Policy draft — awaiting review and publication. This is the supplied Human Intel draft. Online purchasing remains unavailable until the required policies and payment setup are ready.
Privacy Policy
Last updated: 5 October 2026
1. Who is responsible for personal data
Human Intel OÜ, Tornimäe tn 3/5/7, 10145 Tallinn, Estonia, is the controller for personal data used to operate Export Compliance Desk, manage customer relationships and maintain our own service records. Registration number: 16384008. VAT number: EE102473098. Privacy contact: csk@humanintel.eu.
This policy covers the desk’s website, accounts, orders, export assessments and related enquiries. If a particular engagement involves processing personal data solely on a business customer’s instructions, the relevant controller and processor responsibilities must also be addressed in the applicable data-processing agreement.
2. Information we process and its sources
- Account and contact information: your name, work email, company, account identifier, password authentication information and support correspondence.
- Order information: case and payment references, payment status, price, tax-related information available to us and records of your acceptance of terms.
- Case information: product and transaction details, exporter, buyer, end-user and intermediary details, routes, documents, report findings and relevant source records. Business documents can contain names, signatures, addresses and other information about individuals.
- Technical information: IP addresses, browser and device information, authentication and security information, and cookies described in the Cookie Policy. The desk uses IP-derived information to limit repeated requests; hosting or security services may also keep access logs.
We receive information directly from you and your authorised colleagues, from submitted documents, from Stripe’s payment confirmations, and from relevant official or publicly available sources used in an assessment. Where another person supplies your information, it may relate to your role as a business contact or a party to an export transaction.
3. Purposes and legal bases
| Purpose | Legal basis under the GDPR |
|---|---|
| Provide an account and the assessment requested by an individual contracting customer; respond to that person’s pre-contract enquiries | Performance of a contract or steps requested before a contract, Article 6(1)(b) |
| Provide services to a company, communicate with its representatives, analyse necessary case information and support users | Legitimate interests, Article 6(1)(f): delivering the requested business service and managing business relationships, balanced against individuals’ rights |
| Keep required accounting records and respond to binding legal obligations | Legal obligation, Article 6(1)(c) |
| Protect accounts, limit abuse, investigate incidents and establish or defend legal claims | Legitimate interests, Article 6(1)(f): service security and protection of lawful rights; legal obligation where a specific duty applies |
| Optional processing that specifically requires consent, if introduced | Consent, Article 6(1)(a), which can be withdrawn for future processing |
We collect only information reasonably needed for these purposes. Accepting the terms or confirming that you may submit documents is not blanket GDPR consent for every use. We do not ask customers to upload special-category personal data or criminal-offence data through the standard service. Contact us before submitting material needing a different lawful handling arrangement.
4. AI-assisted processing
Submitted case details and documents may be transmitted to Anthropic’s Claude API to extract information, produce preliminary findings and research official sources. Relevant details may therefore be included in prompts and search queries. Only submit material you are authorised to disclose and remove unnecessary personal information.
AI-generated findings can be incomplete or wrong. The report is advisory and does not itself determine legal rights, issue licences, clear sanctions, certify conformity or authorise shipment. It requires human verification and final decisions by the exporter and relevant responsible people. Contact us if you need a finding reviewed or corrected.
Provider retention and other handling of submitted content depend on the applicable commercial agreement, account settings, model and safety or legal exceptions. Information about Anthropic’s commercial data handling is available at Anthropic’s Privacy Center. We do not claim that submitted content is processed without any retention.
5. Who may receive information
Access is limited to authorised Human Intel personnel and providers involved in delivering, supporting or securing the service. Recipient categories include:
- Stripe for hosted checkout, payment processing, applicable tax calculation, fraud prevention and payment administration. Card details are entered on Stripe’s checkout page; the desk does not request or store full payment-card numbers or card security codes.
- Anthropic for AI processing and supported research tools.
- Simply.com A/S for website hosting. Our website hosting is in Denmark; Simply.com identifies its servers and data as located in Denmark at team.blue Denmark A/S data centres. Hosting-related data is covered by the applicable processing agreement. Email, backup, security or other providers may be involved according to the services configured for this website.
- Professional advisers, accountants and competent authorities where necessary for a lawful purpose or legal obligation.
- Google Fonts, where the staff interface requests external font files: the browser sends normal connection information, such as an IP address, to the font service.
We do not sell personal data. We do not send a case to your buyer simply because you enter the buyer’s details. Additional sharing with a buyer, broker or specialist is arranged as part of your instructions or a separately agreed service. Stripe may act as an independent controller for some payment, compliance and fraud-prevention purposes; see Stripe’s Privacy Policy.
6. International transfers
Our Simply.com website hosting is in Denmark, within the European Economic Area. This does not mean that every separate payment, AI, email or support operation is located there. Those service providers and their support or processing operations may be located outside the European Economic Area, including in the United States. The countries and safeguards depend on the providers and service arrangements used.
Transfers requiring GDPR safeguards must use an applicable adequacy decision covering the recipient or appropriate safeguards, such as European Commission Standard Contractual Clauses and any necessary supplementary measures. Contact us for information about the relevant recipients, locations and a copy or explanation of the applicable safeguards, subject to appropriate redaction of confidential details.
7. Retention
We keep personal data for the purposes for which it was collected and for applicable legal obligations, rather than indefinitely. Retention is determined by these criteria:
- Account information: while the account is needed for an active customer relationship or access to purchased cases, followed by any period needed to resolve outstanding matters or retain required records.
- Case details, documents and reports: for completion and support of the purchased review, relevant follow-up, and any justified record-keeping, claim or legal-retention requirement. Submission snapshots may retain evidence that cannot be removed through the ordinary upload screen; you can still make a privacy request.
- Enquiries: until the enquiry and any reasonable follow-up are complete, with relevant correspondence retained where needed for the customer relationship or a dispute.
- Security information: for the period reasonably needed to prevent and investigate abuse or incidents, with longer retention only where an incident or legal duty justifies it.
- Accounting source records: generally seven years from the end of the financial year in which the transaction was recorded, under Estonian accounting requirements; other legal duties may require a different period.
When information is no longer needed, it should be deleted or anonymised through our retention and deletion processes. Copies in backups may remain until the relevant backup cycle ends and must remain protected. Provider-held data can follow separate contractual or statutory retention rules. Closing an account does not automatically erase records we must or are lawfully entitled to retain.
8. Security
The desk uses account-based access controls and stores uploaded evidence in a private directory outside the public website root when correctly configured. Payment credentials and AI keys are handled on the server. We apply proportionate organisational and technical protections; no online system can guarantee absolute security. Protect your password and tell us promptly if you suspect an incident.
9. Your rights and complaints
Depending on the legal conditions, you may request access, correction, erasure, restriction, portability of relevant data, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. Some rights are subject to exceptions, including necessary legal record retention.
Send a request to csk@humanintel.eu. We may need proportionate information to verify your identity. We normally respond within one month; if a permitted extension is needed, we will explain it within that period.
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee, or another supervisory authority competent under the GDPR. You do not need to contact us first to exercise that right.
10. Required information, children and updates
The standard service is for authorised adult business users. Required account, payment and case fields are needed to provide the requested service; without them we may be unable to open a case or complete an assessment. Optional information should be limited to what is relevant.
We may update this policy to reflect changes in the service or data handling. Material changes will be communicated as appropriate. The date at the top identifies this version.