PRE-DEPLOYMENT ETHICS REVIEW GDPR COMPLIANT EU AI ACT ALIGNED 100% EUROPEAN INFRASTRUCTURE
Legal · GDPR Compliance

Privacy Policy &
Data Protection

ANBORELA is built on a privacy-first architecture. This document explains how we collect, use and protect personal data in full compliance with the EU General Data Protection Regulation (GDPR).

Last updated: May 2026 Regulation: GDPR (EU) 2016/679 Jurisdiction: Estonia · EU Status: Pre-deployment research phase
Legal name ANBORELA CREATIVE FINTECH OÜ
Registration number 14746683
Registered address Pärnu mnt 139c, Kesklinna linnaosa,
Tallinn, Harju maakond, 11317 Estonia
Data Protection Officer Francisco Moreno · ai@anborela.ee
Supervisory authority Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Applicable regulation GDPR (EU) 2016/679 · EU AI Act 2024
01

Who We Are and What This Policy Covers

ANBORELA CREATIVE FINTECH OÜ ("ANBORELA", "we", "us") is an independent European research company registered in Estonia under e-Residency, developing a research-grade conversational AI system designed to provide non-clinical behavioural support for people in addiction recovery.

This Privacy Policy applies to all interactions with the ANBORELA website (anborela.ee and anborela.com), the ANBORELA conversational AI system (accessed via Telegram), and any research participation during pilot study phases. It does not apply to third-party platforms (including Telegram itself), which have their own privacy policies.

Important: The ANBORELA AI system is currently in a pre-deployment research phase. No real users are involved at this stage. This policy is published in advance of any public access, in line with our ethics-first, GDPR-by-design commitment.

02

What Data We Collect and Why

A) Website visitors (anborela.ee / anborela.com)

  • Standard web server logs: IP address (anonymised), browser type, pages visited, time of visit. Retained for 30 days for security purposes only.
  • Contact form submissions: name, email address, and message content. Used solely to respond to your enquiry.
  • No tracking cookies, advertising pixels or third-party analytics scripts are used.

B) Research pilot participants (future phases only)

  • Conversation text exchanged with the ANBORELA AI system.
  • Anonymous interaction logs: timestamps, session duration, system responses.
  • No real name, national ID, phone number or medical history is requested or stored.
  • Data is anonymised at the point of collection — no link between data and identity is maintained.
  • Participation is fully voluntary. Participants may withdraw at any time without consequence.
03

Legal Basis for Processing

  • Consent (Art. 6.1.a / Art. 9.2.a) — For research pilot participants who voluntarily opt in after receiving full informed consent documentation.
  • Legitimate interest (Art. 6.1.f) — For basic website security logs, retained for the minimum period necessary and never used for profiling.
  • Contract performance (Art. 6.1.b) — For contact form enquiries, to respond to partnership or collaboration requests.
  • Scientific research (Art. 9.2.j) — For anonymised research data processed during approved pilot studies, subject to ethics committee oversight.
04

Special Category Data — Health and Recovery Context

ANBORELA operates in a domain adjacent to health and addiction recovery. Conversations with the AI system may incidentally reveal information about a person's health status or substance use. We treat all such data as special category data under GDPR Article 9:

  • Explicit informed consent is obtained before any data is collected from research participants.
  • All conversation data is anonymised at the point of collection.
  • Data is stored on European infrastructure only, encrypted at rest and in transit.
  • No data is shared with third parties for commercial purposes under any circumstances.
  • Research access to anonymised datasets is granted only to approved academic partners under formal data sharing agreements.

The ANBORELA system does not diagnose, prescribe or replace professional clinical care. It is a non-clinical support tool. Emergency referral information is always visible to users. If you are in crisis, please contact emergency services in your country.

05

Data Storage, Security and Retention

  • Location: All data is stored on European servers, within EU law jurisdiction. No data is transferred outside the EEA.
  • Infrastructure: ANBORELA does not use Amazon Web Services, Microsoft Azure or Google Cloud.
  • Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  • Retention — website logs: 30 days, then automatically deleted.
  • Retention — contact enquiries: 12 months from last contact.
  • Retention — research data: As specified in the ethics-approved protocol. Anonymised datasets may be retained up to 5 years for scientific purposes (GDPR Art. 9.2.j).
  • No data is sold to third parties under any circumstances.
06

Your Rights Under GDPR

To exercise any right, contact us at ai@anborela.ee. We will respond within 30 days.

Right of access Request a copy of the personal data we hold about you (Art. 15 GDPR).
Right to rectification Ask us to correct inaccurate or incomplete data (Art. 16 GDPR).
Right to erasure Request deletion of your personal data (Art. 17 GDPR).
Right to restriction Ask us to limit how we use your data (Art. 18 GDPR).
Right to portability Receive your data in a machine-readable format (Art. 20 GDPR).
Right to object Object to processing based on legitimate interest (Art. 21 GDPR).
Right to withdraw consent Withdraw consent at any time without affecting prior processing (Art. 7.3 GDPR).
Right to complain Lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee).
07

Cookies and Tracking Technologies

  • Strictly necessary cookies: Session cookies required for basic website functionality only.
  • No advertising cookies, social media pixels or cross-site tracking.
  • No third-party trackers: We do not embed Facebook, Google, LinkedIn or other third-party scripts.
08

Third Parties and Data Sharing

  • Academic research partners: Anonymised datasets only, under formal Data Sharing Agreements and ethics committee approval.
  • Legal obligation: If required by law or court order. We will notify affected individuals to the extent permitted.
  • Telegram: The AI is accessed via Telegram. Telegram's own privacy policy governs their processing (telegram.org/privacy).
09

EU AI Act Compliance

  • The system does not make autonomous clinical decisions or diagnoses.
  • Human oversight is maintained at all stages of the research programme.
  • The system is subject to voluntary ethics review before any public deployment.
  • Academic and regulatory partners may request a full architecture review and model behaviour audit.
  • The AI model is built and controlled by Anborela OÜ — not licensed from Big Tech providers.
10

Changes to This Policy

We may update this Privacy Policy as the ANBORELA project progresses through its research phases or as legal requirements evolve. Material changes will be communicated via a notice on this page with a revised "Last updated" date.

This policy was first published in May 2026, in advance of any public deployment, as part of our commitment to transparency and ethics-first design.

Data Protection Contact

Data Controller & DPO Francisco Moreno
ANBORELA CREATIVE FINTECH OÜ
Postal address Pärnu mnt 139c, Kesklinna linnaosa
Tallinn, 11317 Estonia
Supervisory authority Andmekaitse Inspektsioon · aki.ee