This notice explains what we do with your personal data. It is written to be read, not to be survived. If anything here is unclear, email admin@zaivo.ai and we will explain it in plain terms.
Who we are
Zaivo Consulting OÜ is an Estonian private limited company, registry code 17582710, registered at Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia. We are the controller of the personal data described below — meaning we decide why and how it is used, and we are the ones you hold responsible for it.
Contact for anything privacy-related: admin@zaivo.ai.
We have not appointed a Data Protection Officer. We are not required to.
Because ZAIVO is established in Estonia and sells across the EU, we have not appointed an Article 27 representative — none is required for an EU-established controller.
What we sell, so the rest makes sense
We sell one thing: a Productivity Audit. You book a 60-minute call. We record it. Within 48 hours we send you a report — a PDF slide deck and a written summary. Then you get a free 30-minute follow-up call. Everything below flows from that.
What we collect, and where it comes from
| What | Where it comes from | Do we need it? |
|---|---|---|
| Name, work email, company name, role | You, via the booking form and Calendly | Yes — we cannot deliver without it |
| Phone number, time zone | You, via the booking form (optional fields) | Optional |
| What you tell us before the call — your goals, current tools, pain points | You, via the booking form and any emails | Yes — this is the brief |
| Audio and video of the audit call | Recorded by us during the call, with your consent | Yes, if you consent to recording |
| A transcript of the call | Generated automatically from the recording | Yes, if you consent to recording |
| The report we produce for you | Created by us from your brief and the transcript | Yes — it is the deliverable |
| Billing data: registered company name, address, VAT number, payment status, invoice records | You, via the booking form; held in our invoicing system | Yes — legally required |
| Bank details | Only what appears on the transfer you send us. We never ask for, see or store card numbers. | Not by us |
| Emails and calendar invitations between us | You and us | Yes |
| Basic server logs from the website (IP address, request time, page requested, user agent) | Automatically, by our host | Yes — technical necessity |
We do not buy personal data from data brokers. We do not scrape it. Everything we hold about you, you gave us or generated by working with us.
We ask you not to send us special category data (health, religion, political opinions, trade union membership, biometrics) or anyone's data that you are not entitled to share. If it comes up in the call, we will not use it in the report.
Why we use it, and our legal basis
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Schedule and hold the audit call | To deliver what you paid for | Contract — Art. 6(1)(b) |
| Record the call and transcribe it | So we can produce an accurate report without taking notes at you for an hour | Your explicit consent — Art. 6(1)(a) |
| Produce and deliver the report | To deliver what you paid for | Contract — Art. 6(1)(b) |
| Hold the free follow-up call | To deliver what you paid for | Contract — Art. 6(1)(b) |
| Take payment, issue invoices | To deliver what you paid for; to comply with tax law | Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c) |
| Keep accounting and tax records | Estonian law requires it | Legal obligation — Art. 6(1)(c) |
| Answer your emails | To respond to you | Contract — Art. 6(1)(b), or legitimate interests — Art. 6(1)(f) |
| Keep the website running and secure | To have a website that works | Legitimate interests — Art. 6(1)(f) |
| Handle a refund request or a dispute | To honour our guarantee and defend legal claims | Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Send you marketing emails | Only if you asked for them | Your consent — Art. 6(1)(a) |
About the recording, specifically
We ask for your consent to record before the call starts, and again at the start of the call itself. You can say no.
If you say no, you still get the audit. We take written notes instead. The report may take slightly longer and will be less detailed on direct quotes, but the service is not withdrawn and the refund guarantee still applies in full.
You can withdraw consent to the recording at any time — during the call, or afterwards by emailing admin@zaivo.ai. If you withdraw it, we delete the audio and the transcript. Withdrawal does not affect the lawfulness of what we did before you withdrew, and it does not undo a report that has already been delivered to you.
Other participants on your side of the call are told about the recording before it starts. If you invite colleagues, please tell them the call is recorded before they join.
Who else touches your data
We use a small number of service providers ("processors"). Each one is bound by a data processing agreement. Each is listed here.
| Processor | What it does | Where | Transfer mechanism |
|---|---|---|---|
| Fathom | Records and transcribes the audit call | United States | Standard Contractual Clauses |
| Anthropic (Claude) | Helps generate your report from the transcript and brief | United States | Standard Contractual Clauses |
| Google Workspace | Email, calendar, file storage | EU and United States | Standard Contractual Clauses / EU-U.S. Data Privacy Framework EU–US Data Privacy Framework, with Standard Contractual Clauses as a fallback |
| Calendly | Scheduling and booking form | United States | Standard Contractual Clauses |
| Enty | Invoicing and accounting | European Union | Within the EU — no transfer |
| Revolut Bank UAB | Receiving payment | European Union | Within the EU — no transfer |
| Netlify | Website hosting | United States | Standard Contractual Clauses |
We may also share data with our accountant and, if it ever becomes necessary, with lawyers, auditors or a court. We will share with a public authority only where the law requires it.
Three things we never do
- We never sell your data. Not to anyone, for any price.
- We never share one client's data with another client. Your report is yours. Your business information does not appear in anyone else's report, and it does not go into a public case study without your written permission.
- We never use your data to train AI models. Our processors are contractually barred from training on it too.
