Privacy Notice
Our privacy notice explains how we collect, use, and protect your personal information.
JuttAI – Privacy Notice
Last updated: 12 December, 2025
This Privacy Notice describes how JuttAI (a company incorporated under Estonian law with registry code 17148310 and registered address at Valukoja tn 8/2, Tallinn, 11415, Estonia; “JuttAI,” “we,” “us” or “our”) collects, uses or otherwise processes and safeguards information relating to individuals who visit our website accessible at www.jutt.ai/ and with whom we otherwise interact, including in the course of using our services.
The controller of your personal data is JuttAI. You can contact us by email at data@jutt.ai.
JuttAI is responsible for ensuring that your personal data is processed in accordance with this Privacy Notice and applicable data protection laws, in particular with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
Please note that this Privacy Notice does not apply to the extent we collect and process personal data in the role of a data processor on behalf of our clients, including where we provide our clients JuttAI’s integrated software solutions and other applications through which our clients process personal data by using our platform. Generally, we do not have direct legal relationships with the individuals whose personal data we process on behalf of our clients. Each client is responsible for providing a privacy notice to its individuals concerning the purpose for which our client collects their personal data and how this data is processed.
Our website and services may contain links to external websites or resources. We are not responsible for the content, security, or privacy practices of those external sites. Once you leave our domain, your personal data will be subject to the privacy policies of the respective external site. We encourage you to review those policies before providing any personal data.
1. Personal Data We Collect
In this Privacy Notice, “personal data” is defined as any information relating to an identified or identifiable natural person. We usually collect personal data directly from data subjects or from our clients when data subjects interact with us, including in the course of using our services. The data we collect depends on the context of your relationship and interactions with JuttAI and the choices you make, the exact services and features you use, and applicable data protection law.
1.1. Personal data of our contractual and business partners’ representatives and employees, personal data of the visitors of our websites
Depending on the nature of the relationship between us, we may process the following personal data of our contractual and business partners’ representatives and employees:
- General personal data and contact details: such as your first and last name, e-mail address and phone number;
- Data on the company associated with the data subject: such as name and details of the company, work position or title;
- Data collected in the course of using and engaging with our website and services: such as your IP address, used devices, e-mail and other communications, any usage, navigation, analytics and log data associated with the use and engagement with our website and services. Please note that for such collection of data, we may use cookies or similar technologies, the use of which is described in our cookie notice below;
- Data provided by you or our partners by communicating with us: such as data required for establishing and maintaining a contractual or business relationship, information communicated to us through our website contact form, feedback data and other content collected in customer satisfaction surveys, customer inquiries and support requests, or any other information that you or our partners voluntarily provide to us.
1.2. Personal data of the end-users of our services
End-users are the natural persons who use the services that we offer to our business clients. In most cases, when we process the personal data of the end-users who are using our services, we are in the role of a processor. Our client is usually the controller of the personal data of the end-users. Please refer to the relevant privacy notice of our client (the entity that has integrated our services with their own) to receive more information about how our clients process the personal data of end-users.
As a controller, we may, for limited purposes described below in section 2.2, process the following personal data of the end-users who are using our services:
- Data on analytics about your use of our services (i.e., how you engage with our website and services). Please note that for such collection of data, we may use cookies or similar technologies, the use of which is described in our cookie notice below;
- Responses to chatbot prompts and communications. Any further processing will take place with anonymised data that does not constitute personal data under applicable data protection law.
2. Purposes and Legal Bases for the Processing of Personal Data
2.1. Processing of personal data of our contractual and business partners’ representatives and employees
We may process the personal data of our contractual and business partners representatives and employees for the following purposes and on the legal bases:
- 1) Establishing contractual relationships with our business partners. For these purposes, the legal basis for the processing of your personal data is the performance of a contract (Article 6(1)(b) of the GDPR) and our legitimate interest in establishing and entering into contracts in the course of our ordinary business activities (Article 6(1)(f) of the GDPR).
- 2) Management of contractual and business relationships. For these purposes, the legal basis for processing your personal data is our legitimate interest in maintaining contractual and business relationships, including managing databases of our partners and providing our services to our clients (Article 6(1)(f) of the GDPR).
- 3) Conducting customer satisfaction surveys, managing and responding to customer inquiries and support requests. For these purposes, the legal basis for the processing of your personal data is our legitimate interest in conducting such surveys for business development purposes, managing and responding to such communications which concern our website and services (Article 6(1)(f) of the GDPR).
