Privacy Policy
Summary
This summary is here to be useful, not to replace the policy below. Where the two differ, the full policy governs.
- Who we are. eminnt is a product built and owned by Tkxel, a company registered in the United States and based in Reston, Virginia.
- We never train AI models on your content. Not our models, not anyone else's. We only work with AI providers whose terms contractually forbid it.
- Your content stays yours. The brand knowledge, expert interviews, and drafts you put into eminnt belong to you. We process them to run the service and for nothing else.
- We don't sell your personal information. If you consent to advertising cookies, our LinkedIn and Meta tags do something California law calls "sharing", you can opt out at any time, and nothing fires unless you consent.
- We tell you who touches your data. Every company involved in running our website is named in here. Customers get the complete named list of platform sub-processors with our Data Processing Agreement.
- You have real control. Access, correct, export, or delete your data by emailing privacy@eminnt.ai. We extend the same rights to every US resident, not only those in states that mandate them.
- We connect to Google and LinkedIn. Only with your permission, only for the scopes you approve, and you can disconnect any time.
1. Who we are and what this policy covers
eminnt ("eminnt", "we", "us", "our") is a product created and owned by Tkxel, a company registered in the United States with its principal place of business at:
Tkxel 11921 Freedom Drive Reston, Virginia 20190 United States
Tkxel is the entity responsible for the personal data described in this policy. Contact us at privacy@eminnt.ai or at the postal address above.
This policy explains how we handle personal data when you:
- visit eminnt.ai or any eminnt marketing page, blog, or landing page;
- use our website assistant, request a demo, or fill in a form;
- sign up for, evaluate, or use the eminnt platform;
- connect a third-party service such as Google Search Console, Google Analytics, LinkedIn, or your website CMS;
- take part in an expert or subject-matter-expert (SME) interview conducted through eminnt;
- see one of our ads, or submit a LinkedIn Lead Gen Form;
- receive marketing emails from us, or communicate with our team.
What this policy does not cover. It does not cover third-party websites we link to, the independent privacy practices of services you choose to connect, or the internal privacy practices of Tkxel's separate consulting and services business. Those are governed by their own policies.
2. Definitions
- Personal data: any information relating to an identified or identifiable person. "Personal information" under US state laws means substantially the same thing, and we use the terms interchangeably.
- Processing: anything done with personal data: collecting, storing, using, sharing, deleting, and so on.
- Customer: the organization that has an agreement with us to use the eminnt platform.
- Authorized User: an individual who accesses the platform under a Customer's account: a marketer, an expert/SME, a reviewer, an administrator.
- Customer Content: everything a Customer or its Authorized Users put into or generate in eminnt: brand knowledge inputs, uploaded documents, expert interview transcripts, briefs, drafts, published content, and connected-account data. Customer Content may contain personal data.
- Controller and Processor: a controller decides why and how personal data is processed; a processor acts on the controller's instructions. Which role we play depends on the data, as explained next.
- Sub-processor: a third party we engage that may process personal data on our behalf. See point 10.
3. Our two roles: when we are a controller and when we are a processor
This distinction determines who you contact about your data, so it matters.
We act as a controller for personal data we decide the purposes of ourselves:
- website visitors, prospects, and people who request a demo or download a resource;
- account and billing contacts;
- marketing and sales communications;
- platform usage and telemetry data we use to secure and improve the service.
For this data, this policy is the full description of what we do, and you can exercise your rights with us directly.
We act as a processor for Customer Content. When a Customer uploads a document, connects an analytics property, records an expert interview, or generates a draft, that Customer is the controller. We process it under our agreement with them, typically a Data Processing Agreement (DPA), and only on their instructions.
If you are an individual whose personal data appears inside a Customer's eminnt workspace (for example, you were interviewed for a case study, or you are named in one) and you want to access or delete that data, contact that Customer directly. If you contact us instead, we will pass your request to them within a reasonable time and support them in responding, but we cannot act on Customer Content unilaterally.
To request our DPA, email privacy@eminnt.ai.
4. What personal data we collect
We collect what we reasonably need for the purposes described in point 5, and no more. We do not collect personal data "just in case", and we do not buy personal data from data brokers.
4.1 Website and marketing data (we are controller)
| Data | Examples | How we get it |
|---|---|---|
| Contact details | Name, work email, company, job title, phone (if you provide it) | You give it to us via forms, demo requests, or the website assistant, or by submitting a LinkedIn Lead Gen Form, in which case LinkedIn passes us the profile details you agreed to share (see point 8.5) |
| Communications | Emails, assistant conversations, demo notes, support tickets | Your interactions with us |
| Marketing engagement | Emails opened, links clicked, pages viewed, content downloaded | Analytics and email tooling |
| Event and campaign data | Webinar registrations, campaign source, referring ad | Forms, ad platforms, UTM parameters |
| Cookie and device data | Pseudonymous identifiers, IP address, browser and device, pages viewed, interaction events | Cookies and tags: see point 7 |
4.2 Account and platform data (we are controller)
| Data | Examples |
|---|---|
| Account identity | Name, work email, password hash, role and permissions, workspace membership |
| Profile | Job title, expert profile details, avatar, notification preferences |
| Billing | Billing contact, billing address, plan, invoice history. Card details are handled entirely by our payment processor, we never see or store full card numbers. |
| Usage and telemetry | Features used, actions taken, timestamps, approximate location derived from IP, device/browser, log and error data |
| Support | Correspondence with our team, and: with your permission, session recordings or screen shares used to diagnose an issue |
4.3 Customer Content (we are processor)
| Data | Examples |
|---|---|
| Brand knowledge inputs | Website content we scan at your direction, ICP and positioning notes, brand voice, proof points, uploaded documents, expert profiles |
| Expert and SME material | Interview responses, transcripts, and: where you enable it, audio recordings captured during a case study interview; review comments, claim verifications, and approvals |
| Content in progress | Ideas, briefs, drafts, revisions, SEO and answer-engine scores, calendar entries, published output |
| Collaboration data | Assignments, comments, approval history, shared links |
4.4 Connected integration data (role depends on the integration)
When you connect a third-party service, we receive only what the scopes you approve permit. See point 8 for detail.