Transfers outside the EEA
Some of our processors are in the United States. Where that is the case, the transfer relies on the European Commission's Standard Contractual Clauses, supplemented where relevant by an adequacy decision or the EU-U.S. Data Privacy Framework, together with technical measures such as encryption in transit and at rest.
You can ask us for a copy of the transfer safeguards we rely on for any specific processor. Email admin@zaivo.ai and we will send them.
How long we keep things
| Data | Kept for | Counted from |
|---|---|---|
| Call audio / video recording | 90 days | Delivery of your report |
| Call transcript | 12 months | Delivery of your report |
| Your brief and your report | 7 years | Delivery of your report |
| Contact details and billing records | 7 years | End of the financial year the invoice falls in |
| Booking form data (where no call took place) | 12 months | Date of the booking |
| Website server logs | 30 days | Date of the request |
| Marketing consent records | Until you unsubscribe, plus 24 months from your last contact with us, or until you unsubscribe | Withdrawal of consent |
The 7-year periods are set by Estonian accounting and commercial law, and by the length of time in which a legal claim could still be brought. We keep the report itself for that period so that we can honour a refund, resolve a dispute, or send you a replacement copy if you lose yours.
If you withdraw recording consent, the audio and transcript are deleted sooner — see above.
When a retention period ends, we delete the data or irreversibly anonymise it.
Your rights
Under the GDPR you have the right to:
- Know what we hold about you and why (Art. 15) — and get a copy of it.
- Correct anything inaccurate (Art. 16).
- Delete it (Art. 17) — where we do not have a legal reason to keep it, such as tax records.
- Restrict what we do with it (Art. 18) — for example while a dispute about accuracy is resolved.
- Take it with you in a portable, machine-readable format (Art. 20).
- Object to processing based on our legitimate interests (Art. 21).
- Withdraw consent at any time, for the recording or for marketing (Art. 7(3)), without affecting what was lawful before.
- Not be subject to a solely automated decision with legal or similarly significant effects (Art. 22). We do not make any such decisions. A human being writes and signs off every report.
How to use them
Email admin@zaivo.ai. Say what you want. That is the whole process.
There is no form. We will not charge you. We may ask you to confirm your identity if the request comes from an address we do not recognise, because we are not going to hand your data to someone pretending to be you.
We respond within 30 days. If a request is genuinely complex we may extend that by up to two further months, and if we do, we will tell you within the first 30 days and explain why.
If we get it wrong
You can complain to a supervisory authority. Because we are established in Estonia, our lead authority is:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) Tatari 39, 10134 Tallinn, Estonia info@aki.ee — www.aki.ee
You can also complain to the data protection authority in the EU country where you live or work, or where you think the problem happened. A list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
We would rather you told us first — admin@zaivo.ai — but you are not required to.
Cookies and analytics
Plainly:
- This website sets no analytics cookies.
- This website sets no advertising or tracking cookies.
- We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, or any similar tracker.
- We do not build advertising profiles and we do not share website visitor data with ad networks.
What does happen: our host, Netlify, keeps standard server logs (IP address, timestamp, page requested, browser user agent) for security and to keep the site up. That is a technical necessity, not tracking.
When you open the booking page, Calendly loads and sets its own cookies to make scheduling work. Those are Calendly's cookies, governed by its notice:
- Calendly: https://calendly.com/privacy
We do not take card payments on this site, so no payment provider loads here and none sets a cookie.
Because we set no non-essential cookies of our own, there is no cookie banner. If that ever changes, we will ask for your consent first, properly, with a real reject button.
How we use AI — and what that means for you
We are direct about this because you should not have to guess.
How your report is made. After the call, the recording is transcribed by Fathom. The transcript and your brief are then processed using Anthropic's Claude to help draft and structure the report. AI does the first pass on structure, synthesis and drafting.
A human reviews every report before it reaches you. A named person at ZAIVO — currently Eddie Eliakim, founder — reads, checks, edits and approves every report. They are named in the report itself, so you know who to argue with. No report is sent to you unread by a human.
No automated decisions about you. Nothing in this process makes an automated decision that has legal or similarly significant effects on you or your business. Every recommendation is a human-approved recommendation.
Your data is not used to train models. Not by us, and not by Anthropic or Fathom — that is written into our agreements with them.
AI can be wrong. Every recommendation in your report is a starting point for your judgement, not a substitute for it. Check anything that matters before you act on it, especially numbers, pricing and vendor claims.
The EU AI Act flag
Some of the tools we may recommend are AI systems. If you deploy one, the EU AI Act may place obligations on you as the deployer — things like informing your staff, human oversight, transparency to the people affected, or record-keeping. Those obligations depend on the tool and how you use it.
Where we recommend a tool that would carry EU AI Act deployer obligations for you, we flag it in the report — clearly, next to the recommendation, not in a footnote.
That flag tells you an obligation may exist and roughly what kind. It is not a legal opinion and it is not a compliance assessment. Before you deploy a flagged tool, take advice suited to your business.
Changes to this notice
If we change this notice we update the date at the top. If the change is significant — a new processor, a new purpose, a longer retention period — we email active and recent clients before it takes effect.
Old versions are available on request.