Privacy Policy
This Policy explains how Ryniqo OÜ (“Ryniqo”, “we”) processes personal data as a controller for its marketing site and as a processor for the RynIQ™ Executive Decision Intelligence Platform. It is written to be read by Data Protection Officers, procurement teams, and the executives whose data we handle.
| Version | 2.0 | Effective | On publication |
|---|---|---|---|
| Supersedes | 1.0 (2025) | Governing law | Estonia · EU |
Controller and contact
The controller for personal data processed via ryniqo.com and the RynIQ™ platform is Ryniqo OÜ, a private limited company incorporated in the Republic of Estonia and entered on the Estonian Commercial Register (e-Business Register maintained by the Centre of Registers and Information Systems).
Privacy enquiries and rights requests: privacy@ryniqo.com. We respond to substantive requests within one calendar month, extendable by two further months for complex requests under Article 12(3) GDPR.
A Data Protection Officer is not required under Article 37 GDPR. Privacy accountability sits with the Founder and is delegated operationally to the person answering privacy@ryniqo.com.
Scope
This Policy applies to (a) visitors to ryniqo.com, (b) individuals who complete the Executive Decision Snapshot™, (c) representatives of prospective and current customers communicating with us, and (d) recipients of the Executive Decision Brief™ and related deliverables.
Where Ryniqo processes personal data on behalf of a customer under a signed order — for example, workshop notes or portfolio data uploaded by a customer — Ryniqo acts as a processor and the customer is controller. In those cases the Data Processing Agreement governs, and this Policy applies only to the extent it describes technical and organisational measures.
Categories of data and lawful basis
We process the minimum data required to deliver the Platform and operate our business. We do not knowingly process special-category data (Article 9 GDPR) and ask customers not to submit it.
| Category | Purpose | Lawful basis (Art. 6) |
|---|---|---|
| Identifiers (name, business email, role, company) | Deliver the Snapshot and Executive Review; account access | Contract performance (1(b)); legitimate interests (1(f)) |
| Assessment responses | Generate the Snapshot and Executive Decision Brief | Contract performance (1(b)) |
| Meeting bookings and calendar metadata | Schedule Executive Reviews and workshops | Contract performance (1(b)) |
| Business correspondence and workshop notes | Deliver consulting engagements; internal record | Contract performance (1(b)); legitimate interests (1(f)) |
| Usage analytics (pseudonymous) | Improve the Platform; measure content performance | Legitimate interests (1(f)); consent where required (1(a)) |
| Marketing contact data | Send updates to prospects and customers who opted in or with whom we have a soft opt-in | Consent (1(a)); legitimate interests (1(f)) under PECR-equivalent local rules |
| Security and audit logs | Detect, investigate and remediate incidents; abuse prevention | Legitimate interests (1(f)); legal obligation (1(c)) |
Our legitimate-interest assessments (LIA) balance our commercial interests against the reasonable expectations of data subjects; a summary is available on request to privacy@ryniqo.com.
AI processing and human review
The Snapshot and the Executive Decision Brief use machine learning models to structure, cluster and summarise the responses executives provide. No decision that produces legal effects or similarly significant effects on any individual is taken solely by automated means (Article 22 GDPR is not engaged).
Every formal recommendation issued as an Executive Decision Brief is reviewed by a human before delivery. Decision Confidence™ is an evidence indicator, not an autonomous verdict. See the Responsible AI Policy and the AI Transparency Statement.
Customer content is not used to train foundation models. Model providers are contractually bound to zero-retention or short-retention terms. Prompt and response payloads are logged only to the extent required for security, abuse prevention and quality assurance.
Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, then delete or irreversibly anonymise it.
| Record | Retention |
|---|---|
| Assessment responses | 24 months from submission |
| Executive Decision Briefs | 36 months from delivery |
| Contact enquiries | 12 months from last contact |
| Usage analytics | 14 months from event |
| Marketing lists | Until unsubscribe or 24 months of inactivity |
| Security and audit logs | 12 months (extended for open incidents) |
| Accounting records | 7 years (Estonian Accounting Act §12) |
International transfers
Personal data is hosted in the European Economic Area by default. Where a subprocessor processes data outside the EEA — for example, model inference or transactional email — we rely on one of the following Article 46 safeguards:
- European Commission adequacy decisions (e.g. United Kingdom, Switzerland, EU–US Data Privacy Framework where the recipient is certified);
- the 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Modules 2 or 3 as applicable, together with a Transfer Impact Assessment;
- supplementary technical measures such as encryption in transit and at rest and minimisation before transfer.
A copy of the SCCs entered into with any subprocessor is available to enterprise customers on request under NDA.
Subprocessors
A current list of subprocessors, the services they perform and their hosting regions is maintained at /legal/subprocessors. Customers can subscribe to change notifications by writing to privacy@ryniqo.com. Objections to a proposed subprocessor are governed by the DPA.
Security
Technical and organisational measures include TLS 1.2+ in transit, AES-256 at rest, least-privilege access, MFA on all administrative accounts, row-level authorisation at the database, structured audit logging and regular encrypted backups. Full detail is in the Information Security Policy.
Confirmed personal-data breaches are notified to affected controllers without undue delay and, where feasible, within 72 hours (Article 33 GDPR).
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time without affecting the lawfulness of prior processing.
Requests should be sent to privacy@ryniqo.com. We may verify identity before acting on a request.
You have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), Tatari 39, 10134 Tallinn, Estonia — info@aki.ee — +372 627 4135 — www.aki.ee.
Children
The Platform is intended for use by employees of organisations acting in a professional capacity. It is not directed to children under 16 and we do not knowingly collect personal data from them.
Business and enterprise customers
Where Ryniqo processes personal data on behalf of an organisation, that organisation is controller and remains responsible for the lawful basis of its processing and for informing its own personnel. Ryniqo enters into a Data Processing Agreement with every such organisation on request or as part of order paperwork.
Account and data deletion
Customers can request deletion of an account and its associated personal data by writing to privacy@ryniqo.com. Deletion is executed within 30 days, subject to legal retention obligations (e.g. accounting) and legitimate interests (e.g. dispute defence).
Changes to this Policy
Material changes are announced by updating the version number and effective date and, where appropriate, by individual notice. A version history is maintained in Appendix B.
Definitions
- Controller
- The party that determines the purposes and means of processing personal data.
- Processor
- The party that processes personal data on behalf of a controller.
- Platform
- RynIQ™ Executive Decision Intelligence Platform, including the Snapshot, Executive Review and Brief.
- Personal data
- Any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
- GDPR
- Regulation (EU) 2016/679.
- SCCs
- Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914.
Categories of recipients
- Ryniqo personnel bound by written confidentiality obligations.
- Subprocessors listed at /legal/subprocessors.
- Professional advisers (accountants, lawyers, auditors) under duty of confidence.
- Regulators, courts and law-enforcement bodies where legally required.
- Acquirers or successors in the event of a merger or reorganisation, under equivalent protection.
Version history
| Version | Date | Summary |
|---|---|---|
| 2.0 | On publication | Enterprise rewrite; added AI processing, transfer, and rights sections. |
| 1.0 | 2025 | Initial policy. |