EPAV DESK · PRIVACY POLICY
Version 1.0 · Effective from 9 October 2026
Controller: NeriusCognitaren OÜ, registry code 17503018, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia ("EPAV", "we", "us")
Data protection: privacy@epavdesk.com · Support: support@epavdesk.com
1. What this policy covers
1.1 This policy explains how we process personal data as a controller in connection with EPAV Desk:
- when you create and use a cabinet at my.epavdesk.com, and pay for a subscription;
- when you send an enquiry through the form on epavdesk.com;
- when you contact our support by email, or through the chat on epavdesk.com and in our documentation at docs.epavdesk.com;
- when you visit epavdesk.com, my.epavdesk.com and docs.epavdesk.com.
Our studio website epavai.com has its own privacy policy.
1.2 Where we are not the controller. When a company uses EPAV Desk to talk to its own customers, that company is the controller of the conversations, contacts and knowledge base in its Site, and we process them only on its behalf, under our Data Processing Agreement. If you wrote to a company through a chat, email, Telegram or WhatsApp channel that runs on EPAV Desk, that company's privacy notice applies, and you should contact it to exercise your rights. If you write to us instead, we pass your request on to it.
1.3 We have not appointed a data protection officer, because the GDPR does not require one for us. For any question about your data, write to privacy@epavdesk.com.
2. What data we process, why, and on what basis
2.1 Your cabinet account
- Data: company name, email address, password (stored only as a salted hash), language, the time zone and languages of your browser at sign-up (used to set up your Site), the date of sign-up, of email confirmation and of the last sign-in, and settings you choose. If you use the EPAV mailbox, the email addresses of the colleagues you add for it.
- Why: to create your cabinet and Site, let you sign in, and provide the service you ordered.
- Basis: performance of the contract (Article 6(1)(b) GDPR). For the colleagues you add to the EPAV mailbox, who are not parties to the contract: our legitimate interest in delivering the notifications you set up for them (Article 6(1)(f)).
2.2 Subscription and payments
- Data: your plan and level, subscription status, dates paid until, overage invoices, and the identifiers that creem gives us for your subscription and customer record. We pass creem your email address, your cabinet number and the chosen plan.
- Card details are entered on creem's page and never reach us. creem processes payment data as merchant of record under its own privacy policy.
- For a bank transfer: the company details on the invoice.
- Why: to take payment, apply your plan, handle failed payments and keep accounting records.
- Basis: performance of the contract; for accounting records, our legal obligation (Article 6(1)(c)).
2.3 Emails we send you
- Data: your email address and the content of service emails: confirmation of your email, your Site being ready, trial reminders, payment, limits and AI budget notices, cancellation, deletion and notices about changes to our terms.
- Why and basis: these are part of the service (performance of the contract) or required by law. We do not send marketing newsletters. If we ever want to, we will ask for your consent first.
2.4 Support and our chats
- Data: what you write to support@epavdesk.com or in the chat on our websites and docs.epavdesk.com, your name and email address if you give them, and the technical data of the chat: IP address, browser user agent and language, recorded when a conversation starts, and the last pages visited, kept for 24 hours. The chat's cookies are listed in our Cookie Policy.
- The chat on our websites is answered first by an AI assistant, which says so in its first message. To answer, your message and the relevant parts of our own knowledge base are processed by our AI gateway and, depending on availability, by OpenRouter and the model hosts behind it, by Voyage AI, or by EPAV's own model (see Section 4).
- Why: to answer you and to keep a record of what was agreed.
- Basis: our legitimate interest in answering enquiries and supporting our customers (Article 6(1)(f)), or the contract when you are a customer.
2.4a Enquiries through our website
- Data: what you enter in the form on epavdesk.com (your name, email address and message), with the address of your connection and browser data that we use to protect the form against spam.
- Why: to answer your enquiry and, if you ask, prepare an offer.
- Basis: steps at your request before entering into a contract (Article 6(1)(b)), and our legitimate interest in answering enquiries and keeping the form free of spam (Article 6(1)(f)).
- The form is stored in our own sales system, which runs on our hosting provider.
2.5 Security, abuse prevention and records
- Data: an event log of actions in the cabinet and on Sites (for example sign-up with company name, email and language; payments; plan changes; deletion requests), sign-in sessions, and the technical data our hosting and network providers process to deliver and protect the service, such as IP addresses.
- Why: to keep the service secure, investigate faults and abuse, enforce our Terms, and be able to show what happened.
- Basis: our legitimate interest in a secure and reliable service (Article 6(1)(f)).
2.6 Usage of your Site
- Data: usage figures that we read from your Site and show in your cabinet (Section 11.5 of the Terms).
- These figures are processed as part of the service. Where they contain personal data of your Visitors or Agents, we process them as your processor under the Data Processing Agreement.
- We may use them in anonymous, aggregated form to improve EPAV Desk, based on our legitimate interest.
