Your data

Privacy Notice

Last updated 1 September 2026

This notice explains what we do with your personal data. It is written to be read, not to be survived. If anything here is unclear, email admin@zaivo.ai and we will explain it in plain terms.

Who we are

Zaivo Consulting OÜ is an Estonian private limited company, registry code 17582710, registered at Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia. We are the controller of the personal data described below — meaning we decide why and how it is used, and we are the ones you hold responsible for it.

Contact for anything privacy-related: admin@zaivo.ai.

We have not appointed a Data Protection Officer. We are not required to.

Because ZAIVO is established in Estonia and sells across the EU, we have not appointed an Article 27 representative — none is required for an EU-established controller.

What we sell, so the rest makes sense

We sell one thing: a Productivity Audit. You book a 60-minute call. We record it. Within 48 hours we send you a report — a PDF slide deck and a written summary. Then you get a free 30-minute follow-up call. Everything below flows from that.

What we collect, and where it comes from

What Where it comes from Do we need it?
Name, work email, company name, role You, via the booking form and Calendly Yes — we cannot deliver without it
Phone number, time zone You, via the booking form (optional fields) Optional
What you tell us before the call — your goals, current tools, pain points You, via the booking form and any emails Yes — this is the brief
Audio and video of the audit call Recorded by us during the call, with your consent Yes, if you consent to recording
A transcript of the call Generated automatically from the recording Yes, if you consent to recording
The report we produce for you Created by us from your brief and the transcript Yes — it is the deliverable
Billing data: registered company name, address, VAT number, payment status, invoice records You, via the booking form; held in our invoicing system Yes — legally required
Bank details Only what appears on the transfer you send us. We never ask for, see or store card numbers. Not by us
Emails and calendar invitations between us You and us Yes
Basic server logs from the website (IP address, request time, page requested, user agent) Automatically, by our host Yes — technical necessity

We do not buy personal data from data brokers. We do not scrape it. Everything we hold about you, you gave us or generated by working with us.

We ask you not to send us special category data (health, religion, political opinions, trade union membership, biometrics) or anyone's data that you are not entitled to share. If it comes up in the call, we will not use it in the report.

Why we use it, and our legal basis

What we do Why Legal basis (GDPR)
Schedule and hold the audit call To deliver what you paid for Contract — Art. 6(1)(b)
Record the call and transcribe it So we can produce an accurate report without taking notes at you for an hour Your explicit consent — Art. 6(1)(a)
Produce and deliver the report To deliver what you paid for Contract — Art. 6(1)(b)
Hold the free follow-up call To deliver what you paid for Contract — Art. 6(1)(b)
Take payment, issue invoices To deliver what you paid for; to comply with tax law Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c)
Keep accounting and tax records Estonian law requires it Legal obligation — Art. 6(1)(c)
Answer your emails To respond to you Contract — Art. 6(1)(b), or legitimate interests — Art. 6(1)(f)
Keep the website running and secure To have a website that works Legitimate interests — Art. 6(1)(f)
Handle a refund request or a dispute To honour our guarantee and defend legal claims Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f)
Send you marketing emails Only if you asked for them Your consent — Art. 6(1)(a)

About the recording, specifically

We ask for your consent to record before the call starts, and again at the start of the call itself. You can say no.

If you say no, you still get the audit. We take written notes instead. The report may take slightly longer and will be less detailed on direct quotes, but the service is not withdrawn and the refund guarantee still applies in full.

You can withdraw consent to the recording at any time — during the call, or afterwards by emailing admin@zaivo.ai. If you withdraw it, we delete the audio and the transcript. Withdrawal does not affect the lawfulness of what we did before you withdrew, and it does not undo a report that has already been delivered to you.

Other participants on your side of the call are told about the recording before it starts. If you invite colleagues, please tell them the call is recorded before they join.

Who else touches your data

We use a small number of service providers ("processors"). Each one is bound by a data processing agreement. Each is listed here.

Processor What it does Where Transfer mechanism
Fathom Records and transcribes the audit call United States Standard Contractual Clauses
Anthropic (Claude) Helps generate your report from the transcript and brief United States Standard Contractual Clauses
Google Workspace Email, calendar, file storage EU and United States Standard Contractual Clauses / EU-U.S. Data Privacy Framework EU–US Data Privacy Framework, with Standard Contractual Clauses as a fallback
Calendly Scheduling and booking form United States Standard Contractual Clauses
Enty Invoicing and accounting European Union Within the EU — no transfer
Revolut Bank UAB Receiving payment European Union Within the EU — no transfer
Netlify Website hosting United States Standard Contractual Clauses

We may also share data with our accountant and, if it ever becomes necessary, with lawyers, auditors or a court. We will share with a public authority only where the law requires it.

