Back to Home

Privacy Policy

LAST_UPDATED: JULY_20_2026

Northnode OU, based in Estonia (trading as "initIA"), respects your privacy and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.

SEC_01: DATA_CONTROLLER

01.Data Controller

Northnode OU Address: Telliskivi tn 57, 10412 Tallinn, Estonia Email: hello@initia.studio Supervisory Authority: Estonian Data Protection Inspectorate (www.aki.ee)

SEC_02: DATA_WE_COLLECT

02.Data We Collect

We collect only the data necessary to provide AI automation services. Data is obtained directly from you through our contact form, email, WhatsApp, or during service delivery.

Contact data (name, email, company) - Legal basis: Art. 6.1.b GDPR (contract) Communication data (messages, inquiries) - Legal basis: Art. 6.1.f (legitimate interest) Aggregated analytics data (page views, referrers, device type - no cookies, no personal identifiers) - Legal basis: Art. 6.1.f (legitimate interest) Business data (billing information, if applicable) - Legal basis: Art. 6.1.c (legal obligation)

SEC_03: PROCESSING_PURPOSES

03.Processing Purposes

Provision of consulting and business automation services. Client management and billing. Commercial communication and support. Service improvement through aggregated analysis. Legal compliance and fraud prevention.

SEC_04: DATA_SHARING

04.Data Sharing

We share data with: infrastructure and hosting providers, email delivery providers, and scheduling and messaging service providers we use to book calls and communicate with you. All processors are bound by data processing agreements (DPAs). We share data with authorities only when required by law. We do not sell personal data.

SEC_05: INTERNATIONAL_TRANSFERS

05.International Transfers

Some of our service providers (hosting, scheduling, and messaging services) may process data outside the European Economic Area, including in the United States. Where this occurs, we rely on the European Commission's Standard Contractual Clauses and equivalent safeguards.

SEC_06: DATA_RETENTION

06.Data Retention

Contact data: contract duration + 5 fiscal years. Analytics data: 14 months, held in aggregate form. Billing data: 7 years (Estonian legal obligation).

SEC_07: YOUR_GDPR_RIGHTS

07.Your GDPR Rights

You have the right to: access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and to withdraw consent. We will respond to your request within 30 days.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).

Contact us at: hello@initia.studio

SEC_08: AUTOMATED_DECISIONS

08.Automated Decision-Making

We do not make decisions based solely on automated processing that produce legal effects or significantly affect you.

SEC_09: SECURITY_COOKIES_&_ANALYTICS

09.Security, Cookies & Analytics

We implement encryption, access controls, and regular audits.

This site does not use tracking or advertising cookies. We use privacy-first, cookieless analytics (Vercel Analytics) to understand aggregate traffic patterns - no cookies are set and no individual visitor is identified. We do not use Google Analytics or any cross-site advertising trackers.

If this changes in the future, we will update this policy and request your consent before any non-essential cookie is set.

SEC_10: POLICY_CHANGES

10.Changes to This Policy

We may update this policy and will notify you of significant changes via email or website notice.

© 2026 init|A • All rights reserved.