Privacy policy
This policy explains how Votting Group OÜ ("Juvo", "we", "us", "our") collects, uses and protects personal data when you visit our website, contact us, or use our services. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian data protection law.
1. Who is responsible for your data
The data controller is Votting Group OÜ, registered in Estonia. For any question about this policy or about how your personal data is handled, contact us at info@juvolegal.com.
2. What personal data we collect
We collect the following categories of personal data, depending on how you interact with us:
- Account data. Name, work email address, employer or organisation, role, and login credentials, when you or your organisation set up access to the service.
- Contact and sales enquiry data. Name, email address, phone number, company details and any information you choose to include in a message, when you contact us through the website, by email, or in the course of a sales discussion.
- Usage data. Information about how the service is accessed and used, such as login times, pages viewed, feature interactions, device and browser type, and IP address. This is used to operate, secure and improve the service.
- Documents you upload. Where our service is used to review policies, terms, contracts or other documents, those documents and any personal data they contain (for example, the names of signatories or contacts) are processed in order to provide the service to you.
Uploaded documents sometimes also contain personal data of third parties who do not interact with us directly (for example, the name of a counterparty's representative or a contact named in the document). Where we process such data that we have not obtained directly from the data subject, we may not be able to notify them individually. In that case we rely on Article 14(5)(b) of the GDPR, which allows us to depart from the individual-notification duty where it would prove impossible or would involve disproportionate effort; we have taken measures to protect the rights and freedoms of those data subjects, including making this policy publicly available.
3. Why we process your data, and our legal basis
We process personal data only where we have a lawful basis to do so:
- Performance of a contract. To create and administer an account, deliver the service, process the documents you submit, and provide support, where you or your organisation are a party to an agreement with us.
- Legitimate interests. We process data on the basis of legitimate interests (GDPR Article 6(1)(f)) for specific purposes: keeping our systems and data secure, preventing fraud and misuse, responding to enquiries, and improving our service. Before relying on this basis, we weigh these interests against your rights and freedoms (GDPR Article 13(1)(d)); where that balance does not favour us, we do not rely on it.
- Consent. Where required, for example for non-essential cookies or for marketing communications you have opted into. You may withdraw consent at any time.
- Legal obligation. Where we are required to retain or disclose data to comply with applicable law.
We do not make automated decisions about you, including profiling, that produce legal or similarly significant effects on you. If you do not provide the account data referred to in this policy, we will not be able to set up your access to the service or provide it.
4. Documents you submit are not used to train models
Documents you or your organisation upload, such as policies, terms and contracts, are processed solely to provide you with the service you requested, for example to identify where a document may fall behind a legal requirement, or to generate a review or answer. These documents, and any personal data they contain, are not used to train any underlying model or shared for any purpose unrelated to delivering the service to you.
Where a cloud-based AI model is used to analyse a document, identifiable personal data (for example, names, email addresses and national identification numbers) is removed from the document by an automated anonymisation process before it is sent to that model.
5. How long we keep your data
Personal data is not retained for longer than necessary for the purpose described in this policy. Data is deleted or anonymised as soon as it is no longer needed, unless applicable Estonian or EU law requires a specific longer retention period (for example, for accounting records), in which case we keep it for that statutory period:
- Account and usage data. For the duration of your account or engagement with us. After account closure or the end of the engagement, we delete this data once it is no longer needed to meet legal, accounting or dispute-resolution requirements; we retain it for longer only to the extent and for as long as applicable law requires.
- Invoices and other primary accounting records. Seven years from the end of the relevant financial year, as required by section 12(1) of the Estonian Accounting Act (Raamatupidamise seadus).
- Contact and sales enquiry data that does not lead to an ongoing relationship. Retained only for as long as necessary to handle the enquiry and for a reasonable follow-up period, after which it is deleted or anonymised, unless the law requires longer retention.
- Documents you upload and their analysis results. Deleted at the end of the engagement once no longer needed for the purposes described in this policy, or sooner if you request deletion; retained for longer only to the extent applicable law requires.
6. Hosting and sub-processors
The infrastructure we use to provide the service is located within the European Union and the European Economic Area: authentication and the application database (Supabase) in Frankfurt, Germany; the analysis engine, its database, and the document-search vector database (Qdrant) in Finland. The infrastructure used to route web requests (Vercel) is also being pinned to Frankfurt, Germany. We use a limited number of carefully selected service providers to operate the website and service, for example for hosting, email delivery and payment processing where applicable. Any sub-processor that handles personal data on our behalf is bound by a data processing agreement requiring at least the same standard of protection as this policy, and is required to process data only on our documented instructions. An up-to-date list of sub-processors is available on request at info@juvolegal.com.
7. International transfers
By default, document analysis is processed using the Google Gemini service, whose infrastructure is located in the US. Before a document is sent to that service, identifiable personal data (for example, names, email addresses and national identification numbers) is removed from it by an automated anonymisation process running on our own server in the European Union, as described in section 4 above; personal data does not reach the US-based model in identifiable form. This transfer is safeguarded by either the European Commission's standard contractual clauses (GDPR Article 46(2)(c)) or the recipient's certification under the EU-U.S. Data Privacy Framework, depending on which mechanism applies. If a Customer uses its own AI API key within the service (a "bring your own model" option), any processing carried out through that key is governed by the Customer's own agreement with its chosen AI provider, not by this policy.
8. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including access controls, encryption in transit, and regular review of our security practices. No system can be guaranteed completely secure, but we work to keep risk to a minimum and to respond promptly if an issue arises.
9. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you;
- Request rectification of inaccurate or incomplete data;
- Request erasure of your data, where applicable;
- Request restriction of processing, in certain circumstances;
- Request a portable copy of the data you provided to us;
- Object to processing carried out on the basis of legitimate interests; and
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at info@juvolegal.com. We will respond within the timeframe required by law. If you are not satisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI, www.aki.ee), or, if you live in another EU member state, with the data protection authority of that state.
10. Cookies
We use essential cookies necessary for the website to function, and, where you consent, cookies that help us understand how the website is used. You can control or withdraw cookie consent at any time through your browser settings. See our cookie policy for details.
11. Children
Our website and services are directed at businesses and professionals acting in their professional or business capacity, and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. Where consent to an information society service is given by a child, the statutory age threshold under section 8 of the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) is 13; below that age, consent is valid only if given by the child's legal representative. Our own 18-and-over threshold is a stricter business policy choice, not a statutory minimum.
12. Changes to this policy
We may update this policy from time to time, for example to reflect changes in our practices or in applicable law. The date at the top of this page shows when it was last updated. Material changes will be communicated to account holders where appropriate.
13. Contact us
If you have any questions about this policy or how we handle your personal data, contact Votting Group OÜ at info@juvolegal.com.