Three things we never do

Transfers outside the EEA

Some of our processors are in the United States. Where that is the case, the transfer relies on the European Commission's Standard Contractual Clauses, supplemented where relevant by an adequacy decision or the EU-U.S. Data Privacy Framework, together with technical measures such as encryption in transit and at rest.

You can ask us for a copy of the transfer safeguards we rely on for any specific processor. Email admin@zaivo.ai and we will send them.

How long we keep things

Data Kept for Counted from
Call audio / video recording 90 days Delivery of your report
Call transcript 12 months Delivery of your report
Your brief and your report 7 years Delivery of your report
Contact details and billing records 7 years End of the financial year the invoice falls in
Booking form data (where no call took place) 12 months Date of the booking
Website server logs 30 days Date of the request
Marketing consent records Until you unsubscribe, plus 24 months from your last contact with us, or until you unsubscribe Withdrawal of consent

The 7-year periods are set by Estonian accounting and commercial law, and by the length of time in which a legal claim could still be brought. We keep the report itself for that period so that we can honour a refund, resolve a dispute, or send you a replacement copy if you lose yours.

If you withdraw recording consent, the audio and transcript are deleted sooner — see above.

When a retention period ends, we delete the data or irreversibly anonymise it.

Your rights

Under the GDPR you have the right to:

How to use them

Email admin@zaivo.ai. Say what you want. That is the whole process.

There is no form. We will not charge you. We may ask you to confirm your identity if the request comes from an address we do not recognise, because we are not going to hand your data to someone pretending to be you.

We respond within 30 days. If a request is genuinely complex we may extend that by up to two further months, and if we do, we will tell you within the first 30 days and explain why.

If we get it wrong

You can complain to a supervisory authority. Because we are established in Estonia, our lead authority is:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) Tatari 39, 10134 Tallinn, Estonia info@aki.ee — www.aki.ee

You can also complain to the data protection authority in the EU country where you live or work, or where you think the problem happened. A list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

We would rather you told us first — admin@zaivo.ai — but you are not required to.

Cookies and analytics

Plainly:

What does happen: our host, Netlify, keeps standard server logs (IP address, timestamp, page requested, browser user agent) for security and to keep the site up. That is a technical necessity, not tracking.

When you open the booking page, Calendly loads and sets its own cookies to make scheduling work. Those are Calendly's cookies, governed by its notice:

We do not take card payments on this site, so no payment provider loads here and none sets a cookie.

Because we set no non-essential cookies of our own, there is no cookie banner. If that ever changes, we will ask for your consent first, properly, with a real reject button.

How we use AI — and what that means for you

We are direct about this because you should not have to guess.

How your report is made. After the call, the recording is transcribed by Fathom. The transcript and your brief are then processed using Anthropic's Claude to help draft and structure the report. AI does the first pass on structure, synthesis and drafting.

A human reviews every report before it reaches you. A named person at ZAIVO — currently Eddie Eliakim, founder — reads, checks, edits and approves every report. They are named in the report itself, so you know who to argue with. No report is sent to you unread by a human.

No automated decisions about you. Nothing in this process makes an automated decision that has legal or similarly significant effects on you or your business. Every recommendation is a human-approved recommendation.

Your data is not used to train models. Not by us, and not by Anthropic or Fathom — that is written into our agreements with them.

AI can be wrong. Every recommendation in your report is a starting point for your judgement, not a substitute for it. Check anything that matters before you act on it, especially numbers, pricing and vendor claims.

The EU AI Act flag

Some of the tools we may recommend are AI systems. If you deploy one, the EU AI Act may place obligations on you as the deployer — things like informing your staff, human oversight, transparency to the people affected, or record-keeping. Those obligations depend on the tool and how you use it.

Where we recommend a tool that would carry EU AI Act deployer obligations for you, we flag it in the report — clearly, next to the recommendation, not in a footnote.

That flag tells you an obligation may exist and roughly what kind. It is not a legal opinion and it is not a compliance assessment. Before you deploy a flagged tool, take advice suited to your business.

Changes to this notice

If we change this notice we update the date at the top. If the change is significant — a new processor, a new purpose, a longer retention period — we email active and recent clients before it takes effect.

Old versions are available on request.