Privacy Policy
Version 1.0 · Effective August 3, 2026 · English (governing text)
This Privacy Policy explains how Strukt.ai processes personal data in its role as a data controller (for its own purposes: account management, billing, security, analytics, product improvement) and sets the transparency framework for its role as a data processor on behalf of its Clients. It applies to all visitors to strukt.ai and to Authorised Users of the Service.
1. Data controller identity and contact details
The controller of personal data processed in connection with account registration, the website, and marketing is:
Strukt Technologies OÜ ("Provider")
Registration number: 17488230
Address: Tallinn, Telliskivi tn 57/1, 10412, Estonia
E-mail: privacy@strukt.ai
Data Protection Officer (if appointed): dpo@strukt.ai
This Privacy Policy has been prepared in compliance with Regulation (EU) 2016/679 ("GDPR"), the Estonian Personal Data Protection Act (isikuandmete kaitse seadus, IKS), and the Estonian Electronic Communications Act (elektroonilise side seadus, ESS) implementing the ePrivacy Directive (2002/58/EC).
2. Scope of this policy and definitions
All capitalized terms in this Privacy Policy have the same definitions as in the Terms and Conditions of Service of the Provider unless defined herein.
This Policy applies to:
- visitors to strukt.ai and any sub-pages ("Website");
- prospective customers and leads who interact with the Provider's marketing activities;
- Client contact persons who register for and manage a Strukt.ai Client's account ("Account Data");
- Authorised Users of the Service.
This Policy does not govern the processing of personal data contained within Client Data (i.e. workplace conversation content and employee data of the Client's personnel), for which the Client is the data controller and the Provider is the data processor. Such processing is governed exclusively by the Data Processing Agreement (DPA) between the Provider and the Client.
3. Personal data we collect
3.1 Account and registration data
When you create a Strukt.ai account, we collect:
- full name, work e-mail address
- authentication credentials (stored in hashed form only).
3.2 Usage and technical data
When you access and use the Service, we automatically collect:
- log data (IP address, browser type, operating system, pages visited, time and date of access);
- device identifiers and session tokens;
- feature usage events (e.g. integrations activated, actions performed), for product improvement and support;
- error reports and diagnostic information.
3.3 Communications
When you contact us by e-mail, support form, if any, or other means, we collect the content of your communication, your contact details, and any attachments you provide.
3.4 Cookies and similar technologies
We use cookies and similar tracking technologies on the Website and in the Service. Details of the cookies we use, their purpose, retention period, and how to manage your preferences are set out in our Cookie Policy. Strictly necessary cookies are deployed on the basis of legitimate interest; analytical and marketing cookies require your prior consent in accordance with the ePrivacy Directive as implemented in Estonia.
3.5 Data we do not collect as controller
We do not process the contents of your workplace communications (conversations, messages, or tasks processed by the AI engine) as data controller. That content is Client Data processed on the Client's instructions as described in the DPA.
4. Legal bases for processing
| Processing Activity | Legal Basis (GDPR Art.) |
|---|---|
| Providing the Service and fulfilling the contract (account management, billing, support) | Contract performance – Art. 6(1)(b) |
| Sending transactional communications (invoices, service notices, security alerts) | Contract performance – Art. 6(1)(b) |
| Fraud prevention, security monitoring, and abuse detection | Legitimate interest – Art. 6(1)(f) — Provider's interest in secure service delivery |
| Product analytics and service improvement (aggregated/pseudonymised usage data) | Legitimate interest – Art. 6(1)(f) — improvement of the Service |
| Sending marketing communications to existing customers about related products | Legitimate interest – Art. 6(1)(f), subject to opt-out right under Art. 21 |
| Sending marketing communications to non-customers and new marketing initiatives | Consent – Art. 6(1)(a) |
| Compliance with legal obligations (tax records, responding to regulatory requests) | Legal obligation – Art. 6(1)(c) |
| Resolving disputes and enforcing legal claims | Legitimate interest – Art. 6(1)(f) |
| Analytical cookies and personalisation | Consent – Art. 6(1)(a), implemented via cookie banner |
Note: Where processing is based on legitimate interest, we have conducted a balancing test. Our legitimate interests do not override your fundamental rights and freedoms, and you may object to such processing at any time (see Section 9).
