ConBRIX Privacy Policy

Version 1.0 · effective from 12 September 2026

In case of discrepancy, the Estonian version of this policy prevails.

1. Controller

Nordes Engineering OÜ, registry code 12298039, [address]. Questions about personal data: info@conbrix.eu.

2. Which personal data and why

The ConBRIX service analyses public data of companies (legal persons). The financial data of a legal person is not personal data. We process personal data only about the User (a natural person) and only to the minimum extent.

Data Source Purpose Legal basis (GDPR art. 6)
Work e-mail address, password hash, role in the company, name (optional) The User Account, login, confirmation and password e-mails contract (b)
Customer's registry code and the User's link to the Customer The User Provision of the Service to the Customer contract (b)
Two-factor authentication secret (if the User enables it) The User Account security contract (b)
Contract data (value, duration, counterparty company) and the User's assessments The User Calculation of Output contract (b)
Usage events (views opened, cards, feedback, exports, timestamps) The Service Operation of the Service, development, pseudonymised research legitimate interest (f)
Conversations (when the conversation feature is available): question text and conversation identifier The User Answering, usage accounting contract (b)
Technical logs (IP address, browser type, errors) The Service Security, abuse prevention, compliance with data-source terms legitimate interest (f)
Billing data for a paid Plan (Customer's billing address, VAT number, invoice and payment status) The User, the payment provider Billing, accounting contract (b), legal obligation (c)
E-mail notification preferences The User Contract and partner e-mails; monthly summary contract (b); monthly summary only on the User's subscription (a)
Connected applications (if the User connects the Service to their own AI application) The User Management and revocation of the connection contract (b)

We do not ask for or store the Customer's margin, bids, the full text of contract documents or card data. We do not process special categories of personal data.

The Service is not intended for analysing sole proprietors or other natural persons; from the business register we use only the financial lines of legal persons and do not store the names of board members or other natural persons.

3. Cookies

We use only a session cookie to keep the User logged in (up to 30 days if the User chooses "remember me") and a security cookie (CSRF). We do not use tracking or marketing cookies.

If we add visitor statistics for the public pages, we will use a cookie-free solution on our own server in the European Union that does not store IP addresses and does not identify the User; this policy will be updated before it is introduced.

4. To whom we disclose data

Personal data is not sold or disclosed to third parties for marketing. We use processors for the provision of the Service:

Processor Role Location
Zone Media OÜ server hosting, database and encrypted backups Estonia (EU)
Brevo (Sendinblue SAS) sending confirmation, notification and summary e-mails France (EU)
Stripe Payments Europe Ltd card payments and subscription management in a hosted payment environment; card data is held only by Stripe Ireland (EU); see below
Merit Tarkvara AS (Merit Aktiva) preparation and sending of sales invoices Estonia (EU)
GitHub, Inc. source-code repository — code only, no customer or personal data USA (no personal data is transferred)

All User personal data and Customer data is located in the European Union. The only exception is card payment: companies of the Stripe group may also process payment data outside the European Economic Area; such transfers take place under the European Commission's standard contractual clauses and the EU–US Data Privacy Framework and concern only the data necessary to make the payment (the User's name and e-mail, the Customer's billing address, and card data which the Service itself never sees).

For the conversation feature we use a language model only in a data centre located in the European Union; until such a service is configured, the conversation feature is switched off. Only the text of the User's question and the context needed to answer it is transmitted to the language model, not the Account data as a whole, and the provider does not use it to train the model.

If the User connects the Service to their own AI application (for example Claude or ChatGPT), the Service transmits to it, at the User's own request, the same sentences and cards that the User sees in the Service. The provider of such an application is a service chosen by the User and its data-protection terms apply between the User and that provider. The User can revoke the connection at any time on the Account page.

No User personal data is transmitted to the public data sources (e-Business Register, Tax and Customs Board, Statistics Estonia and others); queries are made about companies' registry codes.

5. Research

Usage events, contract data and feedback are used in pseudonymised and aggregated form to study decision-support methodology (Tallinn University of Technology and partner universities). In pseudonymisation, Account identifiers are replaced with a key that exists only in the Service's production environment; the research environment does not have this key. Neither the User nor the Customer is identifiable in publications, and results are published only across at least five companies. The User may object to use for research at any time by notifying the address in section 1; pseudonymised aggregated data collected up to that point cannot technically be re-identified.

6. Retention

Account data — until the Account is closed; thereafter the User's e-mail, name and password hash are deleted within 30 days and usage events are pseudonymised. Technical logs — 90 days. Unconfirmed account — 30 days. Encrypted backups — 30 days. Accounting data for a paid Plan — 7 years as required by law.

7. The User's rights

The User has the right to access their data (Account page, "Download data"), to rectify it, to erase it (closing the Account), to restrict processing, to data portability, to object to processing based on legitimate interest, and to withdraw the monthly summary subscription at any time via the unsubscribe link in the e-mail or on the Account page. Requests: info@conbrix.eu. We respond within 30 days. A complaint may be lodged with the Estonian Data Protection Inspectorate (www.aki.ee).

8. Security

Passwords are stored only as hashes (argon2id); two-factor authentication secrets are encrypted; data in transit is encrypted (HTTPS); data is located in the European Union; access is role-restricted; backups are encrypted and the encryption key is not stored on the server; data-source access credentials are not accessible to Users. We notify the supervisory authority and affected Users of a data breach as required by law.

9. Changes

We notify Users of changes to this policy by e-mail or in the Service at least 30 days in advance; the current version is always available at conbrix.eu/privaatsus.