ConBRIX Privacy Policy

Version 0.1 (draft) — not yet reviewed by a lawyer · 02.09.2026 · effective: [date]

1. Controller

[Nordes Engineering OÜ, registry code 12298039, address …, e-mail privacy@… — tbv]. Questions about personal data: [e-mail].

2. Which personal data and why

The ConBRIX Service analyses the public data of companies (legal persons). The financial data of a legal person is not personal data. We process personal data only about the User (a natural person) and minimally:

Data Source Purpose Legal basis (GDPR art 6)
E-mail address, password hash, role in the company, name (optional) The User Account, login, confirmation and password e-mails contract (b)
The Customer's registry code and the User's association with the Customer The User Providing the Service to the Customer contract (b)
List of partners (company names/registry codes) The User Displaying partner badges contract (b)
Usage events (opened views, cards, feedback touches, exports, timestamps) The Service Operation of the Service, development, research in pseudonymised form legitimate interest (f); research in aggregated form
Technical logs (IP address, browser type, errors) The Service Security, prevention of abuse, compliance with data-source terms legitimate interest (f)
E-mail notification preferences The User Contract and partner e-mails (A–C); monthly overview (D) contract (b) A–C; consent (a) D

We do not ask for or store the Customer's margin, price quotations, the content of contract documents beyond machine-read fields (value, duration, schedule) or card data. We do not process special categories of personal data.

The Service is not intended for analysing sole proprietors or other natural persons; of the business register data we use only the financial lines of legal persons and do not store the names of management board members or other natural persons.

3. Cookies

We use only a session cookie to keep the User logged in (up to 30 days if the User selects "remember me") and a security cookie (CSRF). We do not use tracking or marketing cookies. [tbv: update if analytics is added.]

4. To whom we transfer data

Personal data is not sold or transferred to third parties for marketing. We use processors to provide the Service:

Processor Role Location
Zone Media OÜ [tbv] server hosting and object storage (backups) Estonia (EU)
[Brevo or Mailjet — tbv] sending transactional and notification e-mails EU
[LLM service in an EU region (e.g. AWS Bedrock eu-central-1 or Anthropic EU residency) — tbv; the chat feature stays disabled until EU-region access exists] chat answers (only the question text is transmitted, never account data) EU
GitHub, Inc. source-code hosting (code ONLY; no client data on GitHub) USA (code, not personal data)
[payment provider, e.g. Stripe] — only when paid plans are introduced payment EU/EEA; card data only with the provider

Personal data is not transferred outside the European Economic Area; should this become necessary in the future, the safeguards of Chapter V of the GDPR will be applied and this policy updated.

No User personal data is transmitted towards the public data sources (RIK, the Estonian Tax and Customs Board, Statistics Estonia and others); queries are made about the registry codes of companies.

5. Research

Usage events and feedback are used in pseudonymised and aggregated form to study decision-support methodology (TalTech and partner universities). Neither the User nor the Customer is identifiable in publications. The User may object to use in research at any time by notifying the address given in section 1; pseudonymised aggregated data collected up to that point cannot technically be re-identified.

6. Retention

Account data — until the Account is closed; thereafter the User's e-mail, name and password hash are deleted within 30 days and usage events are pseudonymised. Technical logs — 90 days. An unconfirmed account — 30 days. Accounting data (in the case of paid plans) — 7 years as required by law.

7. User rights

The User has the right to access their data, to rectify it, to erase it (closing the Account), to restrict processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent (marketing e-mails) at any time via the unsubscribe link or in the settings. Requests: [e-mail]. We respond within 30 days. A complaint may be lodged with the Estonian Data Protection Inspectorate (www.aki.ee).

8. Security

Passwords are stored only as hashes (argon2id); data in transit is encrypted (HTTPS); data is located in the EU; access is role-restricted; backups are encrypted; the access credentials of the data sources are not accessible to Users. In the event of a data breach we notify the supervisory authority and the affected Users in the manner prescribed by law.

9. Changes

We notify Users of changes to this policy by e-mail or in the Service at least 30 days in advance; the current version is always available at [domain]/privaatsus.