GDPR Privacy Notice
Effective Date: April 2026
Introduction
This GDPR Privacy Notice supplements our main Privacy Policy and provides additional information specifically for individuals in the European Economic Area (EEA), United Kingdom, and Switzerland.
Ethos (operating as Ethos OÜ, registry code 16972881, located at Kursi tn 3, 10415 Tallinn, Estonia) is the data controller for the personal information we collect through our service.
Contact: hello@ethosbook.co
Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process your personal data. Here's how we process different types of information:
Performance of Contract
We process the following data to fulfill our contract with you (creating your biography book):
- Account information (name, email, phone) - To create and manage your account
- Payment information - To process your order
- Shipping information - To deliver physical books
- Voice recordings and stories - To generate your personalized book
- Support communications - To help you use our service
Your Consent
We process the following data only with your explicit consent:
- Marketing emails - To send promotional content (you can withdraw consent anytime)
- Analytics cookies (PostHog, Supabase) - To improve our service
- Marketing cookies (Meta Pixel, Rewardful) - For advertising and affiliate tracking
- Sensitive personal information in your stories (health, religion, etc.)
Legitimate Interest
We process the following data based on our legitimate business interests:
- Technical and usage data - To maintain security and prevent fraud
- Customer support interactions - To improve our service quality
- Anonymized analytics - To understand how our service is used
You have the right to object to processing based on legitimate interest.
Legal Obligation
We process certain data to comply with legal requirements:
- Tax and accounting records - Required by Estonian law (7 years)
- Payment records - For anti-money laundering compliance
- Data breach notifications - As required by GDPR
Your GDPR Rights
Right to Access (Article 15)
You can request:
- A copy of all personal data we hold about you
- Information about how we use your data
- Who we share your data with
- How long we keep your data
How to request: Email hello@ethosbook.co with "Access Request" in the subject line.
Right to Rectification (Article 16)
You can request corrections to inaccurate or incomplete information.
How to request: Email hello@ethosbook.co with the corrections you'd like to make.
Right to Erasure / "Right to be Forgotten" (Article 17)
You can request deletion of your personal data. We will delete your data unless we have a legal obligation to keep it.
Exceptions where we cannot delete:
- Tax and accounting records (7 years under Estonian law)
- Legal claims or disputes in progress
- Legal obligations to retain certain data
How to request: Email hello@ethosbook.co with "Deletion Request" in the subject line.
What we delete:
- Your account information
- All voice recordings and stories
- Payment history (after legal retention period)
- All backups within 30 days
Right to Restrict Processing (Article 18)
You can limit how we use your data in certain circumstances:
- While we verify accuracy of contested data
- When processing is unlawful but you don't want deletion
- When we no longer need the data but you need it for legal claims
- While we verify legitimate grounds after you object to processing
How to request: Email hello@ethosbook.co explaining your restriction request.
Right to Data Portability (Article 20)
You can receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV). This includes:
- Your account information
- Transcripts of your voice recordings
- Audio files of your recordings
- Generated book content
How to request: Email hello@ethosbook.co with "Data Portability Request" in the subject line.
Right to Object (Article 21)
You can object to:
- Processing based on legitimate interests
- Direct marketing (including profiling)
- Processing for research or statistical purposes
How to request: Email hello@ethosbook.co with "Objection Notice" in the subject line.
Rights Related to Automated Decision-Making (Article 22)
We use AI to generate your book content, but you are not subject to fully automated decisions that have legal or significant effects on you. Human review and your input are always part of the process.
Right to Withdraw Consent
Where we process data based on your consent, you can withdraw it at any time:
- Marketing emails: Click unsubscribe in any email or email hello@ethosbook.co
- Analytics cookies: Adjust settings in our cookie banner
- Sensitive data processing: Email hello@ethosbook.co
Withdrawing consent doesn't affect the lawfulness of processing before withdrawal.
