Grandparents Sale · 15% off

    Shop

    GDPR Privacy Notice

    Effective Date: April 2026

    Introduction

    This GDPR Privacy Notice supplements our main Privacy Policy and provides additional information specifically for individuals in the European Economic Area (EEA), United Kingdom, and Switzerland.

    Ethos (operating as Ethos OÜ, registry code 16972881, located at Kursi tn 3, 10415 Tallinn, Estonia) is the data controller for the personal information we collect through our service.

    Contact: hello@ethosbook.co

    Lawful Basis for Processing

    Under GDPR, we must have a lawful basis to process your personal data. Here's how we process different types of information:

    Performance of Contract

    We process the following data to fulfill our contract with you (creating your biography book):

    • Account information (name, email, phone) - To create and manage your account
    • Payment information - To process your order
    • Shipping information - To deliver physical books
    • Voice recordings and stories - To generate your personalized book
    • Support communications - To help you use our service

    We process the following data only with your explicit consent:

    • Marketing emails - To send promotional content (you can withdraw consent anytime)
    • Analytics cookies (PostHog, Supabase) - To improve our service
    • Marketing cookies (Meta Pixel, Rewardful) - For advertising and affiliate tracking
    • Sensitive personal information in your stories (health, religion, etc.)

    Legitimate Interest

    We process the following data based on our legitimate business interests:

    • Technical and usage data - To maintain security and prevent fraud
    • Customer support interactions - To improve our service quality
    • Anonymized analytics - To understand how our service is used

    You have the right to object to processing based on legitimate interest.

    We process certain data to comply with legal requirements:

    • Tax and accounting records - Required by Estonian law (7 years)
    • Payment records - For anti-money laundering compliance
    • Data breach notifications - As required by GDPR

    Your GDPR Rights

    Right to Access (Article 15)

    You can request:

    • A copy of all personal data we hold about you
    • Information about how we use your data
    • Who we share your data with
    • How long we keep your data

    How to request: Email hello@ethosbook.co with "Access Request" in the subject line.

    Right to Rectification (Article 16)

    You can request corrections to inaccurate or incomplete information.

    How to request: Email hello@ethosbook.co with the corrections you'd like to make.

    Right to Erasure / "Right to be Forgotten" (Article 17)

    You can request deletion of your personal data. We will delete your data unless we have a legal obligation to keep it.

    Exceptions where we cannot delete:

    • Tax and accounting records (7 years under Estonian law)
    • Legal claims or disputes in progress
    • Legal obligations to retain certain data

    How to request: Email hello@ethosbook.co with "Deletion Request" in the subject line.

    What we delete:

    • Your account information
    • All voice recordings and stories
    • Payment history (after legal retention period)
    • All backups within 30 days

    Right to Restrict Processing (Article 18)

    You can limit how we use your data in certain circumstances:

    • While we verify accuracy of contested data
    • When processing is unlawful but you don't want deletion
    • When we no longer need the data but you need it for legal claims
    • While we verify legitimate grounds after you object to processing

    How to request: Email hello@ethosbook.co explaining your restriction request.

    Right to Data Portability (Article 20)

    You can receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV). This includes:

    • Your account information
    • Transcripts of your voice recordings
    • Audio files of your recordings
    • Generated book content

    How to request: Email hello@ethosbook.co with "Data Portability Request" in the subject line.

    Right to Object (Article 21)

    You can object to:

    • Processing based on legitimate interests
    • Direct marketing (including profiling)
    • Processing for research or statistical purposes

    How to request: Email hello@ethosbook.co with "Objection Notice" in the subject line.

    Rights Related to Automated Decision-Making (Article 22)

    We use AI to generate your book content, but you are not subject to fully automated decisions that have legal or significant effects on you. Human review and your input are always part of the process.

    Where we process data based on your consent, you can withdraw it at any time:

    • Marketing emails: Click unsubscribe in any email or email hello@ethosbook.co
    • Analytics cookies: Adjust settings in our cookie banner
    • Sensitive data processing: Email hello@ethosbook.co

    Withdrawing consent doesn't affect the lawfulness of processing before withdrawal.

