AutoNest
Features How It Works About
Get Started

Privacy Policy

Last updated: 30 July 2026

Contents

  1. Data Controller
  2. Data We Collect
  3. Purposes & Legal Bases
  4. Retention Periods
  5. Recipients & Transfers
  6. International Transfers
  7. AutoNest as Data Processor
  8. Cookies
  9. Your Rights
  10. Withdrawing Consent
  11. Security
  12. Minors
  13. Changes to This Policy
  14. Contact & Supervisory Authority

Summary: AutoNest collects only the data necessary to provide and improve the Service. We do not sell your data. You have full rights under the GDPR. For data processed on behalf of our customers, we act as a data processor and a DPA is available on request. Contact us at contact@autonest.online.

1. Data Controller

The data controller responsible for personal data processed through autonest.online and the AutoNest platform is:

AutoNest
Ristiku tn 62, 10317 Tallinn, Estonia
Email: contact@autonest.online

AutoNest is established in Estonia (European Union) and is subject to Regulation (EU) 2016/679 (General Data Protection Regulation — "GDPR") and the Estonian Personal Data Protection Act.

2. Data We Collect

CategoryData elementsHow collected
Account & registration data Name, email address, password hash, organisation name, role, country Provided when creating or managing an account
Billing data Name, billing address, VAT number (if applicable), payment method reference (tokenised — full card details processed by our payment provider) Provided at subscription sign-up or plan change
Usage & telemetry data Workflow creation and execution counts, feature usage, click events, session duration, page views within the application, error rates Automatically collected as you use the Service
Technical / log data IP address, browser type, operating system, device type, API request logs, timestamps, HTTP status codes Automatically collected by our servers and infrastructure
Support & communication data Name, email, message content, attachments, support ticket history Provided when contacting support via email or in-app chat
Cookie & consent data Cookie consent status, timestamp, preference settings Stored in browser (localStorage) via our cookie notice
Customer workflow data Data you configure in or pass through your workflows (processed as data processor on your behalf — see Section 7) Submitted by you when building and running automations

We do not collect special categories of personal data (Article 9 GDPR) in the course of providing the Service. If you include such data in your workflows, you are responsible for ensuring appropriate legal basis and safeguards are in place.

3. Purposes & Legal Bases

PurposeLegal basis (GDPR Art. 6)
Creating and managing user accounts Art. 6(1)(b) — performance of a contract
Providing and operating the Service Art. 6(1)(b) — performance of a contract
Processing subscription payments Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (VAT/accounting)
Responding to support enquiries Art. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interests
Improving and developing the Service (usage analytics) Art. 6(1)(f) — legitimate interests (improving product quality)
Analytics cookies on the website Art. 6(1)(a) — consent
Ensuring platform security and preventing abuse Art. 6(1)(f) — legitimate interests (protecting systems and users)
Sending product updates and marketing communications Art. 6(1)(a) — consent; or Art. 6(1)(f) — legitimate interests for existing customers
Compliance with legal and tax obligations Art. 6(1)(c) — legal obligation

4. Retention Periods

Data categoryRetention period
Account dataDuration of the account + 30 days after deletion request (then permanently deleted)
Billing and transaction records7 years (Estonian Accounting Act)
Usage and telemetry dataUp to 24 months (aggregated/anonymised thereafter)
Server and API logsUp to 90 days
Support communication data3 years from last interaction
Workflow execution logsAs configured per plan (typically 30–90 days) or as required for debugging active issues
Marketing consent recordsUntil opt-out + 3 years
Cookie consent recordsUp to 12 months

5. Recipients & Third Parties

We do not sell or rent personal data. We may share data with the following categories of recipients:

  • Infrastructure providers: Cloud hosting (EU-based), CDN, and database services acting as data processors under DPAs.
  • Payment processors: Stripe or equivalent PCI-DSS compliant provider that processes card data on our behalf. We do not store raw card numbers.
  • Analytics providers: Service analytics platforms (activated only with consent for marketing/analytics cookies).
  • Support tools: Help desk and communication software used to manage customer enquiries, subject to DPAs.
  • Legal and regulatory authorities: Where required by applicable law or in response to a valid legal process.

