LEGAL · PRIVACY BY DESIGN

Privacy Policy

How Technolay handles personal data across our public website and compliance operations platform.

Version

v2

Effective

22 July 2026

Document status

Approved

1. Who we are

Technolay OÜ (registration number 17546223) (“Technolay”, “we”, “us”, or “our”) is a company registered in Estonia. Technolay operates a compliance operations platform (the “Service”) that helps organizations (“Customers”) track, evidence, and manage compliance with regulatory and security frameworks.

This Privacy Policy explains how we collect, use, and protect personal data when you use the Service, visit our website, or otherwise interact with us.

2. Data we process

  • Account and organization data — names, work email addresses, job roles, and organizational details such as company name, industry, and size provided during onboarding.
  • Connector data — with a Customer’s explicit authorization, read-only configuration and security-posture data from systems the Customer operates. This may incidentally include limited personal data such as user email addresses or account identifiers. We do not request write access, and credentials are stored encrypted.
  • Documents and evidence — policies, procedures, evidence records, and other content Customers upload or author, which may contain personal data at the Customer’s discretion.
  • Usage and technical data — log data, device and browser information, IP address, and usage analytics necessary to operate, secure, and improve the Service.
  • AI processing — relevant control text and connected-system data used by features such as control analysis and document drafting assistance.

3. Purposes and legal bases

We process personal data for the following purposes and legal bases under Article 6 GDPR:

  • Providing and maintaining the Service — performance of a contract (Article 6(1)(b)).
  • Security, fraud prevention, and platform integrity — legitimate interests (Article 6(1)(f)).
  • Compliance with legal and regulatory obligations — legal obligation (Article 6(1)(c)).
  • Product improvement and support communications — legitimate interests (Article 6(1)(f)), or consent where required.

4. Sub-processors

We use the following sub-processors to provide the Service. We will provide advance notice of material changes where required by our contractual commitments to Customers.

  • Supabase — database and file storage, hosted in the EU region.
  • Vercel — application and public-website hosting.
  • IBM watsonx — AI-assisted analysis and drafting, configured in the IBM Cloud Frankfurt region (eu-de).
  • Supabase Auth — authentication and enterprise SSO.
  • Resend — transactional email delivery.
  • Sentry — error and performance monitoring.

5. Data retention

We retain personal data according to its category and purpose. Export or deletion requests remain subject to backup-purge windows and legal retention obligations that override deletion.

  • Account and workspace data — active account plus 90 days after closure.
  • Compliance evidence and controlled documents — 7 years from creation, or account duration plus 2 years, whichever is longer.
  • Security and audit logs — 2 years, rolling.
  • Support and transactional communications — 3 years.
  • Billing and invoice records — 7 years, in line with applicable Estonian accounting and tax requirements.
  • Backups and deletion-recovery copies — purged within 30–90 days after primary data is deleted.

6. International data transfers

Technolay’s primary database and file-storage infrastructure is hosted within the European Union.

AI-assisted analysis and drafting use IBM watsonx configured in the IBM Cloud Frankfurt region (eu-de). IBM or its approved sub-processors may process limited service data outside the EEA where required to provide or support the service; applicable transfers are protected by appropriate safeguards, including the EU Standard Contractual Clauses where required.

7. Security measures

We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, row-level access controls enforcing tenant isolation, multi-factor authentication for administrative access, audit logging of security-relevant actions, and least-privilege access for connected third-party systems.

8. Your rights

Subject to applicable law, you may exercise the rights listed below by contacting info@technolay.com. Customers may also submit data export and deletion requests within the product.

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Request deletion of personal data.
  • Restrict or object to processing.
  • Request data portability.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

9. Cookies

Our public website is designed to operate without analytics, advertising, profiling, or preference cookies. No optional cookies are currently set. Language selection is carried in the page URL rather than stored in a cookie.

Vercel may process request metadata for security and delivery without placing a Technolay tracking cookie. Contact and demo forms transmit submitted information to Technolay and our email-delivery provider so we can respond. The authenticated Service uses necessary session and security technologies.

Read the full Cookie Policy

10. Children’s data

The Service is intended for business use by adult professionals and is not directed at individuals under 16.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service, by email, or through another appropriate notice.

12. Contact us

Questions, requests, or concerns about this Privacy Policy and our processing of personal data may be sent to the contact details below.

Controller

Technolay OÜ (17546223)

Registered address

Tartu mnt 67/1-13b, 10115, Tallinn, Harju maakond, Estonia