Privacy policy

Last updated: July 11, 2026

This policy explains how Votting Group OÜ ("Juvo", "we", "us", "our") collects, uses and protects personal data when you visit our website, contact us, or use our services. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian data protection law.

1. Who is responsible for your data

The data controller is Votting Group OÜ, registered in Estonia. For any question about this policy or about how your personal data is handled, contact us at info@juvolegal.com.

2. What personal data we collect

We collect the following categories of personal data, depending on how you interact with us:

Uploaded documents sometimes also contain personal data of third parties who do not interact with us directly (for example, the name of a counterparty's representative or a contact named in the document). Where we process such data that we have not obtained directly from the data subject, we may not be able to notify them individually. In that case we rely on Article 14(5)(b) of the GDPR, which allows us to depart from the individual-notification duty where it would prove impossible or would involve disproportionate effort; we have taken measures to protect the rights and freedoms of those data subjects, including making this policy publicly available.

We process personal data only where we have a lawful basis to do so:

We do not make automated decisions about you, including profiling, that produce legal or similarly significant effects on you. If you do not provide the account data referred to in this policy, we will not be able to set up your access to the service or provide it.

4. Documents you submit are not used to train models

Documents you or your organisation upload, such as policies, terms and contracts, are processed solely to provide you with the service you requested, for example to identify where a document may fall behind a legal requirement, or to generate a review or answer. These documents, and any personal data they contain, are not used to train any underlying model or shared for any purpose unrelated to delivering the service to you.

Where a cloud-based AI model is used to analyse a document, identifiable personal data (for example, names, email addresses and national identification numbers) is removed from the document by an automated anonymisation process before it is sent to that model.

5. How long we keep your data

Personal data is not retained for longer than necessary for the purpose described in this policy. Data is deleted or anonymised as soon as it is no longer needed, unless applicable Estonian or EU law requires a specific longer retention period (for example, for accounting records), in which case we keep it for that statutory period:

6. Hosting and sub-processors

The infrastructure we use to provide the service is located within the European Union and the European Economic Area: authentication and the application database (Supabase) in Frankfurt, Germany; the analysis engine, its database, and the document-search vector database (Qdrant) in Finland. The infrastructure used to route web requests (Vercel) is also being pinned to Frankfurt, Germany. We use a limited number of carefully selected service providers to operate the website and service, for example for hosting, email delivery and payment processing where applicable. Any sub-processor that handles personal data on our behalf is bound by a data processing agreement requiring at least the same standard of protection as this policy, and is required to process data only on our documented instructions. An up-to-date list of sub-processors is available on request at info@juvolegal.com.

7. International transfers

By default, document analysis is processed using the Google Gemini service, whose infrastructure is located in the US. Before a document is sent to that service, identifiable personal data (for example, names, email addresses and national identification numbers) is removed from it by an automated anonymisation process running on our own server in the European Union, as described in section 4 above; personal data does not reach the US-based model in identifiable form. This transfer is safeguarded by either the European Commission's standard contractual clauses (GDPR Article 46(2)(c)) or the recipient's certification under the EU-U.S. Data Privacy Framework, depending on which mechanism applies. If a Customer uses its own AI API key within the service (a "bring your own model" option), any processing carried out through that key is governed by the Customer's own agreement with its chosen AI provider, not by this policy.

8. Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including access controls, encryption in transit, and regular review of our security practices. No system can be guaranteed completely secure, but we work to keep risk to a minimum and to respond promptly if an issue arises.

9. Your rights

Under the GDPR, you have the right to:

To exercise any of these rights, contact us at info@juvolegal.com. We will respond within the timeframe required by law. If you are not satisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI, www.aki.ee), or, if you live in another EU member state, with the data protection authority of that state.

10. Cookies

We use essential cookies necessary for the website to function, and, where you consent, cookies that help us understand how the website is used. You can control or withdraw cookie consent at any time through your browser settings. See our cookie policy for details.

11. Children

Our website and services are directed at businesses and professionals acting in their professional or business capacity, and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. Where consent to an information society service is given by a child, the statutory age threshold under section 8 of the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) is 13; below that age, consent is valid only if given by the child's legal representative. Our own 18-and-over threshold is a stricter business policy choice, not a statutory minimum.

12. Changes to this policy

We may update this policy from time to time, for example to reflect changes in our practices or in applicable law. The date at the top of this page shows when it was last updated. Material changes will be communicated to account holders where appropriate.

13. Contact us

If you have any questions about this policy or how we handle your personal data, contact Votting Group OÜ at info@juvolegal.com.