NET.AI
GLOBAL PRIVACY POLICY
Effective Date: February 1, 2026
Last Updated: February 1, 2026
Legal Entity: Net.A.I OÜ
Registry Code: 17436121
VAT: EE102954847
Registered Address: Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia
Business Activity: 70201 – Business and other management consultancy activities
Contact: hello@net-ia.biz
Website: https://www.net-ai.io
1. INTRODUCTION
Net.AI is a European consulting and AI systems company specializing in strategic AI advisory, authority and visibility
structuring (SEO and structured data), operational AI implementation, identity validation protocols (including the
21 News Lexicon), decision-support systems, and AI-powered workflow orchestration.
This Privacy Policy explains how personal data is collected, processed, stored, and protected across the entire Net.AI
ecosystem in compliance with Regulation (EU) 2016/679 (GDPR) and applicable European and Estonian data protection laws.
This policy applies to:
- https://www.net-ai.io
- All subpages (AI advisory, AI solutions, SEO and visibility, contact forms, blog)
- 21 News Lexicon
- Client projects
- Demo bookings
- Newsletter subscriptions
- Any digital interaction with Net.AI
2. DATA CONTROLLER
The Data Controller is Net.A.I OÜ (details above). Net.A.I OÜ acts as:
- Data Controller for website and service-related processing.
- Data Processor when delivering AI systems on behalf of clients, under contractual instruction.
3. CATEGORIES OF PERSONAL DATA
A. Website Visitors
- Name
- Email
- Company
- IP address
- Device and browser information
- Session activity
- Cookies and analytics data
B. Prospects and Clients
- Professional details
- Business contact information
- Communication records
- Contractual information
- Billing data
C. AI Advisory and Implementation Projects
When delivering AI systems, we may process:
- Operational workflow data
- CRM data (when acting as processor)
- Business intelligence inputs
- Decision-support datasets
- Limited personal data strictly required for project execution
Net.AI does not claim ownership of client data and processes it only under contractual instruction.
D. 21 News Lexicon and Authority Services
- Identity verification data (if required)
- Professional biography data
- Public reputation data
- Media content
- Ground truth reference files (if selected plan requires anchoring)
E. AI Systems Interaction Data
When AI-powered systems are deployed, we may process:
- User inputs
- Transcriptions (if applicable)
- Interaction logs
- System outputs
Such data is processed solely for service delivery and improvement within agreed scope.
4. PURPOSES OF PROCESSING
Personal data is processed for:
- Strategic consulting delivery
- AI solution implementation
- SEO and authority structuring
- Knowledge Graph optimization
- Fraud prevention
- Identity validation (when applicable)
- Customer communication
- Invoicing and accounting
- Service improvement
- Legal compliance
- Security monitoring
Net.AI does not use personal data for unrelated advertising resale or data brokerage.
5. LEGAL BASES (GDPR)
Processing relies on one or more of the following legal bases:
- Consent
- Contractual necessity
- Legal obligation
- Legitimate interest
- Explicit consent for biometric data (if applicable)
6. AI-SPECIFIC PROCESSING PRINCIPLES
Net.AI applies responsible AI principles:
- Human oversight over critical decisions
- No fully automated legal decisions without review
- Data minimization in model interactions
- Avoidance of unnecessary data retention
- Secure API-level integrations
AI tools are used as processing instruments, not autonomous legal authorities.
7. DATA RETENTION
Retention varies by context:
- Website inquiries: up to 24 months
- Client contracts: duration plus statutory retention (7 to 10 years)
- AI project logs: duration of mandate unless agreed otherwise
- Identity validation materials: retained only as necessary
- Lexicon profiles: duration of publication plus archival period
Data is deleted or anonymized once no longer required.
8. SUBPROCESSORS (CATEGORIES)
Net.AI may use third-party providers in the following categories:
- Cloud hosting and infrastructure
- Content delivery networks
- Payment processors
- Email and transactional messaging providers
- Form and scheduling tools
- AI model providers
- DevOps and version control platforms
- Monitoring and logging services
- Security services
Processors are bound by confidentiality and data protection agreements.
9. INTERNATIONAL TRANSFERS
Where providers operate outside the EEA:
- Standard Contractual Clauses (SCCs) are used
- Adequacy decisions applied when available
- Additional safeguards implemented where necessary
10. SECURITY MEASURES
Net.AI implements:
- Encryption in transit (TLS)
- Encryption at rest (where applicable)
- Role-based access control
- Multi-factor authentication
- Secure development practices
- Access logging
- Incident response procedures
Security measures are continuously reviewed.
11. COOKIES
We use:
- Essential cookies
- Performance analytics (subject to consent where required)
- Security cookies
Users can manage preferences via cookie banner.
12. DATA SUBJECT RIGHTS
You have the right to:
- Access
- Rectification
- Erasure
- Restriction
- Objection
- Data portability
- Withdraw consent
- Lodge complaint with supervisory authority
Contact: hello@net-ia.biz
13. AUTOMATED DECISION-MAKING
Net.AI does not rely solely on automated decision-making producing legal or significant effects without human involvement.
AI systems support and do not replace responsible decision-making.
14. GOVERNANCE AND COMPLIANCE
Net.AI integrates compliance into its architecture. The company collaborates with external legal counsel specialized in GDPR,
IT law, intellectual property, and AI regulatory frameworks. Compliance documentation is maintained and reviewed periodically.
15. LIMITATION OF LIABILITY
While Net.AI implements strong security and governance measures, it cannot guarantee:
- Absolute immunity from cyber threats
- Search engine indexing outcomes
- AI system ranking behavior
- Third-party platform algorithm decisions
Liability is limited to contractual scope and applicable law.
16. POLICY UPDATES
This Privacy Policy may be updated to reflect:
- Regulatory changes
- Service expansion
- Security improvements
- Corporate modifications
The latest version is always available on this page.