- 4) Establishing, exercising and defending any potential legal claims. Where necessary for taking action on such legal claims, and for compliance, regulatory and investigative purposes, which all may derive from legal relationships with our partners, the legal basis for the processing of your personal data is our legitimate interest (Article 6(1)(f) of the GDPR).
- 5) Complying with our legal obligations deriving from applicable law. For these purposes, the legal basis for the processing of your personal data is the respective legal provision obliging us to process the relevant data (in accordance with Article 6(1)(c) of the GDPR). Such legal obligations may derive, for example, from accounting and tax laws.
- 6) Improving and developing our website and services, including for security purposes. For these purposes, the legal basis for the processing of your personal data is our legitimate interest in improving our understanding of our partners’ needs and preferences in order to constantly enhance the functioning of our website and services, including by conducting analytics, improve access to content that JuttAI publishes and to ensure the technical availability and security of our website and services (Article 6(1)(f) of the GDPR). Note that where we use cookies and similar technologies for this purpose, we do so in accordance with our cookie notice, and to the extent the cookies and similar technologies used are not essential for the operation of our website and services, we ask for your consent for the placement of cookies.
- 7) Marketing, including direct marketing of JuttAI’s services. For this purpose, the legal basis for the processing of your personal data is our legitimate interest in advertising our services and other products, in particular to establish contractual and business relationships with the company you represent (Article 6(1)(f) of the GDPR). If you are an individual who subscribes to receive our marketing communications, the legal basis for processing your personal data is your consent (Article 6(1)(a) of the GDPR). In any case, you may object to receiving such marketing information every time such marketing is provided. Note that where we use marketing cookies and similar technologies for marketing purposes, we do so in accordance with our cookie notice below, and we ask for your consent for the placement of marketing cookies.
2.2. Processing of personal data of the end-users of our services
When we process the personal data of end-users, we are usually in the role of a processor, but for some limited personal data processing activities, we act as the controller. This is the case where we process personal data for the following purposes and on the following legal bases:
- 1) Improving our services and conducting other research and development activities with anonymised data. For these purposes, we may process the responses to chatbot prompts and other communications, and this requires us to process this information by anonymising them. Following the anonymisation, the data is no longer personal data that can be connected to you. The legal basis for the processing of your personal data (i.e., anonymising) is our legitimate interest in improving our services and conducting other research and development activities (Article 6(1)(f) of the GDPR).
- 2) Improving and developing our website and services, including for security purposes. For these purposes, the legal basis for the processing of your personal data (which does not include special categories of your personal data) is our legitimate interest in improving our understanding of the personalised needs and preferences of the end-users of our website and services in order to constantly enhance the functioning of our website and services, including by conducting analytics, improve access to content that JuttAI publishes and to ensure the technical availability and security of our website and services (Article 6(1)(f) of the GDPR). If we use cookies and similar technologies for this purpose, we do so in accordance with our cookie notice below, and to the extent the cookies and similar technologies used are not essential for the operation of our website and services, we ask for your consent for the placement of cookies.
- 3) Marketing of JuttAI and its services. We may use different marketing tools, such as targeted advertising, that also affect the end-users of our services. We use marketing cookies and similar technologies for such marketing purposes. We ask for your consent for the placement of marketing cookies. If you have given consent for the marketing cookies, the legal basis for the further processing of your personal data is our legitimate interest in advertising our services and other products (Article 6(1)(f) of the GDPR).
3. Disclosure and Transfer of Personal Data
We put our best efforts to keep your personal data safe and always require a high level of security and confidentiality from our employees and partners. We may share certain categories of your personal data:
- with our trusted service providers when they provide services to us or to you, on behalf of us and under our instructions, such as cloud-based service providers, legal service providers, payment and accounting service providers, etc. We will control and shall remain responsible for the use of your personal data in such cases;
- with our partners who market or support our services;
- with our partners, who provide us with tools for analytics (who may, in particular, process statistical browsing data);
- to public authorities if we are required to disclose personal data by applicable law or to comply with a lawful request of authorities;
- in relation to a merger, acquisition or sale of our business or its part(s).
We may transfer your personal data outside of the European Economic Area in limited cases. In such a case, we use adequate safeguards to protect your personal data, such as the standard contractual clauses for transfers established by the European Commission. You can contact us to get more information about the transfers of your personal data at data@jutt.ai.
