Privacy Policy
Last updated: 9 October 2026
1. Who we are
Thinknauts OÜ ("Thinknauts", "we", "us") is a private limited company registered in Estonia, with its registered address at A. H. Tammsaare pst 54, 80016 Pärnu, Estonia. We operate the website thinknauts.eu and provide the "Inbox Intelligence" analysis service. For questions about this policy or your personal data, contact us at privacy@thinknauts.eu.
This policy explains how we process personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Estonian Personal Data Protection Act.
2. Two different roles
We process personal data in two distinct capacities:
- As a controller — for data about website visitors, prospective clients and our clients' contact persons (Sections 3–6).
- As a processor — for the content of email archives our clients entrust to us for analysis (Section 7). In that case our client is the controller and we act only on their documented instructions under a Data Processing Agreement (GDPR Art. 28).
3. Data we collect as a controller
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Contact form | Name, company, work email, number of mailboxes, your message, chosen language | Responding to your enquiry, preparing a quote | Art. 6(1)(b) — steps prior to a contract; Art. 6(1)(f) — legitimate interest in answering enquiries |
| Client relationship | Contact details of client representatives, contract and invoicing data, correspondence | Performing the contract, invoicing, accounting | Art. 6(1)(b); Art. 6(1)(c) — legal obligations (Estonian Accounting Act) |
| Website technical data | IP address (truncated), browser type, pages visited, referrer, approximate time of visit | Security, operating the site, aggregated statistics | Art. 6(1)(f) — legitimate interest; analytics only with consent, Art. 6(1)(a) |
| Preferences | Language choice, cookie consent status (stored in your browser) | Remembering your settings | Art. 6(1)(f); ePrivacy — strictly necessary |
4. Retention
- Contact form enquiries that do not lead to a contract: deleted within 12 months.
- Client contract and correspondence data: for the duration of the relationship and 3 years thereafter (limitation period), unless a longer period is required by law.
- Accounting source documents: 7 years as required by the Estonian Accounting Act.
- Technical website logs: up to 30 days.
5. Recipients and processors
We share personal data only with service providers who process it on our behalf under written contracts: website hosting and content delivery, email provider, accounting software and our accountant, and — if you consent — an analytics provider. We do not sell personal data. Data may be disclosed to authorities where required by law.
6. International transfers
We aim to keep all processing inside the European Union / EEA. Where a provider processes data outside the EEA, we rely on an adequacy decision of the European Commission or Standard Contractual Clauses with supplementary measures.
7. Email archives analysed for clients (processor role)
The core of our service is analysing a client's historical business email. Those archives inevitably contain personal data of the client's customers, suppliers and employees. For this processing:
- the client is the controller and is responsible for having a lawful basis to share the archive with us;
- we sign a Data Processing Agreement (GDPR Art. 28) before receiving any data;
- data is transferred via an encrypted channel and stored encrypted on servers located in the EU;
- access is limited to the analyst(s) assigned to the project, bound by confidentiality;
- we use AI-assisted tools for extraction and structuring, configured so that data is not used to train third‑party models;
- we process the data only for the purpose of producing the agreed deliverables;
- all raw data, intermediate files and backups are permanently deleted within 14 days of delivery and deletion is confirmed to the client in writing;
- we assist the client with data subject requests and notify them without undue delay of any personal data breach.
If you are a data subject whose data appears in a client's archive, please direct your request to that client (the controller); we will support them in responding.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interest, and to withdraw consent at any time without affecting prior processing. To exercise your rights, email privacy@thinknauts.eu. We respond within one month.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee, info@aki.ee) or with the supervisory authority of your EU member state of residence.
9. Security
We apply appropriate technical and organisational measures, including encryption in transit and at rest, access control, least‑privilege principles, logging and regular review of our providers.
10. Cookies
Information on cookies and similar technologies is provided in our Cookie Policy.
11. Changes
We may update this policy from time to time. The current version is always available at thinknauts.eu/privacy.html, with the date of the last update shown at the top.