Skip to content
aivoma
Free check

Legal

Privacy policy

Last updated: 2026-08-15

1. Who we are

The controller of personal data processed on aivoma.com is Mervantis OÜ (trading as Aivoma), registry code 14412321, Asuvere tee 7-4, Tihemetsa alevik, Saarde vald, 86201 Pärnu maakond, Estonia. Email: [email protected].

2. What we process, why and on what legal basis

Contact and free-check requests

When you submit the contact form we process your name, email address, store URL, the optional details you provide (product count, country, interest, message), plus technical data (IP address, user agent, submission time) used for spam prevention. Purpose: to answer your request, run the AI visibility check you asked for, and prepare an offer. Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract at your request) and Art. 6(1)(f) (our legitimate interest in preventing abuse of the form). We do not use your details for newsletters or marketing without separate consent.

Client work

If you become a client we process contact, billing and store-access data necessary to deliver and invoice the service (Art. 6(1)(b) and 6(1)(c) GDPR — accounting obligations under Estonian law).

Server logs and security

Our hosting and Cloudflare keep short-lived technical logs (IP address, requested URL, user agent) to operate and secure the site (Art. 6(1)(f)).

Analytics

We do not use Google Analytics, advertising pixels or cross-site tracking. If we measure site usage, we use privacy-friendly, cookieless, aggregate analytics (e.g. Cloudflare Web Analytics) that do not identify you (Art. 6(1)(f)).

3. Cookies and similar technologies

The site sets no analytics or marketing cookies, so no cookie banner is needed. Cloudflare may set a strictly necessary security cookie (__cf_bm) to distinguish humans from bots when bot protection or Turnstile is active.

4. Recipients and processors

  • Brevo (Sendinblue SAS, France) — transactional email delivery for form submissions.
  • Cloudflare, Inc. — CDN, DNS, security and (where enabled) Turnstile bot protection. Data may be processed under EU-US Data Privacy Framework and standard contractual clauses.
  • Our accountant and IT service providers under confidentiality, only where necessary.

We do not sell personal data.

5. Retention

Contact requests that do not lead to a contract are deleted no later than 12 months after our last communication. Client and invoicing data are kept for 7 years as required by the Estonian Accounting Act. Server logs are kept for up to 30 days.

6. Your rights

You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, and to withdraw consent at any time. Write to [email protected]. You can also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local supervisory authority.

7. AI crawlers and this website

This site is intentionally readable by search engines and AI assistants. This concerns our published content only; personal data submitted through forms is never published.

8. Changes

We update this policy when our processing changes. The date at the top shows the current version.