Summary: AutoNest collects only the data necessary to provide and improve the Service. We do not sell your data. You have full rights under the GDPR. For data processed on behalf of our customers, we act as a data processor and a DPA is available on request. Contact us at contact@autonest.online.
The data controller responsible for personal data processed through autonest.online and the AutoNest platform is:
AutoNest
Ristiku tn 62, 10317 Tallinn, Estonia
Email: contact@autonest.online
AutoNest is established in Estonia (European Union) and is subject to Regulation (EU) 2016/679 (General Data Protection Regulation — "GDPR") and the Estonian Personal Data Protection Act.
| Category | Data elements | How collected |
|---|---|---|
| Account & registration data | Name, email address, password hash, organisation name, role, country | Provided when creating or managing an account |
| Billing data | Name, billing address, VAT number (if applicable), payment method reference (tokenised — full card details processed by our payment provider) | Provided at subscription sign-up or plan change |
| Usage & telemetry data | Workflow creation and execution counts, feature usage, click events, session duration, page views within the application, error rates | Automatically collected as you use the Service |
| Technical / log data | IP address, browser type, operating system, device type, API request logs, timestamps, HTTP status codes | Automatically collected by our servers and infrastructure |
| Support & communication data | Name, email, message content, attachments, support ticket history | Provided when contacting support via email or in-app chat |
| Cookie & consent data | Cookie consent status, timestamp, preference settings | Stored in browser (localStorage) via our cookie notice |
| Customer workflow data | Data you configure in or pass through your workflows (processed as data processor on your behalf — see Section 7) | Submitted by you when building and running automations |
We do not collect special categories of personal data (Article 9 GDPR) in the course of providing the Service. If you include such data in your workflows, you are responsible for ensuring appropriate legal basis and safeguards are in place.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing user accounts | Art. 6(1)(b) — performance of a contract |
| Providing and operating the Service | Art. 6(1)(b) — performance of a contract |
| Processing subscription payments | Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (VAT/accounting) |
| Responding to support enquiries | Art. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interests |
| Improving and developing the Service (usage analytics) | Art. 6(1)(f) — legitimate interests (improving product quality) |
| Analytics cookies on the website | Art. 6(1)(a) — consent |
| Ensuring platform security and preventing abuse | Art. 6(1)(f) — legitimate interests (protecting systems and users) |
| Sending product updates and marketing communications | Art. 6(1)(a) — consent; or Art. 6(1)(f) — legitimate interests for existing customers |
| Compliance with legal and tax obligations | Art. 6(1)(c) — legal obligation |
| Data category | Retention period |
|---|---|
| Account data | Duration of the account + 30 days after deletion request (then permanently deleted) |
| Billing and transaction records | 7 years (Estonian Accounting Act) |
| Usage and telemetry data | Up to 24 months (aggregated/anonymised thereafter) |
| Server and API logs | Up to 90 days |
| Support communication data | 3 years from last interaction |
| Workflow execution logs | As configured per plan (typically 30–90 days) or as required for debugging active issues |
| Marketing consent records | Until opt-out + 3 years |
| Cookie consent records | Up to 12 months |
We do not sell or rent personal data. We may share data with the following categories of recipients:
AutoNest is based in Estonia (EU) and prioritises EU-hosted infrastructure. Where any processor stores or processes data outside the EEA, we ensure adequate safeguards are in place pursuant to GDPR Chapter V, including Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46(2)(c) GDPR) or reliance on an EU adequacy decision. Copies of applicable transfer mechanisms are available on request.
When you use AutoNest to process personal data belonging to your customers or end users (for example, by building workflows that handle personal data from your own databases or APIs), AutoNest acts as a data processor and you act as the data controller. In this capacity:
To obtain our DPA, please contact contact@autonest.online.
We use cookies and similar technologies on autonest.online. Strictly necessary cookies function without consent. Analytics and marketing cookies are activated only with your explicit consent via our cookie notice. Full details are in our Cookie Policy.
| Right | What it means |
|---|---|
| Access (Art. 15) | Obtain confirmation of whether we process your data and receive a copy. |
| Rectification (Art. 16) | Have inaccurate or incomplete data corrected without undue delay. |
| Erasure (Art. 17) | Request deletion when data is no longer necessary, or where consent is withdrawn and no other legal basis applies. |
| Restriction (Art. 18) | Restrict processing in certain circumstances (e.g. while contesting accuracy). |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format. |
| Object (Art. 21) | Object to processing based on legitimate interests or for direct marketing. |
| Lodge a complaint (Art. 77) | File a complaint with the supervisory authority — see Section 14. |
To exercise any right, email contact@autonest.online with "GDPR Rights Request" in the subject line. We will respond within one calendar month. Identity verification may be required.
Where processing is based on consent (Art. 6(1)(a)), you may withdraw at any time without affecting lawfulness of prior processing. To withdraw:
AutoNest implements industry-standard technical and organisational measures to protect personal data, including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, multi-factor authentication for admin access, automated backups, and regular security reviews. No system is completely immune to risk, and we cannot guarantee absolute security. We will notify you and relevant authorities without undue delay in the event of a personal data breach affecting your data, as required by GDPR Article 33/34.
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from persons under 16. If you believe we have inadvertently collected such data, contact us at contact@autonest.online and we will delete it promptly.
We may update this Privacy Policy as our practices evolve or in response to legal changes. The "Last updated" date reflects the current version. For material changes, we will notify registered users by email or prominent in-app notice at least 14 days in advance.
For any privacy matter, please contact:
AutoNest — Privacy
Ristiku tn 62, 10317 Tallinn, Estonia
Email: contact@autonest.online
If you are not satisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate:
Andmekaitse Inspektsioon
Tatari 39, 10134 Tallinn, Estonia
www.aki.ee | info@aki.ee