Privacy Policy | Subflare

Privacy Policy

Effective Date: January 1, 2026
Last Updated: August 27, 2026
Company: Subflare OÜ, Registry Code: 17370853
Registered Address: Sepapaja 6, Lasnamäe, 15551 Tallinn, Harju County, Estonia (EU)

1. Introduction

This Privacy Policy explains how Subflare OÜ ("Subflare," "we," "our," or "us") processes personal data when you visit our website (subflare.ai), communicate with us, or use our services. Subflare provides a behavioral intelligence platform that delivers analytics, intent scoring, and revenue prediction tools for B2B sales teams. We process personal data in accordance with the European Union General Data Protection Regulation (EU 2016/679) ("GDPR") and applicable Estonian data protection legislation.

Because Subflare's product involves analyzing behavior at the level of individual website visitors and business contacts, we've tried to be specific below about what we track, where data comes from, and what our scoring tools actually do: rather than describing this in generic terms.

2. Data Controller

The data controller responsible for your personal data is:
Subflare OÜ, Sepapaja 6, Lasnamäe, 15551 Tallinn, Harju County, Estonia
Email: privacy@subflare.ai

Subflare is currently assessing whether it is required to appoint a Data Protection Officer under Article 37 of the GDPR, and if so, who can hold that role independently of our operational decision-making. Until that assessment is complete, privacy inquiries should be directed to privacy@subflare.ai, which is monitored by our team.

3. Personal Data We Collect

Information you provide directly:

  • Contact details: name, email address, phone number, company name, and job title
  • Communications: messages, demo requests, support inquiries, and feedback
  • Account information: login credentials and account preferences
  • Billing information: invoicing details and payment records
  • Any other information you voluntarily submit through forms on our website

Information collected automatically:

  • Website usage data: pages visited, session duration, click behavior, referral sources, and interaction patterns
  • Device and technical data: IP address, browser type and version, operating system, screen resolution, and language preferences
  • Cookies and similar tracking technologies (see Section 9 below)

Information from third parties:

We use Apollo.io, a third-party business contact database, to enrich our own lead and prospect records with publicly available business contact information (such as name, business email, job title, employer, and professional profile details). Where we obtain personal data this way rather than directly from you, Article 14 of the GDPR requires us to disclose the source and our purpose for using it: we do so here rather than only in a general reference to "third-party databases." Apollo describes its own role and legal bases for this data in its privacy policy. We do not submit or upload our own contact and lead records into Apollo's database; our use is limited to searching and enriching records we already hold.

4. Purposes and Legal Bases for Processing

We do not intentionally collect special categories of personal data (e.g., health data, racial or ethnic origin, political opinions, or biometric data). If we become aware that such data has been collected inadvertently, we will promptly delete it.

We process personal data for the following purposes, each in accordance with Article 6(1) of the GDPR:

  • Providing and operating our platform and services: Performance of a contract (Art. 6(1)(b))
  • Responding to inquiries, demo requests, and support tickets: Legitimate interest and pre-contractual measures (Art. 6(1)(f) and 6(1)(b))
  • Managing customer accounts and billing: Performance of a contract (Art. 6(1)(b))
  • Sending newsletters and opted-in marketing content to subscribers: Consent (Art. 6(1)(a))
  • Sending product updates to existing customers about the service they use: Performance of a contract or legitimate interest (Art. 6(1)(b)/(f)), consistent with applicable ePrivacy rules for service communications
  • Analyzing website usage to improve our services: Legitimate interest (Art. 6(1)(f))
  • Ensuring the security and integrity of our platform: Legitimate interest (Art. 6(1)(f))
  • Complying with legal and regulatory obligations: Legal obligation (Art. 6(1)(c))
  • Conducting B2B sales and business development outreach (cold prospecting): Legitimate interest (Art. 6(1)(f))

A note on the distinction above: having a valid GDPR legal basis for processing personal data is not the same as being permitted to send a given communication. Direct marketing by email is additionally governed by ePrivacy rules, which impose their own conditions (for example, around unsolicited commercial email) separate from GDPR. Legitimate interest as a GDPR basis for B2B outreach does not by itself authorize every form of marketing contact: we apply ePrivacy requirements on top of the legal bases listed here, and where consent is the basis for a communication (such as our newsletter), that consent is specific, informed, and freely given, with an easy way to withdraw it at any time by unsubscribing or contacting us.

Where we rely on legitimate interest, we conduct balancing assessments to ensure that our interests do not override your fundamental rights and freedoms. You may request further information about these assessments by contacting us at privacy@subflare.ai.

5. Data Sharing and Third-Party Processors

We do not sell, rent, or trade your personal data to any third party. We share personal data with the vendors below, solely for the purposes described in this policy. Most of these vendors act as our processors, meaning they handle data only on our instructions and for our purposes. A few also process certain data for their own purposes in specific circumstances: where that applies, we've noted it rather than describing every vendor as a pure processor by default.

  • Cloud infrastructure: Amazon Web Services (AWS), for hosting and data storage. Processor.
  • Website platform: Webflow, for hosting and managing our website. Processor.
  • Customer relationship management (CRM): Close, for managing sales communications and customer interactions. Processor.
  • Lead enrichment and prospecting: Apollo.io, for enriching lead and contact data. We only search and pull enrichment data from Apollo; we do not submit our own records to it. Apollo acts as our processor for this use, though it separately maintains its own business contact database for its own purposes, as described in Section 3.
  • Workflow automation: Zapier, for connecting data between our email platform, dashboard, and CRM. Processor.
  • Analytics: Google Analytics (GA4), for website performance analysis and usage insights. Google acts as our processor for this data, though Google also independently determines certain processing purposes as described in its own privacy policy.
  • Payment processing: Stripe, for billing and invoicing. Stripe acts as our processor for payment data, and separately as an independent controller for its own regulatory and fraud-prevention obligations.
  • Email delivery: Brevo, for transactional and marketing communications. Processor.
  • Internal notifications: Slack, for lead alerts and internal workflow notifications. Processor.
  • Professional advisors: such as legal, accounting, or auditing services, where required.

