Privacy Policy
Last updated: 17 June 2026
1. Who we are
EGNITE ("we", "us") provides AI visibility analytics for industrial B2B brands. We are the data controller for personal data processed through this service.
2. What we collect
- Account data: email, name, surname, company, optional phone, industry, job function, department, key interest (provided during sign-up and onboarding).
- Usage data: scans you launch, prompts you create, recommendations viewed, timestamps.
- Billing data: plan, subscription status, and Paddle customer ID. We do not store card numbers.
- Technical data: IP address, browser type, cookies strictly necessary for authentication, and consent-based analytics cookies.
3. Why we process it (legal basis)
- Contract: to deliver the scanning, reporting, and account features you signed up for.
- Legitimate interest: to secure the platform, prevent abuse, and improve the service.
- Consent: for non-essential cookies, product emails, and analytics.
- Legal obligation: to retain billing records as required by tax law.
4. Where your data is stored & who we share it with
Your account, workspace and scan data are stored in the European Union (Ireland, AWS eu-west-1). We share data only with processors necessary to run the service:
- Lovable Cloud / Supabase — hosting, database, authentication (EU, Ireland).
- Paddle — billing and tax handling.
- Resend (via Lovable Email) — transactional and newsletter email.
- Cloudflare — edge delivery, TLS and bot protection.
- AI providers (OpenAI, Anthropic, Google, Perplexity, xAI, DeepSeek) — only the public URLs and prompts you submit; no account PII.
Where a provider processes data outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses (and, where applicable, the EU-US Data Privacy Framework), plus the supplementary measure that no directly identifying account data is sent to the AI providers. The full list with regions and transfer bases is on our Subprocessors page.
We never sell personal data.
5. Retention
We keep your account, workspace, and scan data for as long as your account exists — we do not auto-delete your history, so year-over-year AI visibility comparisons stay intact. When you delete your account, all personal and workspace data is erased immediately and irreversibly (see below); only anonymous page-view counters with no link to you are retained. Billing records are kept for 10 years as required by tax law.
6. Your GDPR rights
You can access, rectify, export, or delete your data at any time from Settings → Privacy, or by emailing privacy@egnitegroup.com. We respond to any request sent by email within 30 days of receipt, in line with GDPR Article 12. You also have the right to lodge a complaint with your supervisory authority.
If we ever suffer a personal data breach affecting you, we notify the competent supervisory authority and affected users without undue delay and within 72 hours of becoming aware of it.
7. Security
All data is encrypted in transit (TLS) and at rest. Access is gated by row-level security policies. We perform regular security scans of the backend.
AI provider handling
When you run a GEO scan, we send only the prompt text and the brand/context you entered (products, competitors, market, region). We do not send your email, account ID, or any personal information to OpenAI, Anthropic, Google, Perplexity, xAI, or DeepSeek. Calls are routed through enterprise API endpoints that do not use your data to train foundation models.
Data isolation
Every user's prompts, scan results, and brand data are stored in rows scoped to that user ID. Row-Level Security policies prevent one user from reading another user's data. Your competitors cannot access your workspace.
Export & deletion
You can download a full JSON export of your data or permanently delete your account from Settings → Privacy. Account deletion immediately erases your profile, brands, prompts, scan history, competitor data, expert verifications, support and consultation threads, subscription record, and any newsletter or contact-form records tied to your email address. Your address is added to a do-not-contact list, your login is removed, and you receive a deletion reference for your records.
For a complete security overview, see our Trust & Security page.
8. Contact
Questions? Contact us or email privacy@egnitegroup.com.
See also: Terms of Service, Trust & Security, Subprocessors, Cookie Policy, and our Data Processing Agreement.