1. Who is responsible for your data
Codester OÜ, registry code 16353798, is the controller for Digitizer account, billing, support, and service-security data. Our address is Paekivi tn 8, Vasalemma alevik, Lääne-Harju vald, 76101 Harju maakond, Estonia. Privacy requests can be sent to [email protected].
For personal data in documents and emails submitted by a customer, that customer normally determines the purpose of processing and is the controller. We act as its processor under the Data Processing Agreement. If you are mentioned in a customer's document, contact that customer first; we will assist it with your request.
2. Data we receive
- Account and team data: name, email address, authentication records, workspace and business membership, permissions, invitations, and acceptance of our terms.
- Business and billing data: company name, registry code, VAT number, address, billing contact, invoice reference, usage records, invoices, and payment administration.
- Customer content: submitted files and images, OCR text, extracted fields, document metadata, fingerprints for duplicate detection, and processing results. Documents can contain names, contact information, bank details, transaction details, and other information chosen by the customer.
- Email and integration data: sender and recipient addresses, original emails and attachments where email ingestion is used, sender-approval records, callback URLs, and delivery status and payloads.
- Technical and support data: IP address, browser information, session and access logs, errors, security events, and information you include in support correspondence.
- We receive information from you, workspace administrators, authorised email senders, and your integrations. Company autocomplete and registry enrichment use public business-register information. Optional Google sign-in provides the identity information needed to create or access your account.
3. Why we process it
We process customer-document data on the customer's documented instructions; the customer establishes the applicable legal basis. We do not sell personal data or use customer documents to train general-purpose models. Extraction is automated, but Digitizer does not itself make decisions about people with legal or similarly significant effects. Customers must review outputs and are responsible for their own subsequent decisions.
| Purpose | Legal basis when we are controller |
|---|---|
| Create and administer accounts; provide support and the service | Performance of a contract, or steps requested before one. For an organisation's users, our legitimate interest in administering its service. |
| Measure usage, issue invoices, and meet accounting duties | Contract performance and compliance with legal obligations. |
| Protect accounts, investigate abuse, and maintain reliable service | Legitimate interests in protecting customers and operating a secure service, balanced against individuals' rights. |
| Handle disputes and establish or defend legal claims | Legal obligations and legitimate interests in resolving disputes. |
| Optional marketing or non-essential tracking, if introduced | Consent where required; offered separately and withdrawable. It is not a condition of using the service. |
4. EU document storage and processing
Our production service stores and processes customer documents, extracted data, and their backups in EU data centres. This includes document recognition and extraction; using EU storage alone is not sufficient for this commitment.
You can instruct us to send results to an external callback, email recipient, or other destination. Those destinations may be outside the EU and are under your control. Their processing and retention are governed by your arrangements with them. Do not configure a non-EU destination if your own requirements prohibit such transfers.
Optional identity services and other supporting providers may process account or service metadata internationally. Where we arrange an EEA-to-third-country transfer, we must use an applicable adequacy decision or appropriate safeguards, such as the European Commission's standard contractual clauses and any necessary supplementary measures. Contact us for the relevant recipients, processing locations, or a copy of applicable safeguards. We do not describe every third-party service as EU-only.
5. Who can receive data
Access is limited to authorised personnel, your authorised workspace users, and providers needed to operate the service. Provider categories include EU infrastructure and backup hosting, document-processing infrastructure, transactional email and email routing, optional identity authentication, and business-register lookup. The company register receives search terms or company identifiers, not a full document upload for autocomplete.
We require appropriate confidentiality, security, and data-processing terms from processors. Customers can obtain the current subprocessor identities, functions, and processing countries at [email protected] before entrusting personal data to the service. Subprocessor authorisation and change notices are governed by the Data Processing Agreement.
We may disclose information where required by law, to protect legal rights, or in connection with a lawful business transfer subject to appropriate protections and notice. We do not grant an unrelated party general access to your workspace.
6. Retention and deletion
Customer documents and extracted data are kept until the customer deletes them or closes the workspace, unless a legal obligation requires limited retention. Stored source emails and attachments are separate records: removing a processed document does not remove its source email. Contact [email protected] to request deletion of source email, related processing copies, an account, or a workspace. We verify authority before acting.
Deleted customer content is removed from backup copies within 30 days. Backup copies are restricted to recovery; if restored during that period, deletion instructions must be reapplied before normal use. This does not remove copies already exported or delivered to customer-selected recipients.
We retain our accounting source records, including invoices, for seven years from the end of the financial year in which the transaction was recorded, as required by Estonian accounting law. Deleting documents does not erase the limited usage and invoice records needed to substantiate a charge. We retain other account, support, and security records only while needed for their stated purpose, an unresolved request or incident, a legal duty, or an applicable claims period; we review them for deletion when that need ends.
7. Safeguards
We use account authentication, role and business-based access controls, protected credentials, signed callbacks, and restricted administrative access. Production deployments must use encrypted transport, secured EU storage and backups, and controlled access by authorised personnel. We assess safeguards against the nature and risks of the processing. No system is entirely risk-free; report a suspected security issue to [email protected].
We provide customers with information and assistance required by the Data Processing Agreement when an incident affects their personal data. Notifications to individuals or authorities are made where legally required.
8. Your choices and rights
Depending on the circumstances, you can request access, correction, erasure, restriction, or portability of your personal data, and object to processing based on legitimate interests. You can withdraw any consent without affecting earlier lawful processing. Some requests are subject to legal exceptions, including accounting retention and legal claims.
Send requests to [email protected]. We may need proportionate information to verify identity and clarify the request. We respond within one month; where the law permits an extension for complexity or number of requests, we explain the reason within that first month. If the data belongs to a customer's document, we direct the request to that controller and assist it.
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee, [email protected]) or to the supervisory authority where you live, work, or where an alleged infringement occurred. You do not need our permission to do so.
9. Website preferences and changes
Our Cookies notice explains authentication cookies and preferences stored on your device. Fonts are served from Digitizer rather than requested by your browser from a third-party font service. We do not currently use advertising cookies or third-party analytics trackers.
This policy may be updated to reflect service or legal changes. The date at the top identifies the current version. We will draw material changes to account holders' attention, and obtain consent where a new purpose requires it.
Questions?
Contact Codester OÜ at [email protected].