Legal
Privacy Policy
How Rhinoo OÜ collects, uses, and protects your personal data under the GDPR.
Last updated: June 19, 2026
Rhinoo OÜ ("Rhinoo", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect when you visit rhinoo.solutions, use our contact forms, or engage with our services — and how we process that information in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian law.
By using our website or submitting your details through any form, you acknowledge that you have read this Privacy Policy. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
1. Data Controller
The controller responsible for your personal data is:
Rhinoo OÜ
Registry code: 16482930
VAT number: EE102482930
Registered address: Lõõtsa 8a, 11415 Tallinn, Estonia
Privacy enquiries: privacy@rhinoo.ai
Legal enquiries: legal@rhinoo.ai
2. Scope
This policy applies to:
- Visitors and users of our website and blog
- Prospective clients who submit enquiries through our forms or modals
- Individuals who join waitlists (Documentation, API beta)
- Clients and partners with whom we have or are establishing a business relationship
It does not apply to third-party websites linked from our site. We encourage you to review the privacy policies of any external services you visit.
3. Personal Data We Collect
3.1 Data you provide directly
Depending on how you interact with us, we may collect:
- Identity & contact data — full name, email address
- Project enquiry data — budget range, project description, goals, and messages you submit via our lead modal, hero capture form, contact section, or service pages
- Waitlist data — email address when you register interest in our Documentation portal or API beta programme
- Business relationship data — company name, role, billing details, contract information, and correspondence when you become a client
3.2 Data collected automatically
When you browse our website, we may automatically collect:
- Technical data — IP address, browser type and version, operating system, device type, referring URL, and pages viewed
- Usage data — time spent on pages, click patterns, and interaction with site features (where analytics tools are enabled)
- Cookie data — as described in Section 7 below
We do not intentionally collect special categories of personal data (e.g. health, biometric, or political data) through our website forms. Please do not submit sensitive information unless we have explicitly requested it under a separate agreement.
4. Legal Bases for Processing
Under GDPR Article 6, we process your personal data on the following bases:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and scheduling strategy calls | Consent (form submission) / Legitimate interest (B2B lead management) |
| Delivering AI engineering services under contract | Performance of a contract |
| Waitlist and product update communications | Consent |
| Website security, fraud prevention, and server logs | Legitimate interest |
| Analytics and site performance improvement | Consent (where required) / Legitimate interest (aggregated, non-identifying data) |
| Accounting, tax, and regulatory compliance | Legal obligation |
5. How We Use Your Data
We use personal data to:
- Respond to your enquiries and deliver the AI roadmap or strategy information you request
- Evaluate project fit, prepare proposals, and manage client engagements
- Send waitlist confirmations and notify you about Documentation or API beta releases (only if you opted in)
- Operate, maintain, and improve our website and user experience
- Detect and prevent abuse, spam, or security incidents
- Comply with Estonian and EU legal, tax, and accounting obligations
We will not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without your explicit consent.
6. Data Sharing & Processors
We do not sell your personal data. We may share it only where necessary with:
- Hosting & infrastructure providers — e.g. web hosting (such as Hostinger), email delivery, and cloud services that process data on our behalf under data processing agreements
- CRM & communication tools — if you are added to our sales or project pipeline
- Analytics providers — if and when analytics tools (e.g. Google Analytics) are enabled, subject to your cookie preferences
- Professional advisers — lawyers, accountants, or auditors bound by confidentiality
- Authorities — when required by law, court order, or regulatory request
All third-party processors are selected for GDPR compliance and are contractually required to process data only according to our instructions and implement appropriate security measures.
7. Cookies & Similar Technologies
Our website uses cookies and similar technologies to ensure basic functionality and, where enabled, to understand how visitors use the site.
| Category | Purpose | Duration |
|---|---|---|
| Strictly necessary | WordPress session management, security, load balancing, and form protection | Session / up to 1 year |
| Functional | Remember preferences and improve on-site experience | Up to 1 year |
| Analytics | Measure traffic and page performance (only with consent, when implemented) | Up to 26 months |
You can control cookies through your browser settings. Disabling strictly necessary cookies may affect site functionality. Where required by law, we will request your consent before placing non-essential cookies.
8. International Data Transfers
Your data is primarily processed within the European Economic Area (EEA). If we transfer personal data outside the EEA — for example, to cloud or analytics providers headquartered in third countries — we ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions recognising an equivalent level of data protection
- Binding corporate rules, where applicable
You may request a copy of the relevant safeguards by contacting us at privacy@rhinoo.ai.
9. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Enquiry & lead data — up to 24 months after last contact, unless a business relationship is established
- Client & contract data — for the duration of the engagement plus up to 7 years for legal and accounting purposes
- Waitlist data — until you unsubscribe or the relevant product launches, plus a reasonable follow-up period
- Server & security logs — typically 30–90 days
- Analytics data — as configured in the analytics tool, generally up to 26 months
When data is no longer needed, we securely delete or anonymise it.
10. Your Rights Under the GDPR
If you are located in the EEA, you have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — request deletion where there is no compelling reason to continue processing
- Right to restrict processing — limit how we use your data in certain circumstances
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent — at any time, where processing is consent-based
To exercise any of these rights, email privacy@rhinoo.ai. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with a supervisory authority. In Estonia, this is:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
Website: www.aki.ee
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- HTTPS encryption for data in transit
- Access controls and least-privilege principles for our team
- Secure hosting infrastructure with regular updates
- Internal policies aligned with GDPR and EU AI Act readiness standards
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
12. Children's Privacy
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have inadvertently collected a minor's data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The "Last updated" date at the top of this page indicates when the policy was last revised. Material changes will be communicated via a notice on our website or by email where appropriate.
14. Contact Us
For any questions about this Privacy Policy or how we handle your personal data, contact:
See also our Terms of Use and Legal Information.