Privacy Policy
Version 3.3
Updated July 08, 2026
Effie respects your privacy and is committed to handling personal data transparently, lawfully and securely.
This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise process personal data in connection with the effie websites, products and services, including the effie SaaS platform, web portal, mobile applications, APIs, integrations, dashboards, analytics, image recognition, AI Features, AI Agents, support interactions, marketing communications and related services.
For clarity, “effie”, “Company”, “we”, “us” and “our” refer to the relevant effie legal entity that provides, operates or administers the applicable website, product, service, order form or customer relationship. Depending on the Agreement, territory and actual provision of the Service, the relevant effie entity may be effie.ai Inc., IPLAND EUROPE S. Z O.O., LLC “IPLAND”, or another authorized effie affiliate or reseller.
This Privacy Policy applies both to individuals who interact with our public websites and communications, and to users of the effie SaaS platform made available by corporate customers.
Where a separate written agreement applies, including an Agreement, MSA or Data Processing Agreement (DPA), that agreement may further define the parties’ roles and responsibilities. This Privacy Policy does not replace, amend or override any applicable DPA in relation to Customer Personal Data processed on behalf of a corporate customer.
1. General provisions
We process your personal data only if one of the conditions specified in Article 6 of the GDPR is met, including, but not limited to:
- You have consented to the processing of your personal data (Consent).
- Processing is necessary for the purpose of providing services to you, including the performance of our contractual obligations and Terms of Service (Contract).
- Such processing is required by the laws of the countries in which you are located (Legal obligation).
- Processing is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your rights and freedoms (Legitimate interests).
We take seriously the security of the personal data of our clients, potential clients and other persons who contact us, therefore we strive to protect the confidentiality of your personal data. The Company’s senior management undertakes to take all necessary measures to prevent the misuse of your personal data that becomes known to us. We will process your personal data in strict accordance with the requirements of applicable Law and only if there are legal grounds for such processing.
You are not required to provide us with your personal information, but without certain information we may be unable to provide or make available some of our services, features or communications.
Our role in processing personal data depends on the context and purpose of processing:
When we act independently — for example, when you visit our website, request a demo, communicate with our sales, marketing or support teams, or when we process data for our own security, billing, legal, compliance or administrative purposes — we determine the purposes and means of processing. In such cases, we act as a data controller under the GDPR / UK GDPR or as a business under applicable U.S. state privacy laws.
When we process personal data on behalf of a corporate customer — for example, when providing the effie SaaS platform to your organization and processing data submitted to, synchronized with or generated through the Service under that customer’s instructions — the corporate customer generally determines what personal data is processed and why. In such cases, we generally act as a data processor under the GDPR / UK GDPR or as a service provider / contractor under applicable U.S. state privacy laws.
This general approach applies across our websites, products and services, including the effie SaaS platform, AI Features, AI Agents, integrations, support interactions and related services. However, the exact scope of each party’s role and responsibilities may be further defined in the applicable Agreement, MSA, DPA, AI Use Policy, product documentation or other contractual documentation.
Where a Data Processing Agreement (DPA) applies, it governs our processing of Customer Personal Data on behalf of the corporate customer and takes precedence over this Privacy Policy in relation to such processing. This Privacy Policy does not replace, amend or override the applicable DPA.
What personal data are we processing?
When you use our service (Services), we may process personal data depending on how you interact with us and the Services, the choices you make, which elements of the Service and which features you use.
Do we process sensitive personal data?
We do not intentionally collect special categories of personal data under GDPR Article 9, such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, health data, or biometric data for the purpose of uniquely identifying an individual, unless expressly agreed in writing and supported by a lawful basis.
The Service is not designed for special categories of personal data and sensitive personal data.
For U.S. state privacy law purposes, certain operational data processed through the Service may be treated as “sensitive data” or “sensitive personal information”, including precise geolocation data and employment-related field activity data, depending on the applicable state law and context.
Where precise geolocation is enabled for route, visit, store, audit, mileage, field force or similar Service functionality, such data may identify the location of a user or device with high accuracy and may be subject to opt-in consent, opt-out, limitation, data minimization, sale/share restrictions or other heightened requirements under applicable U.S. state privacy laws. We process such data only to the extent necessary for the Service, customer configuration, the Agreement, documented customer instructions and applicable law. Corporate customers are responsible for ensuring that their users, field representatives, employees, contractors or other individuals receive all required notices and consents where the customer determines the purposes and means of such processing.
Do we receive any information from third parties?
We do not receive any information from third parties, unless explicitly provided herein.
We may receive personal data from third parties in limited circumstances, including from corporate customers, authorized users, customer systems, integrations, service providers, business partners, app stores, analytics providers, support tools, cloud providers or other sources necessary for the operation, security, support, administration or improvement of the Service.
In connection with the use of AI Features and AI Agents, we may receive personal data from the corporate client, its authorized users, as well as from photos, prompts (text instructions for AI), knowledge materials (training or reference materials), and other content that is uploaded to the Service for the operation of the relevant AI features.
How we process your personal data?
We process your personal data to provide, improve and administer our services, communicate with you, maintain security and prevent fraud, and comply with the Law. We may also process your personal data for other purposes with your consent. We process your personal data only if we have compelling legal reasons to do so.
In what situations and with what parties do we share personal data?
We may share personal data in situations specified by Law and with third parties specified by Law.
How we store your personal data?
We use organizational and technical processes and procedures to protect your personal data. However, neither electronic transmission over the Internet nor information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal or change your and personal data.
More information on our technical and organizational security measures is available in our documentation and, for customer processing, in the DPA.
What are your rights?
You may instruct us to provide you with any information about the personal data we hold about you. We reserve the right to refuse to provide information at your request, within the limits of applicable law.
You have the right to withdraw your consent to the processing of personal data at any time, without affecting the lawfulness of the processing that was based on the consent before its withdrawal.
You have the right to send us a request to correct or erase personal data, or to restrict the processing of personal data about you and to object to such processing.
You have the right to instruct us not to process your personal data for automated purposes or for marketing purposes.
Depending on your geographic location, applicable privacy laws may mean that you have additional rights with respect to your personal data.
How can you exercise your rights?
The easiest way to exercise your rights is to:
Visit our website https://effie.ai
Write a request to the effie Support Service at support@effie.ai / gdpr@effie.ai.