    How to Exercise Your Rights

    Email: hello@ethosbook.co

    Subject line: Include the type of request (e.g., "Access Request", "Deletion Request")

    Response time: We will respond within 30 days (may extend by 2 months if complex)

    Identity Verification:

    We'll verify your identity before fulfilling requests to protect your data. We may ask for:

    • Your registered email address
    • Account details you provided
    • Answers to security questions

    No Fee:

    We don't charge for most requests. If requests are clearly unfounded or excessive, we may charge a reasonable fee or refuse the request.

    International Data Transfers

    Your data may be transferred outside the EEA to the United States and other countries. We protect these transfers using:

    Standard Contractual Clauses (SCCs)

    We use EU Commission-approved Standard Contractual Clauses with:

    • Supabase (US-based hosting)
    • Stripe (payment processing)
    • ElevenLabs (voice transcription)
    • Other US-based service providers

    Adequacy Decisions

    We transfer data to countries with EU adequacy decisions where applicable.

    Additional Safeguards

    For transfers to the US, we implement:

    • Encryption in transit and at rest
    • Access controls and authentication
    • Regular security audits
    • Data processing agreements
    • Transfer impact assessments

    Request copies: Email hello@ethosbook.co to receive copies of our Standard Contractual Clauses or transfer safeguards.

    Data Retention Periods

    Data TypeRetention PeriodLawful Basis
    Account informationWhile account active + 90 daysPerformance of contract
    Voice recordingsWhile account active + 90 daysPerformance of contract
    Payment records7 years after transactionLegal obligation (tax law)
    Marketing consentsUntil withdrawn + 30 daysConsent
    Support tickets3 years after resolutionLegitimate interest
    Analytics data (anonymized)IndefinitelyLegitimate interest
    Deleted account backups30 days maximumTechnical necessity

    Supervisory Authority

    If you're unhappy with how we handle your data, you have the right to lodge a complaint with a supervisory authority:

    Estonia (Our Lead Supervisory Authority)

    Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)

    Website: www.aki.ee

    Email: info@aki.ee

    Address: Tatari 39, 10134 Tallinn, Estonia

    Your Local Authority

    You can also contact the data protection authority in your country of residence. Find your local authority at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

    Special Categories of Personal Data

    Your stories may contain "special category" data under GDPR Article 9:

    • Racial or ethnic origin
    • Political opinions
    • Religious or philosophical beliefs
    • Health information
    • Sexual orientation
    • Biometric data

    Processing Basis: We process this data with your explicit consent and only to create your book. You can withdraw consent at any time by emailing hello@ethosbook.co.

    Extra Protections:

    • Encrypted storage and transmission
    • Access restricted to essential personnel
    • Never used for profiling or automated decisions
    • Never shared with third parties except processors under strict contracts

    Data Protection by Design and Default

    We implement privacy-protective measures throughout our service:

    • Encryption: All data encrypted in transit (TLS/SSL) and at rest (AES-256)
    • Access controls: Role-based access with least privilege principle
    • Pseudonymization: Internal systems use IDs instead of names where possible
    • Data minimization: We only collect data necessary for our service
    • Regular audits: Quarterly security and privacy reviews
    • Staff training: All employees trained on GDPR compliance

    Data Breach Notification

    If we experience a personal data breach that risks your rights and freedoms:

    • To you: We'll notify you within 72 hours if high risk
    • To supervisory authority: We'll notify Estonian DPA within 72 hours
    • Information provided: Nature of breach, likely consequences, measures taken

    Changes to This Notice

    We may update this GDPR Privacy Notice to reflect changes in:

    • Our data processing practices
    • GDPR requirements or guidance
    • Supervisory authority recommendations

    When we make significant changes:

    • We'll email you 30 days in advance
    • We'll post the updated notice on our website
    • We'll update the "Effective Date" at the top

    Contact Our Data Protection Officer

    For GDPR-specific questions or to exercise your rights:

    Email: hello@ethosbook.co

    Mail:

    Data Protection Officer

    Ethos OÜ

    Kursi tn 3, 10415 Tallinn, Estonia

    Response time: 7 business days for initial response, 30 days for full resolution


    We respect your GDPR rights and are committed to protecting your personal data with the highest European privacy standards.