This Privacy Policy explains how Subflare OÜ ("Subflare," "we," "our," or "us") processes personal data when you visit our website (subflare.ai), communicate with us, or use our services. Subflare provides a behavioral intelligence platform that delivers analytics, intent scoring, and revenue prediction tools for B2B sales teams. We process personal data in accordance with the European Union General Data Protection Regulation (EU 2016/679) ("GDPR") and applicable Estonian data protection legislation.
Because Subflare's product involves analyzing behavior at the level of individual website visitors and business contacts, we've tried to be specific below about what we track, where data comes from, and what our scoring tools actually do: rather than describing this in generic terms.
The data controller responsible for your personal data is:
Subflare OÜ, Sepapaja 6, Lasnamäe, 15551 Tallinn, Harju County, Estonia
Email: privacy@subflare.ai
Subflare is currently assessing whether it is required to appoint a Data Protection Officer under Article 37 of the GDPR, and if so, who can hold that role independently of our operational decision-making. Until that assessment is complete, privacy inquiries should be directed to privacy@subflare.ai, which is monitored by our team.
Information you provide directly:
Information collected automatically:
Information from third parties:
We use Apollo.io, a third-party business contact database, to enrich our own lead and prospect records with publicly available business contact information (such as name, business email, job title, employer, and professional profile details). Where we obtain personal data this way rather than directly from you, Article 14 of the GDPR requires us to disclose the source and our purpose for using it: we do so here rather than only in a general reference to "third-party databases." Apollo describes its own role and legal bases for this data in its privacy policy. We do not submit or upload our own contact and lead records into Apollo's database; our use is limited to searching and enriching records we already hold.
We do not intentionally collect special categories of personal data (e.g., health data, racial or ethnic origin, political opinions, or biometric data). If we become aware that such data has been collected inadvertently, we will promptly delete it.
We process personal data for the following purposes, each in accordance with Article 6(1) of the GDPR:
A note on the distinction above: having a valid GDPR legal basis for processing personal data is not the same as being permitted to send a given communication. Direct marketing by email is additionally governed by ePrivacy rules, which impose their own conditions (for example, around unsolicited commercial email) separate from GDPR. Legitimate interest as a GDPR basis for B2B outreach does not by itself authorize every form of marketing contact: we apply ePrivacy requirements on top of the legal bases listed here, and where consent is the basis for a communication (such as our newsletter), that consent is specific, informed, and freely given, with an easy way to withdraw it at any time by unsubscribing or contacting us.
Where we rely on legitimate interest, we conduct balancing assessments to ensure that our interests do not override your fundamental rights and freedoms. You may request further information about these assessments by contacting us at privacy@subflare.ai.
We do not sell, rent, or trade your personal data to any third party. We share personal data with the vendors below, solely for the purposes described in this policy. Most of these vendors act as our processors, meaning they handle data only on our instructions and for our purposes. A few also process certain data for their own purposes in specific circumstances: where that applies, we've noted it rather than describing every vendor as a pure processor by default.
The current list of sub-processors, including their location and data transfer mechanism, is maintained at subflare.ai/legal/sub-processors and updated on an ongoing basis. Where a vendor acts as our processor, they are bound by a GDPR-compliant data processing agreement (DPA) requiring them to process personal data only on our documented instructions and to implement appropriate technical and organizational security measures. We may also disclose personal data where required by law, court order, or regulatory authority.
Personal data is processed both within the European Economic Area (EEA) and, through several of our sub-processors, in the United States. Where data is transferred outside the EEA to a country that has not received an adequacy decision from the European Commission, we ensure appropriate safeguards are in place, including:
The transfer mechanism used for each sub-processor is listed at subflare.ai/legal/sub-processors. You may also request a copy of the safeguards applied to international transfers by contacting us at privacy@subflare.ai.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law. Our current retention practice, by category:
When personal data is no longer needed, it is securely deleted or irreversibly anonymized. We are in the process of defining more precise, numerically specific retention periods for each category above as part of ongoing data governance work, and will update this section as that work is finalized.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:
While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee absolute security but are committed to promptly addressing any data breach in accordance with GDPR requirements.
Our website uses cookies and similar technologies, managed through our consent platform (CookieYes), to provide functionality, analyze usage, and improve your experience. CookieYes blocks non-essential cookies from loading until you provide consent through our cookie banner.
Types of cookies we use:
A detailed, current list of the specific cookies we use: including each cookie's name, provider, purpose, and duration: is published in our Cookie Policy. You can manage or withdraw cookie consent at any time through our cookie banner or your browser settings. Disabling certain cookies may affect the functionality of our website. For questions, contact us at privacy@subflare.ai.
Under the GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us at privacy@subflare.ai. We will respond without undue delay and, in any event, within one month of receiving your request, subject to extension in certain circumstances as permitted under the GDPR.
Our platform performs behavioral analytics and intent scoring, which involves profiling, analyzing individual website visitor behavior and business contact data to generate scores and predictions (for example, indicators of a contact's likely purchase intent). We want to be precise about what this does and does not involve, rather than describing it only at a general level.
We do not use fully automated decision-making that produces legal effects or similarly significant effects on individuals within the meaning of Article 22 of the GDPR. The scores and predictions our platform generates are decision-support signals for our customers' sales teams; a human at the customer organization reviews and acts on them; the scoring itself does not automatically grant or deny someone access to anything, determine pricing, or take an equivalent significant action without human involvement.
That said, profiling under GDPR is broader than Article 22, and applies here: the platform does analyze data tied to identifiable individuals, not only aggregated company-level statistics. Our scoring outputs may reference individual contacts, an organization as a whole, or both, depending on the specific feature. We are finalizing more detailed technical documentation of these mechanics, which will be reflected here as it becomes available.
You have the right to object to profiling carried out on the basis of legitimate interest, including for direct marketing purposes, as described in Section 10.
We may also use anonymized and aggregated data, including data collected through the platform, to train, validate, and improve our AI/ML models. This is described in more detail in our Terms of Service (Section 6.3), which also explains how to opt out.
Our services are designed for business use and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete such data promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via email or a notice on our website. We encourage you to review this policy periodically to stay informed about how we protect your data.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Email: privacy@subflare.ai
Website: www.subflare.ai
Address: Sepapaja 6, Lasnamäe, 15551 Tallinn, Harju County, Estonia