5. Purposes of processing
We use personal data for the following purposes:
- creating and managing your account and Subscription;
- providing, maintaining, and improving the Service;
- processing billing, payments, and issuing invoices;
- providing technical support and responding to your queries;
- sending service announcements, security notifications, and legal notices;
- sending marketing and promotional communications where we have a legal basis to do so;
- monitoring and ensuring the security and integrity of the Service;
- complying with applicable legal and regulatory obligations;
- enforcing our Terms and Conditions and other legal rights;
- statistical analysis and product analytics to improve the Service.
We do not engage in profiling that produces legal or similarly significant effects on data subjects without appropriate safeguards under GDPR Article 22.
6. Transparency under the EU AI Act
Strukt.ai uses AI systems to process workplace content provided by Clients. In the interest of transparency, we provide the following information in accordance with the EU AI Act (Regulation (EU) 2024/1689):
- The AI systems used in the Service are designed to assist human decision-making. They do not replace human judgment in matters with significant legal or similarly significant effects on individuals without appropriate human oversight.
- Where the Service involves AI systems subject to the transparency obligations of Article 50 of the AI Act (e.g. AI generating text that could be mistaken for human-authored content), users are informed accordingly.
- The Provider maintains the required technical documentation for AI systems deployed in the Service.
- Clients and their Authorised Users are informed that AI-generated Outputs are not infallible and should be reviewed by a competent human before consequential decisions are taken.
AI governance: As a B2B AI system primarily serving professional workflow use cases, Strukt.ai does not fall under the prohibited AI practices listed in Article 5 of the AI Act. The risk classification of specific AI components is documented in the Provider's AI Act conformity documentation, if one is needed, available to Clients on written request.
7. Sharing of personal data and recipients
7.1 Sub-processors and service providers
We share personal data with trusted third-party service providers who assist us in operating the Service, subject to appropriate data processing agreements. Categories of sub-processors and service providers include:
- cloud infrastructure providers (hosting and storage);
- AI model providers (for the processing of communications data — governed by the DPA);
- payment processors (for billing and subscription management);
- customer support platforms;
- analytics and error-monitoring tools;
- e-mail delivery services.
A current list of sub-processors is maintained and available at https://trust.strukt.ai/subprocessors on written request.
7.2 International transfers
Some of our service providers and sub-processors are located outside the European Economic Area (EEA). Where personal data is transferred to a third country, we ensure that appropriate safeguards are in place as required by GDPR Chapter V, including:
- adequacy decisions of the European Commission;
- Standard Contractual Clauses (SCCs) adopted by the European Commission under Article 46(2)(c) GDPR;
- Binding Corporate Rules (BCRs) where applicable.
Estonia, as an EU Member State, benefits from the full application of GDPR transfer rules.
7.3 Legal disclosures
We may disclose personal data to competent authorities (including the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), law enforcement, or courts) where required by Applicable Law or a binding legal order. We will, to the extent legally permitted, notify the data subject before making such a disclosure.
7.4 Business transfers
In the event of a merger, acquisition, reorganisation, or sale of all or substantially all of our assets, personal data may be transferred to the successor entity, subject to the same or equivalent data protection obligations.
7.5 No sale of personal data
We do not sell, rent, or trade personal data to third parties for their own marketing purposes.
