Ryniqo OÜ · Legal Pack
Legal · Privacy

Privacy Policy

This Policy explains how Ryniqo OÜ (“Ryniqo”, “we”) processes personal data as a controller for its marketing site and as a processor for the RynIQ™ Executive Decision Intelligence Platform. It is written to be read by Data Protection Officers, procurement teams, and the executives whose data we handle.

Version2.0EffectiveOn publication
Supersedes1.0 (2025)Governing lawEstonia · EU
Section 01

Controller and contact

The controller for personal data processed via ryniqo.com and the RynIQ™ platform is Ryniqo OÜ, a private limited company incorporated in the Republic of Estonia and entered on the Estonian Commercial Register (e-Business Register maintained by the Centre of Registers and Information Systems).

Privacy enquiries and rights requests: privacy@ryniqo.com. We respond to substantive requests within one calendar month, extendable by two further months for complex requests under Article 12(3) GDPR.

A Data Protection Officer is not required under Article 37 GDPR. Privacy accountability sits with the Founder and is delegated operationally to the person answering privacy@ryniqo.com.

Section 02

Scope

This Policy applies to (a) visitors to ryniqo.com, (b) individuals who complete the Executive Decision Snapshot™, (c) representatives of prospective and current customers communicating with us, and (d) recipients of the Executive Decision Brief™ and related deliverables.

Where Ryniqo processes personal data on behalf of a customer under a signed order — for example, workshop notes or portfolio data uploaded by a customer — Ryniqo acts as a processor and the customer is controller. In those cases the Data Processing Agreement governs, and this Policy applies only to the extent it describes technical and organisational measures.

Section 03

Categories of data and lawful basis

We process the minimum data required to deliver the Platform and operate our business. We do not knowingly process special-category data (Article 9 GDPR) and ask customers not to submit it.

CategoryPurposeLawful basis (Art. 6)
Identifiers (name, business email, role, company)Deliver the Snapshot and Executive Review; account accessContract performance (1(b)); legitimate interests (1(f))
Assessment responsesGenerate the Snapshot and Executive Decision BriefContract performance (1(b))
Meeting bookings and calendar metadataSchedule Executive Reviews and workshopsContract performance (1(b))
Business correspondence and workshop notesDeliver consulting engagements; internal recordContract performance (1(b)); legitimate interests (1(f))
Usage analytics (pseudonymous)Improve the Platform; measure content performanceLegitimate interests (1(f)); consent where required (1(a))
Marketing contact dataSend updates to prospects and customers who opted in or with whom we have a soft opt-inConsent (1(a)); legitimate interests (1(f)) under PECR-equivalent local rules
Security and audit logsDetect, investigate and remediate incidents; abuse preventionLegitimate interests (1(f)); legal obligation (1(c))

Our legitimate-interest assessments (LIA) balance our commercial interests against the reasonable expectations of data subjects; a summary is available on request to privacy@ryniqo.com.

Section 04

AI processing and human review

The Snapshot and the Executive Decision Brief use machine learning models to structure, cluster and summarise the responses executives provide. No decision that produces legal effects or similarly significant effects on any individual is taken solely by automated means (Article 22 GDPR is not engaged).

Every formal recommendation issued as an Executive Decision Brief is reviewed by a human before delivery. Decision Confidence™ is an evidence indicator, not an autonomous verdict. See the Responsible AI Policy and the AI Transparency Statement.

Customer content is not used to train foundation models. Model providers are contractually bound to zero-retention or short-retention terms. Prompt and response payloads are logged only to the extent required for security, abuse prevention and quality assurance.

Section 05

Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, then delete or irreversibly anonymise it.

RecordRetention
Assessment responses24 months from submission
Executive Decision Briefs36 months from delivery
Contact enquiries12 months from last contact
Usage analytics14 months from event
Marketing listsUntil unsubscribe or 24 months of inactivity
Security and audit logs12 months (extended for open incidents)
Accounting records7 years (Estonian Accounting Act §12)
Section 06

International transfers

Personal data is hosted in the European Economic Area by default. Where a subprocessor processes data outside the EEA — for example, model inference or transactional email — we rely on one of the following Article 46 safeguards:

  • European Commission adequacy decisions (e.g. United Kingdom, Switzerland, EU–US Data Privacy Framework where the recipient is certified);
  • the 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Modules 2 or 3 as applicable, together with a Transfer Impact Assessment;
  • supplementary technical measures such as encryption in transit and at rest and minimisation before transfer.

A copy of the SCCs entered into with any subprocessor is available to enterprise customers on request under NDA.

Section 07

Subprocessors

A current list of subprocessors, the services they perform and their hosting regions is maintained at /legal/subprocessors. Customers can subscribe to change notifications by writing to privacy@ryniqo.com. Objections to a proposed subprocessor are governed by the DPA.

Section 08

Cookies and similar technologies

We use strictly necessary cookies and, subject to consent, analytics cookies. We do not use advertising cookies. See the Cookie Policy for details, categories, retention and browser controls.

Section 09

Security

Technical and organisational measures include TLS 1.2+ in transit, AES-256 at rest, least-privilege access, MFA on all administrative accounts, row-level authorisation at the database, structured audit logging and regular encrypted backups. Full detail is in the Information Security Policy.

Confirmed personal-data breaches are notified to affected controllers without undue delay and, where feasible, within 72 hours (Article 33 GDPR).

Section 10

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time without affecting the lawfulness of prior processing.

Requests should be sent to privacy@ryniqo.com. We may verify identity before acting on a request.

You have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), Tatari 39, 10134 Tallinn, Estonia — info@aki.ee — +372 627 4135 — www.aki.ee.

Section 11

Children

The Platform is intended for use by employees of organisations acting in a professional capacity. It is not directed to children under 16 and we do not knowingly collect personal data from them.

Section 12

Business and enterprise customers

Where Ryniqo processes personal data on behalf of an organisation, that organisation is controller and remains responsible for the lawful basis of its processing and for informing its own personnel. Ryniqo enters into a Data Processing Agreement with every such organisation on request or as part of order paperwork.

Section 13

Account and data deletion

Customers can request deletion of an account and its associated personal data by writing to privacy@ryniqo.com. Deletion is executed within 30 days, subject to legal retention obligations (e.g. accounting) and legitimate interests (e.g. dispute defence).

Section 14

Changes to this Policy

Material changes are announced by updating the version number and effective date and, where appropriate, by individual notice. A version history is maintained in Appendix B.

Section 15

Definitions

Controller
The party that determines the purposes and means of processing personal data.
Processor
The party that processes personal data on behalf of a controller.
Platform
RynIQ™ Executive Decision Intelligence Platform, including the Snapshot, Executive Review and Brief.
Personal data
Any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
GDPR
Regulation (EU) 2016/679.
SCCs
Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914.
Appendix A

Categories of recipients

  • Ryniqo personnel bound by written confidentiality obligations.
  • Subprocessors listed at /legal/subprocessors.
  • Professional advisers (accountants, lawyers, auditors) under duty of confidence.
  • Regulators, courts and law-enforcement bodies where legally required.
  • Acquirers or successors in the event of a merger or reorganisation, under equivalent protection.
Appendix B

Version history

VersionDateSummary
2.0On publicationEnterprise rewrite; added AI processing, transfer, and rights sections.
1.02025Initial policy.