For privacy, GDPR and EU representative communications, you may contact gdpr@effie.ai
Make a phone call
| USA |
+1-224-284-9423
| EU | Ukraine | Asia
+38 095 286 19 89
+38 067 623 76 73
+38 044 333 49 94
We will consider any request and take action in accordance with applicable data protection laws.
2. What information do we collect
2.1. Personal data we collect
We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us in order to access the effie Service, express an interest in obtaining information about us or our products and services, when you participate in activities within the Services, or otherwise when you contact us.
We may also collect personal data that is uploaded, entered, synchronized, generated, submitted or otherwise processed through the Service by or on behalf of a corporate customer, including data of authorized users, employees, contractors, field representatives, merchandisers, administrators, partner/distributor personnel and other persons whose data is entered into the Service by the customer.
Depending on the context, effie may process personal data in different roles.
When we collect and process personal data for our own purposes, we act as a controller under the GDPR / UK GDPR or as a business under applicable U.S. state privacy laws. This may include, for example, personal data relating to website visitors, prospective customers, customer representatives, account administrators, authorized users, support contacts, billing contacts, marketing contacts, security logs, communications with us, and the administration, security and improvement of our websites, products and services.
When we provide the effie Service to a corporate customer and process personal data submitted to, synchronized with or generated through the Service on behalf of that customer, we generally act as a processor under the GDPR / UK GDPR or as a service provider / contractor under applicable U.S. state privacy laws. In that case, the corporate customer determines the purposes and means of processing, and we process Customer Personal Data in accordance with the applicable Agreement, DPA, product settings and the customer’s documented instructions.
If your personal data is processed by us on behalf of a corporate customer, you should normally direct your privacy request to that customer. Where required by applicable law, we will assist the customer in responding to such requests.
2.2. Personal data provided by you
The personal information we collect depends on the context of your interactions with us and the effie Service, the choices you make, and the products and features you use.
The personal data you provide to us may include the following:
name and surname;
phone number;
- email address;
- job title, position or professional role;
- company or organization name and business contact details, where such information relates to an identifiable individual;
- username, user ID, account ID or other account identifier;
- account access and authentication data, including login credentials or other data used for authentication, where applicable. Passwords, where used, are intended to be stored in protected form and used only for authentication, account security and related security purposes;
- information you include in requests, support tickets, incident reports, onboarding and implementation communications, forms, messages or other communications with us.
We may also process personal data submitted to, synchronized with or generated through the effie Service by or on behalf of a corporate customer. In that case, such data is processed in accordance with the applicable Agreement, Data Processing Agreement (DPA), customer settings and documented customer instructions.
2.3. Sensitive information
We do not intentionally collect special categories of personal data under GDPR Article 9 or similar highly sensitive data unless expressly agreed in writing, required for the Service configuration, or permitted by applicable law. Certain operational data, including precise geolocation, photos, device data, account credentials and employment-related field activity data, may be treated as sensitive personal information under some U.S. state privacy laws. Where such laws apply, we will provide the required rights, including limitation, opt-out or consent-based rights where mandated by law.
We do not assign the effie> Service, AI Features and AI Agents to process special categories of personal data (sensitive personal data), unless otherwise expressly provided for by law, contract or separate written consent. We ask that you do not upload such data without a proper legal basis and without objective necessity. If such data enters the effie> Service in violation of our rules or without a proper basis, we may take measures to restrict, block, delete or verify the relevant content or function.
2.4. Application data
If you use our effie> Service (apps), we may also collect the following information if you choose to grant us access or permission:
Geolocation information. We may request access to or permission to collect or track geolocation information from your mobile device, either continuously, in the background, or while you use our mobile application, where location-based functionality is enabled by you or by the corporate customer. This may include precise geolocation used for route planning, visit verification, store/audit activity, mileage tracking, security, support, diagnostics and similar Service functions. You can change device-level permissions in your device settings; however, disabling location access may limit or prevent certain Service functions. Where required by applicable law, we will provide or support the required notice, consent, opt-out, limitation or other legally required mechanism.
Mobile device access. We may request access to or permission to use certain features of your mobile device, including camera, storage, and other features. If you want to change our access or permissions, you can do so in your device settings.
Mobile device data. We automatically collect device information (such as your mobile device ID, model and manufacturer), operating system information, system version and configuration, device and application identification numbers, browser type and version, Internet service provider hardware model and/or mobile operator, and Internet Protocol (IP) address (or proxy server). If you use our application(s), we may also collect information about the telephone network associated with your mobile device, the operating system or platform of your mobile device, the type of mobile device you use, the unique identifier of your mobile device, and information about the features of our application(s) you accessed.
Push notifications. We may request to send you push notifications related to your account or certain features of the application(s).
This information is primarily needed to maintain the security and operation of our application, for troubleshooting purposes, and for internal analytics and reporting purposes.
This information may also be used to provide and secure the web portal, mobile application, API integrations, dashboards, image recognition, AI Features and other product modules enabled by the customer.
All personal information you provide to us must be true, complete and accurate, and you must notify us of any changes to such personal information.
3. How do we process your personal data?
We process your personal data to provide, improve and administer our services, communicate with you, maintain security and prevent fraud, and comply with the law. We may also process your personal data for other purposes with your consent.
We process your personal data for a variety of reasons depending on how you interact with our effie> Service , including:
- To facilitate account creation and authentication and otherwise manage user accounts. We may process your personal data so that we can create an account for you and maintain your account.
- To provide and facilitate the provision of services to the user. We may process your personal data in order to provide you with the service you have requested.
- To respond to/provide support to users. We may process your personal data to respond to your requests and resolve any potential problems you may have with the effie> Service .
- To send you administrative information. We may process your personal data to send you information about our products and services, changes to our terms and conditions and policies, and other similar information.
- To fulfill and manage your orders. We may process your personal data to fulfill and manage your requests made through the effie> Service.
- To ensure communication between users. We may process your personal data if you choose to take advantage of any of our offers that allow you to communicate with another user.
- To preserve or protect vital human interests. We may process your personal data if it is necessary to save or protect a person’s vital interests, for example to prevent harm.
- To provide, operate, secure, monitor, maintain, troubleshoot and administer the effie SaaS service, mobile application, web portal, APIs, integrations, dashboards, analytics, image recognition and AI Features.
- To manage onboarding, implementation, customer configuration, support requests, billing support, security monitoring, logging, diagnostics and incident investigation.
- To process Customer Personal Data on behalf of corporate customers under the applicable DPA, Agreement, order form, service settings and documented customer instructions.