6. International Transfers

AutoNest is based in Estonia (EU) and prioritises EU-hosted infrastructure. Where any processor stores or processes data outside the EEA, we ensure adequate safeguards are in place pursuant to GDPR Chapter V, including Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46(2)(c) GDPR) or reliance on an EU adequacy decision. Copies of applicable transfer mechanisms are available on request.

7. AutoNest as Data Processor

When you use AutoNest to process personal data belonging to your customers or end users (for example, by building workflows that handle personal data from your own databases or APIs), AutoNest acts as a data processor and you act as the data controller. In this capacity:

  • AutoNest processes such data only on your documented instructions;
  • A Data Processing Agreement (DPA) is available upon request and is required for compliance with GDPR Article 28;
  • You are responsible for ensuring that you have a lawful basis for processing the personal data you pass through the Service;
  • AutoNest implements appropriate technical and organisational security measures to protect data processed on your behalf.

To obtain our DPA, please contact contact@autonest.online.

8. Cookies

We use cookies and similar technologies on autonest.online. Strictly necessary cookies function without consent. Analytics and marketing cookies are activated only with your explicit consent via our cookie notice. Full details are in our Cookie Policy.

9. Your Rights Under GDPR

RightWhat it means
Access (Art. 15)Obtain confirmation of whether we process your data and receive a copy.
Rectification (Art. 16)Have inaccurate or incomplete data corrected without undue delay.
Erasure (Art. 17)Request deletion when data is no longer necessary, or where consent is withdrawn and no other legal basis applies.
Restriction (Art. 18)Restrict processing in certain circumstances (e.g. while contesting accuracy).
Portability (Art. 20)Receive your data in a structured, machine-readable format.
Object (Art. 21)Object to processing based on legitimate interests or for direct marketing.
Lodge a complaint (Art. 77)File a complaint with the supervisory authority — see Section 14.

To exercise any right, email contact@autonest.online with "GDPR Rights Request" in the subject line. We will respond within one calendar month. Identity verification may be required.

10. Withdrawing Consent

Where processing is based on consent (Art. 6(1)(a)), you may withdraw at any time without affecting lawfulness of prior processing. To withdraw:

  • Cookies: Use "Cookie Preferences" in the footer or email contact@autonest.online.
  • Marketing emails: Use the unsubscribe link in any email or email contact@autonest.online with "Opt-Out" in the subject.

11. Security

AutoNest implements industry-standard technical and organisational measures to protect personal data, including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, multi-factor authentication for admin access, automated backups, and regular security reviews. No system is completely immune to risk, and we cannot guarantee absolute security. We will notify you and relevant authorities without undue delay in the event of a personal data breach affecting your data, as required by GDPR Article 33/34.

12. Minors

The Service is intended for users aged 18 and over. We do not knowingly collect personal data from persons under 16. If you believe we have inadvertently collected such data, contact us at contact@autonest.online and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy as our practices evolve or in response to legal changes. The "Last updated" date reflects the current version. For material changes, we will notify registered users by email or prominent in-app notice at least 14 days in advance.

14. Contact & Supervisory Authority

For any privacy matter, please contact:
AutoNest — Privacy
Ristiku tn 62, 10317 Tallinn, Estonia
Email: contact@autonest.online

If you are not satisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate:

Andmekaitse Inspektsioon
Tatari 39, 10134 Tallinn, Estonia
www.aki.ee  |  info@aki.ee

AutoNest

Intelligent workflow automation for modern engineering teams.

Ristiku tn 62, 10317
Tallinn, Estonia

Product

FeaturesHow It WorksIntegrations

Legal

Terms of ServicePrivacy PolicyCookie PolicyCookie Preferences

Contact

contact@autonest.online
© AutoNest. All rights reserved. Ristiku tn 62, 10317 Tallinn, Estonia

We use cookies to operate this site and, with your consent, for analytics. See our Cookie Policy. Withdraw consent at any time via "Cookie Preferences" in the footer or by emailing contact@autonest.online.