How to Exercise Your Rights
Email: hello@ethosbook.co
Subject line: Include the type of request (e.g., "Access Request", "Deletion Request")
Response time: We will respond within 30 days (may extend by 2 months if complex)
Identity Verification:
We'll verify your identity before fulfilling requests to protect your data. We may ask for:
- Your registered email address
- Account details you provided
- Answers to security questions
No Fee:
We don't charge for most requests. If requests are clearly unfounded or excessive, we may charge a reasonable fee or refuse the request.
International Data Transfers
Your data may be transferred outside the EEA to the United States and other countries. We protect these transfers using:
Standard Contractual Clauses (SCCs)
We use EU Commission-approved Standard Contractual Clauses with:
- Supabase (US-based hosting)
- Stripe (payment processing)
- ElevenLabs (voice transcription)
- Other US-based service providers
Adequacy Decisions
We transfer data to countries with EU adequacy decisions where applicable.
Additional Safeguards
For transfers to the US, we implement:
- Encryption in transit and at rest
- Access controls and authentication
- Regular security audits
- Data processing agreements
- Transfer impact assessments
Request copies: Email hello@ethosbook.co to receive copies of our Standard Contractual Clauses or transfer safeguards.
Data Retention Periods
| Data Type | Retention Period | Lawful Basis |
|---|---|---|
| Account information | While account active + 90 days | Performance of contract |
| Voice recordings | While account active + 90 days | Performance of contract |
| Payment records | 7 years after transaction | Legal obligation (tax law) |
| Marketing consents | Until withdrawn + 30 days | Consent |
| Support tickets | 3 years after resolution | Legitimate interest |
| Analytics data (anonymized) | Indefinitely | Legitimate interest |
| Deleted account backups | 30 days maximum | Technical necessity |
Supervisory Authority
If you're unhappy with how we handle your data, you have the right to lodge a complaint with a supervisory authority:
Estonia (Our Lead Supervisory Authority)
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Website: www.aki.ee
Email: info@aki.ee
Address: Tatari 39, 10134 Tallinn, Estonia
Your Local Authority
You can also contact the data protection authority in your country of residence. Find your local authority at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Special Categories of Personal Data
Your stories may contain "special category" data under GDPR Article 9:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Health information
- Sexual orientation
- Biometric data
Processing Basis: We process this data with your explicit consent and only to create your book. You can withdraw consent at any time by emailing hello@ethosbook.co.
Extra Protections:
- Encrypted storage and transmission
- Access restricted to essential personnel
- Never used for profiling or automated decisions
- Never shared with third parties except processors under strict contracts
Data Protection by Design and Default
We implement privacy-protective measures throughout our service:
- Encryption: All data encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access controls: Role-based access with least privilege principle
- Pseudonymization: Internal systems use IDs instead of names where possible
- Data minimization: We only collect data necessary for our service
- Regular audits: Quarterly security and privacy reviews
- Staff training: All employees trained on GDPR compliance
Data Breach Notification
If we experience a personal data breach that risks your rights and freedoms:
- To you: We'll notify you within 72 hours if high risk
- To supervisory authority: We'll notify Estonian DPA within 72 hours
- Information provided: Nature of breach, likely consequences, measures taken
Changes to This Notice
We may update this GDPR Privacy Notice to reflect changes in:
- Our data processing practices
- GDPR requirements or guidance
- Supervisory authority recommendations
When we make significant changes:
- We'll email you 30 days in advance
- We'll post the updated notice on our website
- We'll update the "Effective Date" at the top
Contact Our Data Protection Officer
For GDPR-specific questions or to exercise your rights:
Email: hello@ethosbook.co
Mail:
Data Protection Officer
Ethos OÜ
Kursi tn 3, 10415 Tallinn, Estonia
Response time: 7 business days for initial response, 30 days for full resolution
We respect your GDPR rights and are committed to protecting your personal data with the highest European privacy standards.