Privacy Policy

NET.AI
GLOBAL PRIVACY POLICY

Effective Date: February 1, 2026
Last Updated: February 1, 2026

Legal Entity: Net.A.I OÜ Registry Code: 17436121 VAT: EE102954847 Registered Address: Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia Business Activity: 70201 – Business and other management consultancy activities Contact: hello@net-ia.biz Website: https://www.net-ai.io

1. INTRODUCTION

Net.AI is a European consulting and AI systems company specializing in strategic AI advisory, authority and visibility structuring (SEO and structured data), operational AI implementation, identity validation protocols (including the 21 News Lexicon), decision-support systems, and AI-powered workflow orchestration.

This Privacy Policy explains how personal data is collected, processed, stored, and protected across the entire Net.AI ecosystem in compliance with Regulation (EU) 2016/679 (GDPR) and applicable European and Estonian data protection laws.

This policy applies to:

  • https://www.net-ai.io
  • All subpages (AI advisory, AI solutions, SEO and visibility, contact forms, blog)
  • 21 News Lexicon
  • Client projects
  • Demo bookings
  • Newsletter subscriptions
  • Any digital interaction with Net.AI

2. DATA CONTROLLER

The Data Controller is Net.A.I OÜ (details above). Net.A.I OÜ acts as:

  • Data Controller for website and service-related processing.
  • Data Processor when delivering AI systems on behalf of clients, under contractual instruction.

3. CATEGORIES OF PERSONAL DATA

A. Website Visitors

  • Name
  • Email
  • Company
  • IP address
  • Device and browser information
  • Session activity
  • Cookies and analytics data

B. Prospects and Clients

  • Professional details
  • Business contact information
  • Communication records
  • Contractual information
  • Billing data

C. AI Advisory and Implementation Projects

When delivering AI systems, we may process:

  • Operational workflow data
  • CRM data (when acting as processor)
  • Business intelligence inputs
  • Decision-support datasets
  • Limited personal data strictly required for project execution

Net.AI does not claim ownership of client data and processes it only under contractual instruction.

D. 21 News Lexicon and Authority Services

  • Identity verification data (if required)
  • Professional biography data
  • Public reputation data
  • Media content
  • Ground truth reference files (if selected plan requires anchoring)

E. AI Systems Interaction Data

When AI-powered systems are deployed, we may process:

  • User inputs
  • Transcriptions (if applicable)
  • Interaction logs
  • System outputs

Such data is processed solely for service delivery and improvement within agreed scope.

4. PURPOSES OF PROCESSING

Personal data is processed for:

  • Strategic consulting delivery
  • AI solution implementation
  • SEO and authority structuring
  • Knowledge Graph optimization
  • Fraud prevention
  • Identity validation (when applicable)
  • Customer communication
  • Invoicing and accounting
  • Service improvement
  • Legal compliance
  • Security monitoring

Net.AI does not use personal data for unrelated advertising resale or data brokerage.

5. LEGAL BASES (GDPR)

Processing relies on one or more of the following legal bases:

  • Consent
  • Contractual necessity
  • Legal obligation
  • Legitimate interest
  • Explicit consent for biometric data (if applicable)

6. AI-SPECIFIC PROCESSING PRINCIPLES

Net.AI applies responsible AI principles:

  • Human oversight over critical decisions
  • No fully automated legal decisions without review
  • Data minimization in model interactions
  • Avoidance of unnecessary data retention
  • Secure API-level integrations

AI tools are used as processing instruments, not autonomous legal authorities.

7. DATA RETENTION

Retention varies by context:

  • Website inquiries: up to 24 months
  • Client contracts: duration plus statutory retention (7 to 10 years)
  • AI project logs: duration of mandate unless agreed otherwise
  • Identity validation materials: retained only as necessary
  • Lexicon profiles: duration of publication plus archival period

Data is deleted or anonymized once no longer required.

8. SUBPROCESSORS (CATEGORIES)

Net.AI may use third-party providers in the following categories:

  • Cloud hosting and infrastructure
  • Content delivery networks
  • Payment processors
  • Email and transactional messaging providers
  • Form and scheduling tools
  • AI model providers
  • DevOps and version control platforms
  • Monitoring and logging services
  • Security services

Processors are bound by confidentiality and data protection agreements.

9. INTERNATIONAL TRANSFERS

Where providers operate outside the EEA:

  • Standard Contractual Clauses (SCCs) are used
  • Adequacy decisions applied when available
  • Additional safeguards implemented where necessary

10. SECURITY MEASURES

Net.AI implements:

  • Encryption in transit (TLS)
  • Encryption at rest (where applicable)
  • Role-based access control
  • Multi-factor authentication
  • Secure development practices
  • Access logging
  • Incident response procedures

Security measures are continuously reviewed.

11. COOKIES

We use:

  • Essential cookies
  • Performance analytics (subject to consent where required)
  • Security cookies

Users can manage preferences via cookie banner.

12. DATA SUBJECT RIGHTS

You have the right to:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Data portability
  • Withdraw consent
  • Lodge complaint with supervisory authority

Contact: hello@net-ia.biz

13. AUTOMATED DECISION-MAKING

Net.AI does not rely solely on automated decision-making producing legal or significant effects without human involvement. AI systems support and do not replace responsible decision-making.

14. GOVERNANCE AND COMPLIANCE

Net.AI integrates compliance into its architecture. The company collaborates with external legal counsel specialized in GDPR, IT law, intellectual property, and AI regulatory frameworks. Compliance documentation is maintained and reviewed periodically.

15. LIMITATION OF LIABILITY

While Net.AI implements strong security and governance measures, it cannot guarantee:

  • Absolute immunity from cyber threats
  • Search engine indexing outcomes
  • AI system ranking behavior
  • Third-party platform algorithm decisions

Liability is limited to contractual scope and applicable law.

16. POLICY UPDATES

This Privacy Policy may be updated to reflect:

  • Regulatory changes
  • Service expansion
  • Security improvements
  • Corporate modifications

The latest version is always available on this page.