- To comply with privacy, cybersecurity, breach notification, accounting, tax, audit, corporate, sanctions, export control and other legal or regulatory obligations where applicable.
3.1. Use of AI Features and AI Agents
The effie> service may use AI features to analyze photos, data, and other materials uploaded to the system, as well as to generate tips, recommendations, and other results for the user.
For the operation of AI features, we may process photos, files, text queries, responses, technical logs, and other data necessary for the operation, support, security, and improvement of the relevant features.
AI results are of an auxiliary nature and should not be used as the sole basis for making decisions about individuals without human verification.
To provide AI features, we may engage external technical providers, and in some cases, personal data may be transferred outside Ukraine or the EU with the use of appropriate protection mechanisms.
We do not assign AI features for biometric identification, emotion recognition, covert surveillance, or other prohibited use scenarios.
We ask that you do not upload sensitive personal data without a proper legal basis. If a user or client uploads materials containing personal data of third parties to the service, the responsibility for the legality of such upload rests with such user or client.
More detailed rules for using AI functions are defined separately in the AI Use Policy and other documents of the effie> Service.
Unless expressly agreed in writing, we do not use Customer Personal Data to train public foundation models or general-purpose third-party AI models for the benefit of third parties. Customer-specific configuration, validation, debugging, security monitoring and support may be performed only within the scope of the Agreement, DPA, AI Use Policy and customer instructions.
4. What legal grounds do we rely on when processing your personal data?
We process your personal data only when necessary and have a legal basis for doing so (i.e. a legal basis) to do so in accordance with applicable law, for example, with your consent, to comply with laws, to provide you with services to conclude/ to fulfill our contractual obligations, to protect your rights or to pursue our legitimate business interests.
The General Data Protection Regulation (GDPR), UK GDPR, ISO/IEC 27701 require us to explain what legal basis we rely on when processing your personal data. Therefore, we may rely on the following legal grounds to process your personal data:
Consent. We may process your personal data if you have given us permission (i.e. consent) to use your personal data for certain purposes. You can withdraw your consent at any time.
Performance of a contract. We may process your personal data where we believe it is necessary to fulfill our contractual obligations to you, including the provision of our effie> Service , or at your request before entering into a contract with you.
Legal obligations. We may process your personal data where we believe it is necessary to comply with our legal obligations, for example to cooperate with law enforcement authorities or regulatory agencies, to exercise or defend our legal rights, or to disclose your information as evidence in legal proceedings in which we participate.
Vital interests. We may process your personal data where we believe it is necessary to protect your vital interests or the vital interests of a third party, for example in situations involving a potential threat to the safety of any person.
Legitimate interests. We may process your personal data if we believe that such processing is necessary for our legitimate interests or the legitimate interests of a third party, provided that such interests do not override your rights and freedoms. This may include, in particular, ensuring information security, service stability, network and infrastructure security, preventing fraud, abuse and unauthorized access, maintaining event logs, investigating incidents, diagnosing and correcting errors, protecting the rights and claims of the Company, internal technical analytics, billing integrity (correctness of technical accounting of the use of functions) and proper administration of the effie> Service.
Where we act as a processor for a corporate customer, the customer is responsible for determining the lawful basis for processing Customer Personal Data. In that case, we process such data on the customer’s documented instructions and in accordance with the applicable DPA and Agreement.
5. When and with whom do we share your personal data?
We may share your personal information in certain situations described in this section and/or with the following third parties.
We may need to share your personal data in the following situations:
Business transfer. We may share or transfer your personal information in connection with or during negotiations of any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
When we use Google Maps Platform APIs . We may share your personal information using certain Google Maps Platform APIs (e.g., Google Maps API, Places API).
We may also transfer personal data to providers of cloud infrastructure, hosting, AI models, data processing services, authentication services, monitoring and logging services, support channels, telecommunications services, payment and accounting services, integration providers, professional advisors, auditors, representative in the European Union, affiliates, as well as government authorities or other persons in cases expressly provided for by law or necessary to protect our rights, security, legitimate interests or performance of a contract.
Where we process Customer Personal Data on behalf of a corporate customer, subprocessors and third-party providers are governed by the DPA, applicable subprocessor terms and contractual safeguards.
Where personal data subject to UK data protection law is transferred outside the United Kingdom to a country not covered by an applicable UK adequacy regulation, we rely on appropriate safeguards where required, including the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or another lawful transfer mechanism.
We may disclose personal data to effie affiliates and authorized resellers only where reasonably necessary to provide, sell, implement, support, secure or administer the Service, or where required under the applicable Agreement or law.
We do not sell Customer Personal Data processed through the Service. We do not use Customer Personal Data for cross-context behavioral advertising or targeted advertising unless expressly permitted by the customer and applicable law. Website cookies and marketing technologies are addressed separately in the Cookie Policy and the U.S. State Privacy Notice below.
6. Do we use COOKIES and other tracking technologies?
We may use cookies and other tracking technologies to collect and store your personal information.
We may use cookies and similar tracking technologies (such as web beacons and pixels) to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.
If you access our website or Service from the United Kingdom, our use of cookies and similar technologies may also be subject to the UK Privacy and Electronic Communications Regulations (PECR). Where required, we will request your consent before using non-essential cookies or similar technologies.
For additional information about U.S. state privacy choices relating to sale, sharing, targeted advertising, cross-context behavioral advertising and applicable opt-out rights, please see the U.S. State Privacy Notice below.
7. How long do we store your personal data?
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law, the Agreement, DPA, order form, customer settings, product limitations or applicable documentation.
Retention periods may vary depending on the type of data, the relevant Service module, customer configuration, product limitations, backup cycles, security requirements, legal requirements and the role in which we process the data.
Different retention periods may apply to different categories of data, including:
• account and access data;
• support requests, incidents and security logs;
• uploaded content, including photos, files, rules, questionnaires and knowledge materials;
• AI Output, prompts, telemetry, technical logs and usage records;
• backups, technical records and data necessary to comply with contractual, accounting, tax, audit, legal, dispute resolution, cybersecurity, fraud prevention, compliance or other statutory retention requirements.
For Customer Personal Data processed through the Service, the default technical retention depth for certain Service data and photos may be up to 12 full months, unless another retention period, access depth, deletion period or data availability period is specified in the Agreement, DPA, order form, customer settings, product limitations or applicable documentation. This retention depth describes the standard technical capability and configuration of the Service and does not constitute a guaranteed, mandatory or minimum retention period.
