PRIVACY POLICY
Last updated: July 14, 2025
1. Overview
Segura Intelligence Group OÜ (“Segura,” “we,” “our,” or “us”) provides Brain‑as‑a‑Service—AI‑driven data analytics and consulting—principally to clients in North America, the EU/EEA, and the United Kingdom. We comply with the EU General Data Protection Regulation (GDPR), UK GDPR, the 2025 EU‑U.S. Data Privacy Framework (DPF), and the California Consumer Privacy Act (CCPA/CPRA). We do not sell personal data and do not knowingly process data from individuals under 18.
2. Who We Are
| Data Controller | Segura Intelligence Group OÜ – Registry Code 16703157 |
|---|---|
| EU Address | Juhkentali 8, 10132 Tallinn, Estonia |
| U.S. Address | 166 Geary St. STE 1500, #2260, San Francisco, CA 94108, USA |
| Primary Email / DPO | eureka@agnosticai.xyz |
| UK Representative (GDPR Art 27) | DataRep UK Ltd., 107‑111 Fleet St., London EC4A 2AB, United Kingdom |
3. Scope
This Policy covers personal data when you:
- visit agnosticai.xyz or sub‑domains,
- interact via forms, email, chat, or marketing,
- use or purchase our Brain‑as‑a‑Service offerings.
It does not apply to third‑party sites or services that link to us; review their policies separately.
4. What Data We Collect
| Category | Examples | Source | Retention* |
|---|---|---|---|
| Contact Data | Name, email, phone, employer | You | Contract + 7 yrs |
| Business Data | Industry, revenue band, tech stack | You | Contract + 7 yrs |
| Technical Data | IP, device, browser, pages, video analytics | GA4, Hotjar, Meta Pixel, LinkedIn Insight, Cloudflare | 26 months (max) |
| Marketing Prefs | Opt‑in/opt‑out, email engagement | MailerLite | Until unsubscribe |
| Payment Data | Tokenised IDs, last 4 digits | Stripe | 7 yrs (accounting) |
| User Content | Files you upload for analysis | You | Per contract / deletion |
*Retention may be extended when required by law.
5. Why & How We Use Data
| Purpose | Examples | Legal Basis (EEA/UK) |
|---|---|---|
| Service delivery & support | Analytics, dashboards, connectors | Contract (Art 6 (1)(b)) |
| Billing & account | Invoicing, reconciliation | Contract / Legal obligation |
| Security & fraud prevention | IP filtering, anomaly alerts | Legitimate interest / Legal obligation |
| Site analytics | Aggregated stats, A/B tests | Legitimate interest; Consent for non‑essential cookies |
| Marketing | B2B soft‑opt‑in emails, remarketing | Legitimate interest; Consent where required |
| Compliance | Tax, sanctions screening | Legal obligation |
6. Legal Bases for Processing
- Consent – non‑essential cookies, newsletters.
- Contract – to provide services/trials.
- Legitimate Interest – B2B marketing, platform security.
- Legal Obligation – accounting, regulatory requests.
7. Cookies & Similar Tech
We use first‑ and third‑party cookies for functionality, analytics, and advertising. EU/UK/California visitors see a banner to accept, reject, or customise non‑essential cookies. Details live in our Cookie Policy.
8. Do‑Not‑Track & Global Privacy Control
We honour browser‑based Global Privacy Control (GPC) and California Do‑Not‑Sell / Do‑Not‑Share signals by disabling non‑essential tracking and blocking cross‑context behavioural advertising.
9. Automated Decision‑Making & Profiling
Our predictive AI models are run only under client instruction and never produce decisions with legal or similarly significant effects on individuals without human review. You may object to profiling (see Section 14).
10. Sharing & International Transfers
| Recipient | Purpose | Safeguard |
|---|---|---|
| SiteGround (DE) | Hosting | EEA – no transfer |
| Cloudflare Inc. (US) | CDN & WAF | EU‑U.S. DPF (2025) + SCCs |
| Stripe Inc. (US) | Payments | DPF + 2021 SCCs |
| Google LLC (US) | Analytics & Workspace | DPF + SCCs |
| Meta Platforms Inc./IE | Advertising pixels | SCCs + supplementary measures |
| LinkedIn Ireland | Insight tag | SCCs |
| MailerLite UAB (EU) | Email SaaS | EEA – no transfer |
| Hotjar Ltd. (EU) | Heatmaps & feedback | EEA – no transfer |
For UK transfers we append the UK International Data Transfer Addendum (IDTA) to the SCCs.
11. Data Retention
- Contract & accounting records: 7 years.
- Marketing lists: until you opt out.
- Google Analytics data: 24–26 months (max).
12. Security Measures
- Encryption: TLS 1.3 in transit; AES‑256 at rest.
- Hosting: SiteGround ISO 27001‑certified DC (Frankfurt).
- Access: zero‑trust IAM, hardware keys for admins.
- Monitoring: 24/7 logs, WAF, documented breach plan (GDPR Arts 33‑34, CCPA §1798.82).
No method is 100 % secure, but we follow industry best practices and continuously improve.
13. Your Rights
| Region | Rights Summary |
|---|---|
| EEA / EU | Access, Rectification, Erasure, Restriction, Portability, Objection, Withdraw Consent (GDPR Arts 15‑21) |
| United Kingdom | Same as above under UK GDPR |
| California | Know, Delete, Correct, Opt‑out of sale/share, Limit use of sensitive data, No discrimination (CCPA/CPRA); “Shine the Light” request once per year (§1798.83) |
14. Exercising Your Rights
Email eureka@agnosticai.xyz with the subject “Privacy Request – [Right]”.
- Acknowledgement: within 72 hours.
- Resolution: within 30 days (45 days for CCPA, extendable once).
15. Limitation of Liability & Disclaimer
The website and services are provided “as‑is” and “as‑available.” To the extent permitted by law, Segura disclaims all warranties and is not liable for indirect, incidental, consequential, or punitive damages arising from or related to this Policy or our processing activities. Nothing here excludes liability that cannot be limited under applicable law.
16. Changes to This Policy
We may update this Policy to reflect legal, technical, or business changes. Posting the revised Policy on our site constitutes notice. Material changes will be flagged via banner or email at least 14 days before taking effect. Check the “Last updated” date above for the current version.
17. Dispute Resolution & Governing Law
- Governing law & venue: Estonian law; disputes subject to Harju County Court (Tallinn).
- Informal resolution: Contact us first; we aim to resolve within 30 days.
- Supervisory authorities: EEA – Estonian Data Protection Inspectorate; UK – ICO; US/California – CPPA; DPF arbitration through BBB National Programs for cross‑border transfers.
18. Contact Us
Email: eureka@agnosticai.xyz
Postal (EU): Segura Intelligence Group OÜ, Juhkentali 8, 10132 Tallinn, Estonia
Postal (USA): Segura Intelligence Group OÜ, 166 Geary St. STE 1500, #2260, San Francisco, CA 94108, USA
UK Representative: DataRep UK Ltd., 107‑111 Fleet St., London EC4A 2AB, UK
Segura Intelligence Group OÜ
Committed to privacy, security & responsible data analytics.