4. Retention of Your Personal Data
We process your personal data only for as long as necessary for the fulfilment of the original purposes of personal data processing, which are described above, or as long as required to fulfil our legal obligations.
We determine the appropriate retention period for personal data on the basis of the amount, nature, and sensitivity of the personal data being processed, the potential risk of harm from unauthorised use or disclosure of the personal data, whether we can achieve the purposes of the processing through other means, and on the basis of applicable legal requirements (such as applicable statutes of limitation).
When the retention of your personal data is no longer necessary to achieve the purposes of processing, your data will be permanently removed, unless you instruct us otherwise and we agree on the terms of longer storage of your data.
5. Your Rights
By contacting us at data@jutt.ai, you may exercise your rights as the data subject to the extent permitted under applicable law, including the following rights:
- You may request access to your personal data;
- To the extent permitted under applicable law, you may request us to correct, update, change or erase your personal data. In some cases, you may also have a right to object to the processing of your personal data;
- If you request the erasure of your personal data, please note that certain personal data is strictly necessary in order to fulfil the purposes defined in this Privacy Notice and the processing of which may also be required by applicable law. If personal data is erased under your request, we will only retain such copies of the information as are necessary for us to protect our or third parties’ legitimate interests, comply with governmental orders, resolve disputes, troubleshoot problems, or enforce any agreement you have entered into with us. Therefore, such personal data may not be erased in full;
- You may withdraw your consent regarding the processing of your personal data, where the legal basis for processing is your consent. Please note that withdrawal of consent does not affect the lawfulness of the processing of personal data carried out on the basis of consent before withdrawal;
- You may use your right to data portability. In some cases, we may limit or deny your request if we are required or permitted by applicable law to do so, e.g. if it is necessary for the purpose of our legitimate interest to protect our trade secrets or any other confidential information; and
- To the extent permitted under applicable law, you may request more information about our legitimate interest and why we think our legitimate interest overrides your rights and interests as a data subject. This applies where the legal basis for the processing of your personal data is our legitimate interest.
We will respond to your requests and provide you with additional privacy-related information within the timeframes specified in applicable personal data protection law. Please note that we may ask you for additional information to adequately verify your identity before taking action on your request to exercise your rights as a data subject.
If you are not satisfied with our response or have a concern that your privacy rights have been infringed, you may contact us at data@jutt.ai. You also have the right to lodge a complaint with your local supervisory authority. List and contact details of European supervisory authorities can be found here.
6. Security Measures
We use reasonable technical and organisational measures (including physical, electronic and administrative) to protect your personal data from loss, destruction, misuse and unauthorised access or disclosure, including by implementing additional restrictions or measures for safeguarding special categories of personal data which are, for instance, retained separately from any other personal data and anonymised, where possible, with viable methods.
Please note that no method of transmission over the Internet, or method of electronic storage, is fully secure. While we use all reasonable efforts to protect your personal data from loss, destruction, unauthorised access, misuse, or disclosure, we cannot fully guarantee the security of your personal data.
7. Cookies
Cookies are data files that are written to your device when you use our website and services, and which may also contain your personal data. Cookies are used, for example, for tracking and analysing website usage in order to enhance its functionality.
We may use cookies for the following purposes:
- Technical cookies - necessary for the basic functioning of the website.
- Analytical cookies - to collect data on website usage and improve user experience. Some analytics tools may be offered by third parties.
- Marketing cookies - to personalise advertising and track the effectiveness of marketing campaigns.
- Preference cookies - to remember user preferences and settings.
Analytical cookies, marketing cookies and preference cookies are used only with the user’s consent. Technical cookies that are necessary for the website’s basic functioning cannot be declined.
The length of time a cookie will be retained on your device depends on whether it is a persistent or a session cookie.
- Session cookies are temporary cookies that stay on your device until you leave our site.
- Persistent cookies will be retained on your device after you have finished using our website or services until they expire or are manually deleted.
You can manage or disable cookies through your browser settings at any time.
8. Updates
From time to time, we may update this Privacy Notice to reflect any changes that may occur. In the event of any substantial update, we will notify you via the email address you have provided, or the company on behalf of which you use our services has communicated to us.
Contact Information
If you have any questions regarding this Privacy Notice, please contact us at:
- JuttAI OÜ
- Website: https://jutt.ai
- Email: data@jutt.ai