Upon termination or expiration of the applicable Agreement, Customer Personal Data may be retained for up to 30 days for the purpose of customer export, transition, technical closure and deletion procedures, unless a longer retention period is agreed with the customer, purchased as an additional retention option, required by law, or necessary for legal, tax, accounting, audit, dispute resolution, cybersecurity, fraud prevention, compliance or other statutory purposes.
After the applicable post-termination retention period expires, Customer Personal Data will be deleted, anonymized or isolated from active use in accordance with the Agreement, DPA, product limitations, backup cycles and applicable law. If immediate deletion is not technically possible, including because data is stored in backups, logs or security archives, we will restrict active use of such data and delete, anonymize or overwrite it in accordance with applicable deletion cycles and legal requirements.
Operational Service data, including photos, prompts, AI Output, usage records, telemetry and technical logs, is retained only for the period reasonably necessary to provide, secure, support, maintain and troubleshoot the Service, or, where permitted by the Agreement, DPA or customer instructions, to improve the Service, or as otherwise required or permitted by applicable law.
Certain categories of personal data may be retained for a longer period where necessary for tax, accounting, audit, legal hold, dispute resolution, cybersecurity, fraud prevention, compliance or other statutory retention purposes. In such cases, we retain the relevant data only for the period required or permitted by applicable law and restrict active use of such data where appropriate.
8. How do we store your personal data?
We strive to protect your personal data through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal data we process. However, despite our security measures and efforts to protect your information, neither electronic transmission over the Internet nor information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals or other unauthorized third parties will not be able to breach our security and improperly collect, access, steal or change your personal data. Although we will do our best to protect your personal information, transmission of personal information to and from our effie> Service is at your own risk. You must access the effie> Service only in a secure environment.
The Company maintains security and privacy governance aligned with ISO/IEC 27001 and ISO/IEC 27701 where applicable to the relevant certification scope. Security controls may include access control, authentication, encryption in transit, encryption at rest where supported by the relevant infrastructure, logging, monitoring, backups, vulnerability management, incident response and subprocessor governance. Additional information may be provided in the Security Overview, DPA or customer security documentation.
9. Do we collect personal data about minors?
We do not knowingly collect personal information from or provide services to people under 18 years of age.
We do not knowingly solicit personal information from children under 18 years of age. By using the effie> Service , you confirm that you are at least 18 years of age. If we learn that personal information from users under 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of information that we may have collected from children under 18 years of age, please contact us at support@effie.ai / gdpr@effie.ai.
The Service is intended for business use and is not directed to children or minors. Corporate customers must not intentionally upload children’s data.
10. What are your privacy rights?
In some regions, you have rights that allow you greater access and control over your personal information. You may review, change or terminate your account at any time. In addition, you have the right:
(i) request access to and obtain copies of your personal information,
(ii) request correction or deletion;
(iii) restrict the processing of your personal information;
(iv) if applicable, transfer data; And
(v) not be subject to automated decision making.
In some regions (for example, in Ukraine), you have certain rights in accordance with current data protection legislation (Article 8 of the Law of Ukraine “On the Protection of Personal Data”). These include the right to:
Information about your personal data – You can contact us at any time to receive information about:
• whether we process your personal data;
• for what purpose;
• sources of personal data collection;
- where we process your personal data;
• what categories of personal data we process;
• who is the recipient of your personal data and information about their transfer;
• Do we use automated decision making and its mechanism, if so.
Access to your personal data – You can access all of your personal data that we process.
Change of data – if information about you is or has become inaccurate or incomplete, you have the right to demand that the data be corrected or supplemented.
Withdrawal of consent – You can withdraw your consent to data processing at any time and this will not affect the lawfulness of processing based on consent before its withdrawal.
Destruction of data – You can request the destruction of data if it is inaccurate, or processed illegally, or if otherwise provided by law.
Restriction of processing – You may request that we restrict what we do with respect to your personal data.
Objection – You have the right to object to some of the actions we take with respect to your personal data for specific reasons related to your personal situation. If, despite your objection, we find that there are compelling legal grounds for processing that override your interests, rights and freedoms, or grounds for the establishment, exercise or defense of legal claims, we will continue to process the data raised in the objection. , to the extent necessary. If you do not agree with this assessment of the situation, you can exercise your right to file a complaint with the appropriate government agency (information below).
Complaints to the relevant government authority – in connection with our actions as the controller (owner) of your personal data, you have the right to lodge a complaint with the relevant regulatory authority or court. For Ukraine, such a body is the Commissioner of the Verkhovna Rada of Ukraine for Human Rights. You can find his contacts at https://www.ombudsman.gov.ua/ .
In certain circumstances, you may also have the right to object to the processing of your personal data. You may make such a request by contacting us at the contact information provided in the «How can you contact us regarding our personal data privacy policy?».
We will consider any request and take action in accordance with applicable data protection laws.
For privacy, GDPR and EU representative communications, you may contact gdpr@effie.ai.
If you are located in the EU or UK and believe that we are unlawfully processing your personal data, you also have the right to lodge a complaint with the data protection authority of an EU member state or the UK data protection authority. If you are located in Switzerland, you can contact the Federal Data Protection Commissioner. We encourage you to first contact us at the addresses provided in the «How can you contact us regarding our personal data privacy policy?» section.
We do not assign AI Features and AI Agents to make decisions without real human participation (solely automated decision-making) regarding individuals. If a certain corporate client (customer) uses the effie> Service in its own processes that may affect employees, contractors, representatives or other individuals, such client (customer) is obliged to independently ensure the lawful basis for processing (lawful basis), human control (Human Review), informing individuals, compliance with employment law and personal data protection law requirements.
Withdrawal of your consent.
Where we rely on your consent to process your personal data, which may be express and/or implied consent depending on applicable law, you have the right to withdraw your consent at any time. You may withdraw your consent at any time by contacting us at the contact details provided in the section «How can you contact us regarding our personal data privacy policy?»
Please note, however, that this will not affect the lawfulness of processing prior to withdrawal of consent or, where applicable law permits, it will not affect processing of your personal data carried out on lawful grounds other than consent.
Account Information.
If you would like to review or change the information in your account or terminate your account at any time, you may:
Contact us using the contact information provided.