2.7 No automated decisions, no profiling, no training
We do not make decisions about you that have legal or similarly significant effects by automated means only, and we do not profile you for advertising. We do not use your data or the content of your Site to train AI models.
3. How long we keep it
| Data | How long |
|---|---|
| Cabinet account | Until you ask us to delete it. We delete it within 7 days of the request |
| Sign-in sessions | 30 days; expired sessions and one-time email links are deleted 7 days after they expire |
| Event log | 400 days (about 13 months). When we delete an account, a record of the deletion with the company name and email address stays in the log for this period |
| Addresses of colleagues added to the EPAV mailbox | Until you remove them or your account is deleted |
| Backups of our cabinet database | Replaced as they expire under our hosting provider's schedule |
| Usage figures of a Site | Until the Site is removed |
| Accounting records (invoices and payment records) | 7 years from the end of the financial year, as Estonian accounting law requires |
| Support emails, enquiries and chat conversations with us | As long as needed to handle your request and keep a record of our dealings with you, and no longer than 3 years after the last message |
| EPAV mailbox sending journal | 2 days |
4. Who receives your data
We share personal data only with these recipients, and only as far as needed:
| Recipient | Role and purpose | Location and transfer basis |
|---|---|---|
| Railway Corporation | Hosting of the cabinet, Sites, our AI gateway and the chat | Sites and our AI gateway in the EU West region (Amsterdam); a US company. EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Cloudflare, Inc. | DNS and network services for our domains; receiving email sent to our addresses | Global network; a US company. Data Privacy Framework and Standard Contractual Clauses |
| Google LLC (Gmail) | The mailbox that receives email to our support address | United States. EU-U.S. Data Privacy Framework (Google LLC is certified) |
| Sand Dune Mail Ltd (SMTP2GO) | Delivery of the emails we send | EU servers; a New Zealand company. Adequacy decision for New Zealand |
| creem (Armitage Labs OÜ) | Sale of the subscription as merchant of record: payment, invoice, VAT. An independent controller | Estonia |
| OpenRouter, Inc., and the model hosts behind it; Voyage AI (MongoDB) | AI processing of messages in the chat on our websites and documentation, as listed in our Sub-processor List | United States and other countries as listed there. Data Privacy Framework or Standard Contractual Clauses |
| Our accountants | Bookkeeping of invoices for bank transfers | Estonia (Xolo); for invoices in Ukrainian hryvnia, an accountant in Ukraine. Ukraine has no adequacy decision; we pass only the details needed for the invoice you asked for |
| Authorities and courts | Where the law requires us to disclose data, or to establish or defend legal claims |
We do not sell personal data and do not share it for advertising.
5. Transfers outside the EEA
Some recipients are established or process data outside the European Economic Area, mainly in the United States. We rely on adequacy decisions of the European Commission (including the EU-U.S. Data Privacy Framework for certified companies) or on the Standard Contractual Clauses adopted by the Commission. For messages in our chats, OpenRouter may pass a request to a model host outside the EEA, including in countries without an adequacy decision, under its own terms with that host, as our Sub-processor List describes. For invoices in Ukrainian hryvnia, the invoice details go to our accountant in Ukraine. You can ask us for more information about these safeguards at privacy@epavdesk.com.
6. Your rights
Under the GDPR you have the right to:
- access your personal data and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict processing;
- receive the data you gave us in a portable format;
- withdraw consent at any time, where processing is based on consent;
- complain to a supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, https://www.aki.ee. You can also complain in the EU country where you live or work.
Your right to object. Where we process your data on the basis of our legitimate interest (Sections 2.4 to 2.6), you may object at any time on grounds relating to your situation, and we will stop unless we have compelling legitimate grounds or need the data for legal claims.
To exercise a right, write to privacy@epavdesk.com from the email address of your account, or tell us how we can confirm it is you. It is free of charge. We reply within one month; for complex or numerous requests we may extend this by two further months and will tell you why. You can also ask for your account to be deleted with the button at the bottom of the cabinet; we delete it within 7 days. We may refuse requests that are manifestly unfounded or excessive.
Do you have to give us your data? The data in Section 2.1 is needed to create a cabinet and provide the service; without it we cannot conclude the contract. Accounting data is required by law. Everything else, such as what you write to our support, is up to you.
7. Security
We protect personal data with technical and organisational measures appropriate to the risk, described in Annex 2 of our Data Processing Agreement. For example, passwords of the cabinet are stored only as hashes, the encryption key of each Site is stored encrypted, and our services are reached over HTTPS.
8. Children
EPAV Desk is a service for businesses and is not directed at children. We do not knowingly collect data of children for our own purposes.
9. Cookies
The cabinet sets two cookies, for your session and your language. Our Cookie Policy describes them, and the cookies and browser storage that Sites and the chat use.
10. Changes to this policy
We may update this policy. We publish every version with its date, and tell account owners about material changes by email at least 15 days before they take effect.
11. Contact
NeriusCognitaren OÜ · Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia · privacy@epavdesk.com