Effective Date:
January 1, 2026
Last Updated:
February 20, 2026
Company: Subflare OÜ, Registry Code: 17370853
Registered Address:
Sepapaja 6,
Lasnamäe,
15551 Tallinn,
Harju County,
Estonia (EU)
1. Introduction
Subflare OÜ ("Subflare," "we," "our," or "us") is committed to protecting and respecting your privacy. This Privacy Policy describes how we collect, use, store, share, and protect personal data when you visit our website (subflare.ai), communicate with us, or use our services.Subflare provides a behavioral intelligence platform that delivers analytics, intent scoring, and revenue prediction tools for B2B sales teams. We process all personal data in accordance with the European Union General Data Protection Regulation (EU 2016/679) ("GDPR") and applicable Estonian data protection legislation.By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our website and services.
2. Data Controller
The data controller responsible for your personal data is:
Subflare OÜ Sepapaja 6, Lasnamäe 15551 Tallinn, Harju County Estonia
Email: privacy@subflare.ai
3. Personal Data We Collect
We collect and process the following categories of personal data:
Information you provide directly:
- Contact details: name, email address, phone number, company name, and job title
- Communications: messages, demo requests, support inquiries, and feedback
- Account information: login credentials and account preferences
- Billing information: invoicing details and payment records
- Any other information you voluntarily submit through forms on our website
Information collected automatically:
- Website usage data: pages visited, session duration, click behavior, referral sources, and interaction patterns
- Device and technical data: IP address, browser type and version, operating system, screen resolution, and language preferences
- Cookies and similar tracking technologies (see Section 9 below)
Information from third parties:
Publicly available business information from professional networks or company databases used for B2B sales and outreach purposes
4. Purposes and Legal Bases for Processing
We do not intentionally collect special categories of personal data (e.g., health data, racial or ethnic origin, political opinions, or biometric data). If we become aware that such data has been collected inadvertently, we will promptly delete it.
We process personal data for the following purposes, each in accordance with Article 6(1) of the GDPR:
- Providing and operating our platform and services. Legal basis: Performance of a contract (Art. 6(1)(b)).
- Responding to inquiries, demo requests, and support tickets. Legal basis: Legitimate interest and pre-contractual measures (Art. 6(1)(f) and Art. 6(1)(b)).
- Managing customer accounts and billing. Legal basis: Performance of a contract (Art. 6(1)(b)).
- Sending marketing communications and product updates. Legal basis: Consent (Art. 6(1)(a)).
- Analyzing website usage to improve our services. Legal basis: Legitimate interest (Art. 6(1)(f)).
- Ensuring the security and integrity of our platform. Legal basis: Legitimate interest (Art. 6(1)(f)).
- Complying with legal and regulatory obligation. Legal basis: Legal obligation (Art. 6(1)(c)).
- Conducting B2B sales and business development outreach. Legal basis: Legitimate interest (Art. 6(1)(f)).
Where we rely on legitimate interest, we conduct balancing assessments to ensure that our interests do not override your fundamental rights and freedoms. You may request further information about these assessments by contacting us at privacy@subflare.ai
5. Data Sharing and Third-Party Processors
We do not sell, rent, or trade your personal data to any third party.We may share personal data with the following categories of recipients, solely for the purposes described in this policy:
- Cloud infrastructure providers — for hosting and data storage
- Customer relationship management (CRM) platforms — for managing sales communications and customer interactions
- Analytics tools — for website performance analysis and usage insights
- Payment processors — for processing billing and invoicing
- Email service providers — for transactional and marketing communications
- Professional advisors — such as legal, accounting, or auditing services, where requiredAll third-party processors are bound by GDPR-compliant data processing agreements (DPAs) that require them to process personal data only on our documented instructions and to implement appropriate technical and organizational security measures.We may also disclose personal data where required by law, court order, or regulatory authority.
6. International Data Transfers
Your personal data is primarily stored and processed within the European Economic Area (EEA).Where data is transferred to countries outside the EEA that have not received an adequacy decision from the European Commission, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-U.S. Data Privacy Framework, where applicable
- Other legally recognized transfer mechanisms under Chapter V of the GDPR
You may request a copy of the safeguards applied to international transfers by contacting us at at privacy@subflare.ai.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law.General retention guidelines:
- Customer account data: retained for the duration of the contractual relationship and up to 7 years thereafter for legal and accounting purposes
- Marketing and communication data: retained until you withdraw consent or unsubscribe
- Website usage and analytics data: retained in anonymized or aggregated form for up to 26 months
- Billing records: retained for the period required by applicable tax and accounting regulationsWhen personal data is no longer needed, it is securely deleted or irreversibly anonymized.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to:Encryption of data in transit (TLS/SSL) and at restAccess controls and role-based permissionsRegular security assessments and monitoringSecure development practicesEmployee confidentiality obligationsWhile we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee absolute security but are committed to promptly addressing any data breach in accordance with GDPR requirements.
9. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to provide functionality, analyze usage, and improve your experience.
Types of cookies we use:- Strictly necessary cookies — required for the website to function properly (no consent required)
- Analytics cookies — help us understand how visitors interact with our website
- Functional cookies — remember your preferences and enhance your experienceYou can manage or disable cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of our website.For detailed information about the cookies we use, please refer to our Cookie Banner or contact us at privacy@subflare.ai
10. Your Rights Under the GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — obtain confirmation of whether we process your data and request a copy
- Right to rectification (Art. 16) — request correction of inaccurate or incomplete data
- Right to erasure (Art. 17) — request deletion of your personal data where applicable
- Right to restriction of processing (Art. 18) — request that we limit how we process your data
- Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest or for direct marketing purposes
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time where processing is based on consent
- Right to lodge a complaint — file a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority
To exercise any of these rights, please contact us at privacy@subflare.ai. We will respond to your request within 30 days, in accordance with GDPR timelines.
11. Automated Decision-Making
We do not engage in fully automated decision-making or profiling that produces legal effects or similarly significant effects on individuals, as defined under Article 22 of the GDPR.Our behavioral analytics and intent scoring tools analyze aggregated business data to provide insights to our B2B clients. These tools do not make automated decisions about individual consumers.
12. Children's Privacy
Our services are designed for business use and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete such data promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via email or a notice on our website.We encourage you to review this policy periodically to stay informed about how we protect your data.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Email: privacy@subflare.ai
Website: https://www.subflare.ai
Address:
Sepapaja 6
Lasnamäe 15551
Tallinn, Harju County
Estonia