Upon your request to terminate your account, we will deactivate or delete your account and your personal information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms and/or satisfy applicable legal requirements. If you have questions or comments regarding your privacy rights, you can write to us at: effie Support Service support@effie.ai.
11. United Kingdom Privacy Notice
If you are located in the United Kingdom, the processing of your personal data may be subject to the UK GDPR and the Data Protection Act 2018. In such cases, references in this Privacy Policy to GDPR rights, lawful bases, data subject rights, security obligations and international transfers should be read as including the corresponding requirements under UK data protection law.
UK individuals may have the right to access, correct, erase, restrict or object to the processing of their personal data, request data portability, withdraw consent where processing is based on consent, and not be subject to solely automated decision-making where applicable.
If and to the extent Article 27 of the UK GDPR requires us to appoint a UK representative, we will provide the relevant contact details in this Privacy Policy or another appropriate notice.
If you are located in the United Kingdom, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO). We encourage you to contact us first at gdpr@effie.ai so that we can try to resolve your concern.
12. U.S. State Privacy Notice
12.1. This section supplements the Privacy Policy and applies only to residents of U.S. states that provide specific privacy rights under applicable state privacy laws, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Indiana, Kentucky, Minnesota, Maryland, Rhode Island, Florida and any other U.S. state privacy law that applies to our processing. The inclusion of a state-specific section does not mean that a particular law applies to every processing activity, customer relationship, website visitor or Service user. We will apply state-specific rights only where the relevant law applies to us and to the relevant processing activity.
For purposes of this section, “personal data” or “personal information” generally means information linked or reasonably linkable to an identified or identifiable individual, subject to the definitions, exemptions and limitations under the applicable state law. In a B2B SaaS context, some data processed through the Service may be processed by us as a processor / service provider / contractor on behalf of a corporate customer. If your request concerns Customer Personal Data processed on behalf of a corporate customer, we may direct the request to that customer or act on its documented instructions, as required by the applicable DPA and law.
We do not currently use Customer Personal Data processed through the effie Service for sale, sharing, cross-context behavioral advertising or targeted advertising. If our website cookies or similar technologies are used in a way that gives rise to applicable opt-out rights under U.S. state privacy laws, you may exercise such rights through the cookie banner, cookie preferences tool, or by contacting us at support@effie.ai / gdpr@effie.ai.
Current and future state laws. As of the date of this update, additional comprehensive state privacy laws have been enacted but are not yet generally effective, including the Alabama Personal Data Protection Act (effective May 1, 2027), the Oklahoma Consumer Data Privacy Act (effective January 1, 2027), the Louisiana Data Privacy Act (effective January 1, 2027), and Vermont’s Data Privacy and Online Surveillance Act (effective January 1, 2028). We will apply those laws only from their applicable effective dates and only where their scope requirements are met.
Depending on the applicable state law, you may have one or more of the following rights:
• Right to know / confirm processing: the right to confirm whether we process your personal data and to receive information about such processing.
• Right of access: the right to access personal data we process about you.
• Right to correction: the right to correct inaccuracies in your personal data, where applicable.
• Right to deletion: the right to request deletion of personal data, subject to legal exceptions.
• Right to portability: the right to obtain a copy of personal data in a portable and, where technically feasible, readily usable format.
• Right to opt out: the right to opt out of sale of personal data, targeted advertising, sharing for cross-context behavioral advertising, or certain profiling, where applicable.
• Right to limit or withdraw consent for sensitive personal information / sensitive data: the right to limit use of sensitive personal information or withdraw consent for sensitive data processing, where applicable.
Sensitive data / sensitive personal information. Depending on the applicable U.S. state law, sensitive data may include precise geolocation data, account log-in credentials and etc. Where such laws apply, we will process sensitive data only as permitted by the applicable law, including through consent, opt-out, limitation, strict necessity, data minimization or other legally required mechanism.
• Right to appeal: the right to appeal our refusal to act on your request, where applicable.
• Right to non-discrimination / no retaliation: the right not to be discriminated against for exercising applicable privacy rights.
Universal opt-out mechanisms and GPC. Certain U.S. state privacy laws require covered businesses to recognize legally recognized universal opt-out mechanisms / opt-out preference signals, including Global Privacy Control (GPC), for applicable opt-out rights relating to sale, sharing, targeted advertising or certain profiling.
We are currently in the process of implementing technical support for GPC and other legally recognized universal opt-out mechanisms where required by applicable law. Until such technical support is implemented, you may exercise applicable opt-out rights through the cookie banner, cookie preferences tool, or by contacting us at support@effie.ai / gdpr@effie.ai.
We do not treat traditional Do-Not-Track (DNT) signals as the same mechanism as GPC or other legally recognized universal opt-out mechanisms unless applicable law requires otherwise.
Many U.S. state privacy laws apply only to individuals acting in a personal or household context and may exclude employment, commercial or B2B-context data. We apply state-specific rights only where the relevant law applies to the individual, the data and the processing activity.
12.2. California Notice at Collection and CCPA/CPRA rights
For California residents, this notice is intended to provide information required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act — CCPA/CPRA. In the preceding 12 months, we may have collected the following categories of personal information: identifiers; business contact information; professional or employment-related information; commercial/account information; internet or other electronic network activity; device and application data; geolocation data where enabled; audio, electronic, visual or similar information such as photos, video frames or support communications where applicable; inferences or analytics derived from Service use; and sensitive personal information where precise geolocation, account credentials or similar data are treated as sensitive under California law.
We collect such information from you, corporate customers, authorized users, customer systems and integrations, website and Service technologies, mobile applications, support communications, business partners, service providers and other lawful sources. We use it for the purposes described in this Privacy Policy, including providing the Service, account management, customer support, security, fraud prevention, analytics, billing support, legal compliance, AI/image recognition where enabled and business communications.
California residents may have the right to know/access, request deletion, request correction, obtain information about categories of personal information collected, used, disclosed, sold or shared, opt out of sale or sharing of personal information, limit the use and disclosure of sensitive personal information, and not be discriminated against for exercising CCPA/CPRA rights.
We do not sell Customer Personal Data processed through the Service. If website analytics, advertising, pixels or similar technologies constitute “sale” or “sharing” under CCPA/CPRA, California residents may opt out through the cookie banner, cookie preferences tool, or by contacting support@effie.ai / gdpr@effie.ai. We are in the process of implementing technical support for Global Privacy Control (GPC) where required by California law.
