ConBRIX Privacy Policy
Version 0.1 (draft) — not yet reviewed by a lawyer · 02.09.2026 · effective: [date]
1. Controller
[Nordes Engineering OÜ, registry code 12298039, address …, e-mail privacy@… — tbv]. Questions about personal data: [e-mail].
2. Which personal data and why
The ConBRIX Service analyses the public data of companies (legal persons). The financial data of a legal person is not personal data. We process personal data only about the User (a natural person) and minimally:
| Data | Source | Purpose | Legal basis (GDPR art 6) |
|---|---|---|---|
| E-mail address, password hash, role in the company, name (optional) | The User | Account, login, confirmation and password e-mails | contract (b) |
| The Customer's registry code and the User's association with the Customer | The User | Providing the Service to the Customer | contract (b) |
| List of partners (company names/registry codes) | The User | Displaying partner badges | contract (b) |
| Usage events (opened views, cards, feedback touches, exports, timestamps) | The Service | Operation of the Service, development, research in pseudonymised form | legitimate interest (f); research in aggregated form |
| Technical logs (IP address, browser type, errors) | The Service | Security, prevention of abuse, compliance with data-source terms | legitimate interest (f) |
| E-mail notification preferences | The User | Contract and partner e-mails (A–C); monthly overview (D) | contract (b) A–C; consent (a) D |
We do not ask for or store the Customer's margin, price quotations, the content of contract documents beyond machine-read fields (value, duration, schedule) or card data. We do not process special categories of personal data.
The Service is not intended for analysing sole proprietors or other natural persons; of the business register data we use only the financial lines of legal persons and do not store the names of management board members or other natural persons.
3. Cookies
We use only a session cookie to keep the User logged in (up to 30 days if the User selects "remember me") and a security cookie (CSRF). We do not use tracking or marketing cookies. [tbv: update if analytics is added.]
4. To whom we transfer data
Personal data is not sold or transferred to third parties for marketing. We use processors to provide the Service:
| Processor | Role | Location |
|---|---|---|
| Zone Media OÜ [tbv] | server hosting and object storage (backups) | Estonia (EU) |
| [Brevo or Mailjet — tbv] | sending transactional and notification e-mails | EU |
| [LLM service in an EU region (e.g. AWS Bedrock eu-central-1 or Anthropic EU residency) — tbv; the chat feature stays disabled until EU-region access exists] | chat answers (only the question text is transmitted, never account data) | EU |
| GitHub, Inc. | source-code hosting (code ONLY; no client data on GitHub) | USA (code, not personal data) |
| [payment provider, e.g. Stripe] — only when paid plans are introduced | payment | EU/EEA; card data only with the provider |
Personal data is not transferred outside the European Economic Area; should this become necessary in the future, the safeguards of Chapter V of the GDPR will be applied and this policy updated.
No User personal data is transmitted towards the public data sources (RIK, the Estonian Tax and Customs Board, Statistics Estonia and others); queries are made about the registry codes of companies.
5. Research
Usage events and feedback are used in pseudonymised and aggregated form to study decision-support methodology (TalTech and partner universities). Neither the User nor the Customer is identifiable in publications. The User may object to use in research at any time by notifying the address given in section 1; pseudonymised aggregated data collected up to that point cannot technically be re-identified.
6. Retention
Account data — until the Account is closed; thereafter the User's e-mail, name and password hash are deleted within 30 days and usage events are pseudonymised. Technical logs — 90 days. An unconfirmed account — 30 days. Accounting data (in the case of paid plans) — 7 years as required by law.
7. User rights
The User has the right to access their data, to rectify it, to erase it (closing the Account), to restrict processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent (marketing e-mails) at any time via the unsubscribe link or in the settings. Requests: [e-mail]. We respond within 30 days. A complaint may be lodged with the Estonian Data Protection Inspectorate (www.aki.ee).
8. Security
Passwords are stored only as hashes (argon2id); data in transit is encrypted (HTTPS); data is located in the EU; access is role-restricted; backups are encrypted; the access credentials of the data sources are not accessible to Users. In the event of a data breach we notify the supervisory authority and the affected Users in the manner prescribed by law.
9. Changes
We notify Users of changes to this policy by e-mail or in the Service at least 30 days in advance; the current version is always available at [domain]/privaatsus.