8. Retention periods
| Category of Data | Retention Period |
|---|---|
| Account registration data | Duration of the Subscription plus 3 years after termination (for legal claims) |
| Billing and invoicing records | 7 years from the date of the transaction (Estonian Accounting Act, raamatupidamise seadus) |
| Technical log data (IP addresses, access logs) | 12 months from collection, unless extended for security incident investigation |
| Client support communications | 3 years from resolution of the support request |
| Marketing consent records | Until withdrawal of consent plus 1 year |
| Cookie consent logs | 1 year from consent |
| Legal correspondence and dispute records | 10 years from resolution |
| Client Data (as processor) | As specified in the DPA — deleted within 30 days of termination unless the Client requests export |
9. Your rights as a data subject
Under GDPR and the IKS, you have the following rights in relation to personal data for which we act as data controller:
| Right | Description |
|---|---|
| Right of access | You may request a copy of the personal data we hold about you and information about how we process it. |
| Right to rectification | You may request correction of inaccurate or incomplete personal data without undue delay. |
| Right to erasure | You may request deletion of your personal data where one of the grounds in Art. 17(1) applies (e.g. data no longer necessary, consent withdrawn) and no exception under Art. 17(3) applies. |
| Right to restriction | You may request restriction of processing in specified circumstances, e.g. while accuracy is contested. |
| Right to data portability | Where processing is based on consent or contract and carried out by automated means, you may receive your personal data in a structured, commonly used, machine-readable format. |
| Right to object | You may object at any time to processing based on legitimate interest, including direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests. |
| Right not to be subject to solely automated decisions | You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects on you. We do not engage in such processing without human oversight. |
| Right to withdraw consent | Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal. |
9.1 How to exercise your rights
To exercise any of the above rights, please submit a written request to privacy@strukt.ai. We will respond within one calendar month of receipt. The period may be extended by a further two months for complex or numerous requests, with notice to you. We may ask you to verify your identity before processing a request.
9.2 Complaints
If you believe that your data protection rights have been violated, you may lodge a complaint with:
- the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), Tatari 39, Tallinn 10134, Estonia; e-mail: info@aki.ee; website: www.aki.ee; or
- the supervisory authority of the EU Member State of your habitual residence or place of work.
We encourage you to contact us first at privacy@strukt.ai so that we can attempt to resolve any concern before a complaint is filed.
10. Security
We implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with GDPR Article 32. These measures include, but are not limited to:
- encryption of personal data in transit (TLS 1.2 or higher) and at rest;
- pseudonymisation and access control mechanisms;
- regular security testing, vulnerability assessments, and penetration testing;
- multi-factor authentication for administrative access;
- staff data protection training and confidentiality obligations;
- incident response and data breach notification procedures in accordance with GDPR Article 33.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with GDPR Article 34.
11. Children's data
The Service is not directed at or intended for use by children under the age of 18. We do not knowingly collect personal data from children. If we become aware that personal data of a child under 18 has been collected, we will take steps to delete it promptly. If you believe we have inadvertently collected such data, please contact privacy@strukt.ai.
12. Cookies and tracking technologies
Our Website and Service use cookies and similar technologies. Our Cookie Policy provides detailed information on:
- the specific cookies we use and their function (strictly necessary, functional, analytical, marketing);
- the third-party cookies set by integrated services;
- how to manage or withdraw consent through our cookie preference centre;
- the legal basis for each category of cookie.
In line with Estonian law implementing the ePrivacy Directive and GDPR, we only set non-essential cookies after obtaining your freely given, specific, informed, and unambiguous consent through a cookie banner. Consent may be withdrawn at any time by re-accessing the cookie preference centre.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, new legal requirements, or the introduction of new features. Where changes are material, we will notify you by e-mail to the registered account address and/or by a prominent notice on the Website at least 14 days before the changes take effect. The "last updated" date at the top of this Policy will always reflect the current version.
Continued use of the Service after the effective date of a revised Privacy Policy constitutes acceptance of the changes, to the extent permitted by GDPR and Applicable Law.
14. Contact Us
For any questions or concerns about this Privacy Policy or our data protection practices, please contact:
E-mail: privacy@strukt.ai
Address: Strukt Technologies OÜ
Registration number: 17488230
Address: Tallinn, Telliskivi tn 57/1, 10412, Estonia
Data Protection Officer (if applicable): dpo@strukt.ai
We aim to respond to all privacy enquiries within 5 business days.
Last updated: August 3, 2026