We may disclose personal information to service providers, contractors, processors, subprocessors, affiliates, professional advisers, auditors, public authorities and other recipients described in this Privacy Policy and the DPA. We do not knowingly sell or share personal information of children or minors. We do not use sensitive personal information for purposes other than those permitted by applicable law unless required consent or notice is provided.
12.3. Specific information for Colorado residents
The Colorado Privacy Act may provide Colorado residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, and opt out of the sale of personal data, targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects. Colorado residents may also have the right to appeal a refusal to act on a privacy request.
Where required by Colorado law, Universal opt-out mechanisms are addressed in Section 12.1 above.
12.4. Specific information for Connecticut residents
The Connecticut Data Privacy Act may provide Connecticut residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects, and appeal a refusal to act on a privacy request.
Connecticut law includes specific protections for sensitive data and may require consent for certain sensitive data processing.
Where required by Connecticut law, Universal opt-out mechanisms are addressed in Section 12.1 above.
We will apply Connecticut-specific rights and restrictions only where that law applies to the relevant processing.
12.5. Specific information for Virginia residents
The Virginia Consumer Data Protection Act may provide Virginia residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data provided by or obtained about the consumer, obtain a portable copy of personal data, and opt out of targeted advertising, sale of personal data or profiling in furtherance of decisions that produce legal or similarly significant effects. Virginia law requires consent for processing sensitive data where applicable and, effective July 1, 2026, prohibits the sale or offer for sale of consumers’ precise geolocation data where the law applies. Virginia residents may also have the right to appeal a refusal to act on a privacy request.
12.6. Specific information for Utah residents
The Utah Consumer Privacy Act provides Utah residents with a narrower set of rights than some other U.S. state privacy laws. Utah residents may have the right to confirm whether we process their personal data, access their personal data, correct inaccuracies in their personal data (taking into account the nature of the personal data and the purposes for which we process it), request deletion of personal data provided by the consumer, obtain a copy of personal data that the consumer previously provided to us in a portable and readily usable format where technically feasible, and opt out of the processing of personal data for targeted advertising or sale of personal data.
Utah residents also have the right not to be discriminated against for exercising UCPA rights. For example, we will not deny services, charge different prices or provide a different level of service solely because a Utah resident exercises applicable privacy rights, except as permitted by law. Utah law generally does not provide all rights available in some other states, such as a general right to appeal our decision on a request. We will apply Utah-specific rights only where the Utah Consumer Privacy Act applies.
12.7. Specific information for Texas residents
The Texas Data Privacy and Security Act may provide Texas residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, and opt out of targeted advertising, sale of personal data or profiling in furtherance of decisions that produce legal or similarly significant effects. Texas residents may also have the right to appeal a refusal to act on a privacy request.
Where required by Texas law, Universal opt-out mechanisms are addressed in Section 12.1 above.
Texas-specific rights apply only where the Texas Data Privacy and Security Act applies.
12.8. Specific information for Oregon residents
The Oregon Consumer Privacy Act may provide Oregon residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of sale of personal data, targeted advertising or certain profiling, and appeal a refusal to act on a privacy request. Oregon residents may also have the right to obtain information about the categories of third parties, and in some circumstances specific third parties, to whom personal data has been disclosed, subject to applicable law.
Oregon law includes specific rules for sensitive data. Where required, we will not process sensitive data subject to Oregon law except as permitted by law, under customer instructions, under the DPA, or with any required consent.
Oregon law also requires recognition of legally recognized universal opt-out mechanisms / opt-out preference signals for applicable opt-out rights and, from January 1, 2026, includes specific restrictions on the sale of precise geolocation data where the law applies. Universal opt-out mechanisms are addressed in Section 12.1 above.
12.9. Specific information for Montana residents
The Montana Consumer Data Privacy Act may provide Montana residents with rights to access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or profiling that produces legal or similarly significant effects, and appeal a refusal to act on a privacy request.
Where required by Montana law, Universal opt-out mechanisms are addressed in Section 12.1 above.
We will apply Montana-specific rights only where that law applies.
12.10. Specific information for Delaware residents
The Delaware Personal Data Privacy Act may provide Delaware residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a copy of personal data in a portable and readily usable format, opt out of targeted advertising, sale of personal data or certain profiling, and appeal a refusal to act on a privacy request. Delaware law also includes specific rules for sensitive data and children’s data.
Where required by Delaware law, Universal opt-out mechanisms are addressed in Section 12.1 above.
We will apply Delaware-specific requirements only where that law applies.
12.11. Specific information for Iowa residents
The Iowa Consumer Data Protection Act provides Iowa residents with a more limited set of rights than some other state privacy laws. Iowa residents may have the right to confirm whether we process personal data, access personal data, delete personal data provided by the consumer, obtain a copy of personal data that the consumer previously provided to us in a portable and, to the extent technically practicable, readily usable format, and opt out of the sale of personal data.
Iowa law generally does not provide all rights available under some other state privacy laws, such as a general right to correction or a general opt-out right for targeted advertising. We will apply Iowa-specific rights and response periods only where the Iowa Consumer Data Protection Act applies.
12.12. Specific information for Nebraska residents
The Nebraska Data Privacy Act may provide Nebraska residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or certain profiling, and appeal a refusal to act on a privacy request.
Where required by Nebraska law, Universal opt-out mechanisms are addressed in Section 12.1 above.
We will apply Nebraska-specific rights only where that law applies.
12.13. Specific information for New Hampshire residents
The New Hampshire comprehensive privacy law may provide New Hampshire residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or certain profiling, and appeal a refusal to act on a privacy request.
Where required by New Hampshire law, Universal opt-out mechanisms are addressed in Section 12.1 above.
We will apply New Hampshire-specific rights only where that law applies.
12.14. Specific information for New Jersey residents
The New Jersey Data Privacy Act may provide New Jersey residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a copy of personal data, opt out of sale, targeted advertising or certain profiling, and appeal a refusal to act on a privacy request.
Where required, Universal opt-out mechanisms are addressed in Section 12.1 above.
New Jersey law includes specific requirements for sensitive data and for recognizing universal opt-out mechanisms after the applicable effective dates. We will apply New Jersey-specific requirements only where that law applies.
12.15. Specific information for Tennessee residents
The Tennessee Information Protection Act may provide Tennessee residents with rights to confirm whether we process personal information, access personal information, correct inaccuracies, delete personal information, obtain a portable copy of personal information, opt out of sale of personal information, targeted advertising or certain profiling, and appeal a refusal to act on a privacy request. Tennessee law may provide an affirmative defense for businesses maintaining a written privacy program reasonably conforming to recognized frameworks. We will apply Tennessee-specific rights only where that law applies.
