Legal document
Privacy Policy
How Enkronos OÜ processes account, learning, billing and evidence data in Workforce OS.
1. Controller and contact
The controller is Enkronos OÜ, Kotkapoja tn 2a-10, 10615 Tallinn, Estonia, VAT EE102151239. Privacy contact: contact@ainova.io.
2. Data we process
- Account and organisation data such as email, display name, membership, roles and authentication events.
- Learning data such as assignments, attempts, progress, completion and evidence records.
- Commerce data such as SKU, amount, currency, tax snapshot, Stripe identifiers, subscription state and refund history. Card details are handled by Stripe.
- Legal evidence such as accepted document version, consent type, timestamp, locale and, where configured and proportionate, IP address and user agent.
- Support and Training Provider application data supplied by the requester.
3. Purposes and legal bases
We use data to provide the service and perform orders, manage accounts and security, maintain learning and evidence records, process payments and refunds, communicate operational messages, comply with legal obligations and establish or defend claims. Optional analytics are not active in the current application repository. Consent is used where a separate consent is legally required, including immediate digital-content performance.
4. Providers actually identified in the application
The current application code integrates Stripe for checkout and payment events and Resend for transactional email and email delivery events. No analytics tracker, advertising SDK, OpenAI integration, Ollama integration or other external AI provider is embedded in the current application code. Provider configuration may change only through the documented release process and this notice will be updated when that changes.
5. Sharing and transfers
We disclose data to the providers above only as necessary for their service roles, to organisation administrators according to access permissions, and to authorities or advisers where required. International transfers, if any, are governed by the provider's applicable safeguards and the final data-processing configuration. We do not sell personal data.
6. Retention and rights
Retention periods are determined by the configured retention policy, the order and accounting record, security needs and applicable law. We do not invent a fixed period where the application has not configured one. You may request access, correction, deletion, restriction, portability or objection as applicable, and may complain to the competent supervisory authority. Financial, consent and audit records may need to be retained where required by law or for legal defence.
7. Security
We use access control, tenant isolation, password hashing, MFA support, signed webhooks, idempotency, audit events, private object storage boundaries and least-privilege provider configuration. No online service can guarantee absolute security; suspected incidents should be reported to the privacy contact.
8. Updates
Material changes are versioned. Where a change requires renewed acceptance, the application records a new consent before the relevant future action.