The current list of sub-processors, including their location and data transfer mechanism, is maintained at subflare.ai/legal/sub-processors and updated on an ongoing basis. Where a vendor acts as our processor, they are bound by a GDPR-compliant data processing agreement (DPA) requiring them to process personal data only on our documented instructions and to implement appropriate technical and organizational security measures. We may also disclose personal data where required by law, court order, or regulatory authority.

6. International Data Transfers

Personal data is processed both within the European Economic Area (EEA) and, through several of our sub-processors, in the United States. Where data is transferred outside the EEA to a country that has not received an adequacy decision from the European Commission, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The EU-U.S. Data Privacy Framework, where the recipient is a certified participant
  • Other legally recognized transfer mechanisms under Chapter V of the GDPR

The transfer mechanism used for each sub-processor is listed at subflare.ai/legal/sub-processors. You may also request a copy of the safeguards applied to international transfers by contacting us at privacy@subflare.ai.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law. Our current retention practice, by category:

  • Account and customer relationship data: retained for the duration of the contractual relationship, plus a limited period thereafter for legal, accounting, and legitimate business purposes
  • Billing and accounting records: retained for the period required by applicable Estonian tax and accounting law
  • Sales prospect and lead data (including data enriched via Apollo.io): retained for as long as reasonably relevant to ongoing or prospective business engagement, with inactive records periodically reviewed for deletion
  • Marketing consent records: retained until consent is withdrawn or the subscription is cancelled, plus a minimal period to evidence the consent itself
  • Support and communication records: retained for a period reasonably tied to the support relationship and any follow-up needs
  • Website usage and analytics data: retained in anonymized or aggregated form for up to 26 months

When personal data is no longer needed, it is securely deleted or irreversibly anonymized. We are in the process of defining more precise, numerically specific retention periods for each category above as part of ongoing data governance work, and will update this section as that work is finalized.

8. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Access controls and role-based permissions
  • Regular security assessments and monitoring
  • Secure development practices
  • Employee confidentiality obligations

While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee absolute security but are committed to promptly addressing any data breach in accordance with GDPR requirements.

9. Cookies and Tracking Technologies

Our website uses cookies and similar technologies, managed through our consent platform (CookieYes), to provide functionality, analyze usage, and improve your experience. CookieYes blocks non-essential cookies from loading until you provide consent through our cookie banner.

Types of cookies we use:

  • Strictly necessary cookies: required for the website to function properly (no consent required)
  • Analytics cookies: including Google Analytics (GA4), to help us understand how visitors interact with our website
  • Functional cookies: remember your preferences and enhance your experience

A detailed, current list of the specific cookies we use: including each cookie's name, provider, purpose, and duration: is published in our Cookie Policy. You can manage or withdraw cookie consent at any time through our cookie banner or your browser settings. Disabling certain cookies may affect the functionality of our website. For questions, contact us at privacy@subflare.ai.

10. Your Rights Under the GDPR

Under the GDPR, you have the following rights regarding your personal data:

Access(Art. 15): obtain confirmation of whether we process your data and request a copy
Rectification(Art. 16): request correction of inaccurate or incomplete data
Erasure(Art. 17): request deletion of your personal data where applicable
Restriction(Art. 18): request that we limit how we process your data
Portability(Art. 20): receive your data in a structured, machine-readable format
Object(Art. 21): object to processing based on legitimate interest or direct marketing
Withdraw consent(Art. 7(3)): withdraw consent at any time where processing is based on consent
Complaint: file a complaint with the Estonian Data Protection Inspectorate or your local supervisory authority

To exercise any of these rights, please contact us at privacy@subflare.ai. We will respond without undue delay and, in any event, within one month of receiving your request, subject to extension in certain circumstances as permitted under the GDPR.

11. Profiling and Automated Decision-Making

Our platform performs behavioral analytics and intent scoring, which involves profiling, analyzing individual website visitor behavior and business contact data to generate scores and predictions (for example, indicators of a contact's likely purchase intent). We want to be precise about what this does and does not involve, rather than describing it only at a general level.

We do not use fully automated decision-making that produces legal effects or similarly significant effects on individuals within the meaning of Article 22 of the GDPR. The scores and predictions our platform generates are decision-support signals for our customers' sales teams; a human at the customer organization reviews and acts on them; the scoring itself does not automatically grant or deny someone access to anything, determine pricing, or take an equivalent significant action without human involvement.

That said, profiling under GDPR is broader than Article 22, and applies here: the platform does analyze data tied to identifiable individuals, not only aggregated company-level statistics. Our scoring outputs may reference individual contacts, an organization as a whole, or both, depending on the specific feature. We are finalizing more detailed technical documentation of these mechanics, which will be reflected here as it becomes available.

You have the right to object to profiling carried out on the basis of legitimate interest, including for direct marketing purposes, as described in Section 10.

We may also use anonymized and aggregated data, including data collected through the platform, to train, validate, and improve our AI/ML models. This is described in more detail in our Terms of Service (Section 6.3), which also explains how to opt out.

12. Children's Privacy

Our services are designed for business use and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete such data promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via email or a notice on our website. We encourage you to review this policy periodically to stay informed about how we protect your data.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Email: privacy@subflare.ai
Website: www.subflare.ai
Address: Sepapaja 6, Lasnamäe, 15551 Tallinn, Harju County, Estonia