12.16. Specific information for Indiana residents
The Indiana Consumer Data Protection Act may provide Indiana residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or profiling in furtherance of decisions that produce legal or similarly significant effects, and appeal a refusal to act on a privacy request. Indiana-specific rights apply only where that law applies.
12.17. Specific information for Kentucky residents
The Kentucky Consumer Data Protection Act may provide Kentucky residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or certain profiling, and appeal a refusal to act on a privacy request. Kentucky-specific rights apply only where that law applies.
12.18. Specific information for Minnesota residents
The Minnesota Consumer Data Privacy Act may provide Minnesota residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or certain profiling, and appeal a refusal to act on a privacy request. Minnesota law may also include additional transparency rights, including rights related to profiling and, where applicable, information about the data used in profiling decisions.
Where required by Minnesota law, Universal opt-out mechanisms are addressed in Section 12.1 above.
We do not design the Service to make solely automated decisions that produce legal or similarly significant effects about individuals without meaningful human involvement. If a corporate customer uses the Service in its own processes affecting individuals, that customer is responsible for applicable notices, lawful basis, human review and employment/privacy compliance.
12.19. Specific information for Maryland residents
The Maryland Online Data Privacy Act may provide Maryland residents with rights to access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or certain profiling, and appeal a refusal to act on a privacy request. Maryland law includes stricter data minimization and sensitive data concepts than many other state laws, including restrictions on collecting, processing or sharing sensitive data unless permitted by the law.
Where required by Maryland law, Universal opt-out mechanisms are addressed in Section 12.1 above.
We do not design the Service for unnecessary, excessive or out-of-scope personal data, and we do not intentionally process sensitive data except as permitted by law, by customer instruction, by the DPA, or with required consent.
12.20. Specific information for Rhode Island residents
The Rhode Island Data Transparency and Privacy Protection Act may provide Rhode Island residents with rights to confirm whether we process personal data, access personal data, correct inaccuracies, delete personal data, obtain a copy of personal data, opt out of sale, targeted advertising or certain profiling, and appeal a refusal to act on a privacy request. Rhode Island law also requires transparency regarding categories of personal data and third parties in certain circumstances. We will apply Rhode Island-specific rights only where that law applies.
12.21. Specific information for Florida residents
The Florida Digital Bill of Rights, effective July 1, 2024, applies only to certain businesses that meet specific statutory thresholds and conditions. If it applies to our processing, Florida residents may have rights to access personal data, correct inaccuracies, delete personal data, obtain a portable copy of personal data, opt out of targeted advertising, sale of personal data or certain profiling, and appeal certain decisions regarding privacy requests. We will apply Florida-specific rights only where the Florida law applies to the relevant business and processing.
12.22. Specific information for other U.S. states and future laws
If another U.S. state privacy law applies to our processing, we will provide and honor the rights required by that law, including any mandatory notice, access, deletion, correction, portability, opt-out, appeal, sensitive-data, consumer health data, biometric, children’s privacy, profiling or other requirements, to the extent applicable. We may update this Privacy Policy to reflect new U.S. state privacy laws, amendments, implementing regulations or regulatory guidance.
12.23. New York Data Security Notice
New York does not currently have a comprehensive consumer privacy law equivalent to CCPA/CPRA for all businesses, but the New York SHIELD Act requires reasonable administrative, technical and physical safeguards for private information where applicable. For New York residents, we maintain safeguards designed to protect private information, which may include access controls, confidentiality obligations, security policies, monitoring, incident response, vendor/subprocessor controls and other measures described in the Security Overview and DPA.
12.24. How to submit U.S. privacy requests
You may submit privacy requests by contacting support@effie.ai / gdpr@effie.ai.. We may need to verify your identity and authority to act before processing a request. Authorized agents may submit requests where permitted by law, subject to verification and proof of authority. If we decline to act on a request and the applicable law provides a right to appeal, you may appeal by replying to our decision or contacting support@effie.ai / gdpr@effie.ai.with the subject line “Privacy Appeal”.
We will respond to authenticated consumer requests within the time period required by applicable law, generally 45 days where applicable, with extensions where permitted by law. Iowa law may allow a longer response period where applicable. If a request concerns Customer Personal Data processed in the Service on behalf of a corporate customer, we may refer the request to that customer or act on that customer’s documented instructions.
13. Republic of Kazakhstan Privacy Notice
13.1. Scope of this Kazakhstan Privacy Notice
This section provides additional information for individuals, users and corporate customers located in the Republic of Kazakhstan, or where the processing of personal data is subject to the laws of the Republic of Kazakhstan on personal data and their protection.
This section supplements the rest of this Privacy Policy. If there is any inconsistency between this section and the general provisions of this Privacy Policy in relation to processing subject to Kazakhstan personal data laws, this section applies to the extent required by such laws.
13.2. Websites, contact forms and direct communications
If you are located in the Republic of Kazakhstan and voluntarily provide us with personal data through our website, contact form, e-mail, messenger, telephone call, demo request, presentation request or another public communication channel, we may process such data to respond to your request, communicate with you, prepare an offer, provide information about the effie Service, maintain business correspondence, ensure website and communication security, and comply with applicable legal requirements.
Where required by the laws of the Republic of Kazakhstan, such processing, including any cross-border transfer of personal data, must be based on your consent or another lawful basis permitted by applicable law.
Your personal data may be processed outside the Republic of Kazakhstan, including in Ukraine, the European Economic Area, the United States and other countries where our companies, affiliates, hosting providers, communication providers, support providers, analytics, security or other technical providers are located, subject to the requirements of applicable law.
If you do not wish to provide personal data through public website or communication channels, please do not submit forms, requests, messages or other personal data through such channels and do not use interactive website features that require the provision of personal data.
13.3. Corporate use of the effie Service
The effie Service is provided to corporate customers. If you use the effie Service as an employee, contractor, representative, mobile employee, merchandiser, administrator or other authorized user of our corporate customer, we usually process your personal data on behalf of that corporate customer and in accordance with its documented instructions.
