entities and professionals acting in the course of their business activity (B2B). It is not intended for private consumers.
2. Categories of Personal Data Processed
| Category | Specific data | Source |
|---|---|---|
| Identification data | Name, business email | Provided by user at registration |
| Authentication data | Password (bcrypt hashing), 2FA tokens and recovery codes (encrypted) | Generated by user |
| Company data | Company name, industry, business model, geography, domain, description, target audience, products/services, competitors, tone of voice | Provided during onboarding and profile setup |
| Consent data | Date/time of acceptance of Privacy Policy and Terms, IP address at time of consent | Recorded automatically at registration |
| Technical data | IP address, user agent, session logs, login attempt logs | Collected automatically |
| Generated content | Articles, answers, questions, entities, knowledge base claims | Generated by AI from user input |
| Billing data | Stripe customer ID, card type, last 4 digits, subscription plan | Stripe — full card data is never processed by Eniteo |
We do not collect special categories of personal data under Art. 9 GDPR (health, religious, political, biometric data, etc.).
3. Purposes and Legal Bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Service delivery (AEO/GEO content generation, AI citation monitoring, onboarding) | Art. 6.1.b — contract performance |
| Account authentication and security | Art. 6.1.b — contract performance; Art. 6.1.f — legitimate interest (fraud prevention) |
| Transmission of company data to AI sub-processors (Anthropic, OpenAI) for content generation | Art. 6.1.a — explicit consent (revocable at any time) |
| Billing and subscription management | Art. 6.1.b — contract performance; Art. 6.1.c — legal obligations |
| Transactional emails (email verification, service notifications, weekly digest) | Art. 6.1.b — contract performance |
| Aggregated, anonymised analytics for product improvement | Art. 6.1.f — Eniteo's legitimate interest |
| Compliance with legal and fiscal obligations | Art. 6.1.c — legal obligation |
4. Processors and Sub-Processors
Eniteo uses the following processors pursuant to Art. 28 GDPR:
| Sub-processor | Country | Processing | Safeguard |
|---|---|---|---|
| Anthropic PBC | USA | AI content generation (Claude API) | SCCs Art. 46 GDPR |
| OpenAI LLC | USA | Question generation, embeddings | SCCs Art. 46 GDPR |
| Stripe Inc. / Stripe Payments Europe Ltd. | USA / Ireland (EU) | Payment processing | SCCs; Stripe Europe under Central Bank of Ireland supervision |
| Resend Inc. | USA | Transactional emails | SCCs Art. 46 GDPR |
| Hetzner Online GmbH | Germany (EU) | Hosting, database, storage | No extra-EU transfer |
Company data transmitted to AI providers is limited to Knowledge Base content and company profile. No personal identification data (name, email) is transmitted to AI models. Updated list available on request at [email protected].
5. Retention Periods
| Category | Retention | Reason |
|---|---|---|
| Account and company data | Duration of contract + 7 years | Fiscal and accounting obligations (Estonian Accounting Act — Raamatupidamise seadus, § 12) |
| Consent data | Duration of contract + 7 years | Proof of consent under Art. 7.1 GDPR |
| Access and login attempt logs | 90 days | Security and prevention of unauthorised access |
| Generated content | Duration of contract; deleted on account closure | Service delivery |
| Billing data (Stripe) | 7 years from transaction | Accounting obligations (Estonian Accounting Act, § 12) |
6. Data Subject Rights (Arts. 15–22 GDPR)
- Access (Art. 15): Request a copy of your data from Settings → Export data or by writing to [email protected].
- Rectification (Art. 16): Update inaccurate data from the dashboard or contact [email protected].
- Erasure / Right to be forgotten (Art. 17): Use Settings → Delete account. Data is anonymised immediately; final deletion within 5 years subject to legal obligations.
- Restriction (Art. 18): Request suspension of processing by writing to [email protected].
- Portability (Art. 20): Download all your data in structured JSON format from Settings → Export data.
- Objection (Art. 21): You may object to processing based on legitimate interest by writing to [email protected].
- Withdrawal of consent (Art. 7.3): Consent for AI processing is revocable at any time from Settings → Account. Withdrawal does not affect the lawfulness of prior processing.
- Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority. As an Estonian-registered company, our primary authority is the Andmekaitse Inspektsioon (aki.ee). You may also contact the supervisory authority of your member state of residence.
We respond to requests within 30 days (Art. 12.3 GDPR). To exercise your rights visit our dedicated page or write to [email protected].
7. Security Measures (Art. 32 GDPR)
- Encryption in transit with TLS 1.3 (HTTPS enforced on all endpoints).
- Passwords stored with bcrypt hashing (cost 12).
- Two-factor authentication (TOTP 2FA) available for all accounts.
- Least-privilege access principle (RBAC).
- Daily encrypted backups (AES-256).
- Audit logs for data access and modifications.
- Rate limiting on all public and authenticated endpoints.
- Periodic penetration testing and automated dependency scanning.
8. Cookies
For detailed information see the Cookie Policy. Strictly necessary technical cookies require no consent; analytics cookies are activated only with explicit consent.
9. Changes
Material changes will be communicated by email with at least 15 days' notice. The current version is always available on this page.
10. Contact
Eniteo AI OÜ (company being incorporated in Estonia)
Email: [email protected]
GDPR rights: eniteo.ai/en/data-rights