Privacy Policy
Version 1.0 · 2026-10-08
Controller: Nordrose Technologies OÜ, registry code 16358057, Erika tn 14, 10416 Tallinn, Estonia. Contact: privacy@nordro.io.
This policy describes how Zeronode processes personal data on zeronode.ai, in the dashboard and in the AI sales assistant service.
When you visit zeronode.ai
The website sets no tracking cookies and uses no third-party analytics. If you send the contact form or an early access request, we use your name, email and message to reply to you.
When you register and use the dashboard
When you create an account we process your name, email address, company name and a password hash to provide the service and send service messages. The legal basis is contract (GDPR Article 6(1)(b)). Billing records are kept for 7 years as accounting law requires. Account data is deleted within 30 days after the account is closed. Signing in uses a session cookie that is necessary for the service to work.
When you talk to the AI assistant on one of our customers’ websites
The Zeronode AI assistant runs on our customers’ websites. The controller of your data is the company whose website you are on, and its privacy notice applies. Zeronode processes the data on its behalf as a processor.
- Conversation content. Messages and uploaded photos are sent to a model provider (OpenAI; Google for photos) to generate replies. The providers do not use them to train their models.
- Browsing context. The assistant sees which pages you viewed on that website during the same visit. You are not tracked across other websites or across visits.
- Browser storage. To continue a conversation, the widget keeps the conversation id and content in your browser storage. No cookies are set and no persistent identifier is created.
- Deletion. You can delete your conversations yourself from the widget. Conversations are deleted automatically 30 days after the last message, photos after 7 days.
- Contact details. If you leave your name, email or phone in the conversation, they are passed to the website owner so they can contact you.
Your rights
You have the right to access, correct and delete your data, to restrict processing and to object. Write to privacy@nordro.io. If your question concerns a conversation on a customer’s website, contact that website’s owner first. You have the right to lodge a complaint with your data protection authority; in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon).
Data location and sub-processors
Data is stored in the European Union. Model providers process conversation content in the USA under the EU-US Data Privacy Framework and Standard Contractual Clauses.
| Sub-processor | Purpose | Location | Transfer basis | Retention at provider |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | servers, database, photo storage, widget files | Stockholm, Sweden | no transfer outside the EU | per the retention table |
| OpenAI | conversation model | USA | EU-US Data Privacy Framework, Standard Contractual Clauses | up to 30 days for abuse monitoring; not used for training |
| photo search, room visualisation, email notifications to the Customer | USA and other Google locations | EU-US Data Privacy Framework, Standard Contractual Clauses | limited period for abuse monitoring; not used for training |