In such case, the corporate customer that granted you access to the Service, configured the Service, determined your role, uploaded or synchronized your data, or instructed you to use the Service is generally the owner and/or operator of the personal data database within the meaning of the laws of the Republic of Kazakhstan, to the extent that such customer determines the purposes, categories, sources, legal grounds, business processes, users, access rights, settings, retention periods and methods of use of such data.
We process such Customer Personal Data in accordance with the applicable Agreement, DPA, Service configuration, product settings and the corporate customer’s documented instructions.
13.4. Responsibility of the corporate customer
The corporate customer is responsible, within its area of control, for ensuring that personal data submitted to, synchronized with, generated through or otherwise processed in the effie Service is collected and used lawfully under the laws of the Republic of Kazakhstan.
This includes, where applicable, responsibility for:
- determining the lawful basis for collection and processing of personal data;
- obtaining and documenting consents of personal data subjects where required by law;
- informing employees, contractors, representatives, mobile users and other authorized users about the processing of their personal data in the Service;
- determining whether the processing of geolocation data, photos, video materials, CCTV materials, field activity data, audit data or other materials is lawful and necessary for the corporate customer’s business purposes;
- determining whether Kazakhstan data localization requirements apply to the relevant data, users, business processes or Service configuration;
- ensuring that the corporate customer’s internal instructions, employment documents, policies and user authorizations allow the relevant use of the Service;
- responding to requests of personal data subjects where the corporate customer determines the purposes and legal grounds of processing.
13.5. Data localization in the Republic of Kazakhstan
The laws of the Republic of Kazakhstan may require certain personal data to be stored in databases located in the territory of the Republic of Kazakhstan.
Where such requirements apply to the corporate customer’s data, users, employees, contractors, representatives, business processes or selected Service configuration, the corporate customer is responsible for determining the applicability of such requirements and for timely agreeing with us on an appropriate localized configuration, contractual arrangement, DPA, annex, technical documentation or separate agreement, where such configuration is required and available.
Unless a localized configuration is expressly agreed with the corporate customer, we do not represent that all data processed through the effie Service is stored exclusively in the Republic of Kazakhstan.
13.6. Data uploaded by the corporate customer and authorized users
The corporate customer and its authorized users are responsible, within their area of control, for the lawfulness, accuracy and necessity of generating, collecting, uploading, importing, synchronizing and using personal data, photos, video materials, CCTV materials, geolocation data, reports, files and other materials that they provide or upload to the Service.
If you believe that the use of the Service, uploading of data or processing of your personal data does not comply with the laws of the Republic of Kazakhstan, the internal policies of your organization or the authority granted to you, please do not upload such data to the Service and contact your employer, corporate customer, Service administrator or another responsible person on the corporate customer’s side.
13.7. Requests of personal data subjects from the Republic of Kazakhstan
If your personal data was provided to us by a corporate customer or processed in connection with the corporate customer’s use of the effie Service, you should generally contact that corporate customer to exercise your personal data subject rights, because that customer determines the purposes, legal grounds and essential means of processing.
Where required by applicable law and the applicable DPA, we will reasonably assist the corporate customer in responding to such requests.
If you provided personal data to us directly through our website, contact form, demo request, presentation request, e-mail or another public communication channel, you may send us a request using the contact details specified in this Privacy Policy.
14. Do Not Track Controls
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track feature. ‘DNT’), which you can activate to indicate your desire not to have data about your online activities tracked or collected. There is currently no single technology standard for recognizing and implementing DNT signals. Therefore, we do not currently respond to browser DNT signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted in the future that we must follow, we will inform you about such practices in a revised version of this privacy notice.
DNT is not the same as Global Privacy Control (GPC) or another legally recognized universal opt-out mechanism / opt-out preference signal under certain U.S. state privacy laws.
We are in the process of implementing technical support for GPC and other legally recognized universal opt-out mechanisms where required by applicable law. Until such technical support is implemented, you may exercise applicable opt-out rights through the cookie banner, cookie preferences tool, or by contacting us at support@effie.ai / gdpr@effie.ai.
15. Are we making changes to the personal data privacy policy?
Yes, we will update our privacy policy as necessary to remain compliant with applicable laws.
We may update our privacy policy from time to time. The updated version will be indicated by an updated date and the updated version will be effective as soon as it becomes available. If we make material changes to our privacy practices, we may notify you either by prominently posting notice of such changes or by directly sending you a notification. We encourage you to review our privacy policy frequently to stay informed about how we are protecting your information.
If we make material changes that affect active customers or the processing of Customer Personal Data, we may provide notice through the website, customer portal, email, Service notification, legal center or another reasonable method, depending on the nature of the change and applicable law.
16. How can you contact us regarding our personal data privacy policy?
If you have additional questions or comments about this notice, you may contact our Data Protection Officer (DPO) by email at support@effie.ai / gdpr@effie.ai, or by contacting with us by mail:
1. USA: effie.ai Inc., 570 Lake Cook Road Suite 300, Deerfield, IL 60015, USA (principal place of business); 16192 Coastal Highway, Lewes, Delaware 19958, USA (registered agent / service of process address)
2. EU: IPLAND EUROPE SP. Z O.O., st. Nowogrodzka 31, 00-051 Warsaw, Poland
3. ASIA REGION | UKRAINE: LLC «IPLAND», 27 Hetmana Kyryla Rozumovskoho Str., Kyiv City, 03115, Ukraine
17. How can you review, update or delete the information we collect about you?
Subject to the applicable laws of your country, you may have the right to request access to, change or delete the personal data we collect about you. To request to review, update or delete your personal information, please contact effie Support Service support@effie.ai / gdpr@effie.ai.
18. EU Representative in the European Union (Article 27 GDPR)
If and to the extent the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) applies to our processing activities pursuant to Article 3(2) GDPR, we have appointed an EU representative under Article 27 GDPR.
Our representative in the European Union is:
IPLAND EUROPE SP. Z O.O.
Registered office: st. Nowogrodzka 31, 00-511 Warsaw, Poland
NIP: 7011107745 | REGON: 523244786 | KRS Number: 0000993934
E-mail: gdpr@effie.ai
You may contact our EU Representative regarding GDPR-related matters, including requests from data subjects and communications from supervisory authorities. You may also contact us directly using the contact details in this Notice.
The email address above is a dedicated channel for EU Representative communications and is monitored to ensure prompt handling of requests.
The EU Representative is designated for GDPR-related communications where Article 27 GDPR applies. The appointment of an EU Representative does not change the role of the relevant effie company as controller or processor under the applicable Agreement, DPA or law.