| Integration | What we receive |
|---|---|
| Google Search Console | Query, impression, click, position, and page-level performance data for properties you select |
| Google Analytics (GA4) | Aggregated traffic and engagement metrics for properties you select |
| Profile/page identifiers, access tokens, and publishing permissions for the accounts you authorize | |
| Website / CMS | Publishing credentials or API tokens, plus existing content we read to audit or update |
4.5 Data we do not want
Please don't put special-category or sensitive data into eminnt, health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, precise geolocation, immigration status, government ID numbers, or financial account numbers. eminnt is not designed or configured for it, and doing so may breach your agreement with us.
We do not collect sensitive personal information in order to infer characteristics about anyone, and we never sell or share sensitive personal data, a point some US state laws, including Maryland's, address directly.
5. Why we use personal data, and our legal basis
Under the GDPR and UK GDPR we must have a legal basis for each purpose. Here they are.
| Purpose | Legal basis |
|---|---|
| Providing the eminnt platform and its features | Performance of a contract |
| Sending your content to an AI provider to generate the output you requested | Performance of a contract |
| Creating and administering accounts, authentication, permissions | Performance of a contract |
| Billing, invoicing, collections | Performance of a contract; legal obligation |
| Support, onboarding, integration setup (we are a managed software service) | Performance of a contract; legitimate interests |
| Securing the service: abuse prevention, fraud detection, logging, backups | Legitimate interests; legal obligation |
| Improving the service through aggregated and de-identified usage analysis | Legitimate interests |
| Direct marketing to business contacts | Consent where required (EEA/UK); legitimate interests where permitted, always with an opt-out |
| Analytics, session recording, and advertising cookies | Consent |
| Responding to enquiries, demo requests, and assistant conversations | Legitimate interests; steps prior to entering a contract |
| Complying with law, responding to lawful requests, establishing or defending legal claims | Legal obligation; legitimate interests |
6. AI, machine learning, and your content
This section states our commitments plainly, because it is the question every prospect asks.
We do not use your content to train AI models. Not our own models, and not third-party models. Brand knowledge inputs, uploaded documents, expert interviews, drafts, and published content are never used as training or fine-tuning data.
We only use AI providers that are contractually barred from training on your data. eminnt uses third-party large language model providers to power its features. It is our standing procurement requirement that any such provider is engaged under enterprise or API terms that (a) prohibit the use of customer inputs and outputs to train or improve their models, and (b) limit retention to what is needed to return a response and meet the provider's own abuse-monitoring obligations. We do not opt in to any programme, preview, or free tier that would permit training on your data. If we could not obtain those terms from a provider, we would not use that provider.
How your content reaches an AI model. When you run a feature that researches, drafts, optimizes, audits, or builds a case study, the relevant context from your workspace is sent to an AI provider to generate the output you asked for. It is processed to fulfil that request and returned to your workspace.
Content between customers is never mixed. One Customer's brand knowledge, proof, or drafts are never used to generate output for another Customer.
Human review. Our staff do not read Customer Content routinely. Access is limited to specific circumstances: you ask us for support and grant access; we need to investigate a security incident or suspected abuse; or the law requires it. Such access is role-restricted, granted on a least-privilege basis, and logged.
Automated decision-making. eminnt generates and scores content. It does not make decisions that produce legal or similarly significant effects about individuals, so the GDPR Article 22 rules on solely automated decision-making do not apply. Content and scores produced by eminnt are drafts and recommendations for a person to review, the expert review step exists precisely so a human stays in the loop.
AI transparency. Where the EU AI Act applies to us, we meet its transparency requirements:
- Our website assistant tells you that you are interacting with an AI system, not a person.
- Content produced by eminnt is AI-generated or AI-assisted, and our platform makes that visible to the people working on it. Customers remain responsible for reviewing, approving, and (where their own obligations or local law require it) disclosing AI involvement in what they publish.
- We do not use AI to infer emotions, categorize people by biometric data, or perform any of the practices the AI Act prohibits.
Aggregated and de-identified data. We may create aggregated or de-identified statistics (such as how often a feature is used across all accounts) to operate and improve the service. This data cannot identify you or your organization, we maintain it in de-identified form, and we do not attempt to re-identify it.
7. Cookies and similar technologies
This section is our full cookie policy. eminnt.ai/cookies links here.
7.1 What cookies and similar technologies are
A cookie is a small text file a website stores on your device so it can recognize your browser on a later visit or later page. Cookies set by eminnt.ai are first-party; cookies set by another domain through content on our pages are third-party.
We also use a few things that behave like cookies:
- Local storage: data held in your browser, similar to a cookie but not sent with every request.
- Tags and pixels: small pieces of code, often loaded through a tag manager, that record that an event happened, such as a page view.
- Session recording: a script that captures interaction events like mouse movement, clicks, and scrolling to reconstruct an anonymized playback of a visit. Ours is explained in point 7.5, because it deserves more than a line in a table.
Throughout this section, "cookies" means all of the above.
7.2 How we categorize them
| Category | What it does | Consent required |
|---|---|---|
| Strictly necessary | Runs the site: security, load balancing, and remembering your cookie choices | No: the site can't work without them |
| Functional | Remembers preferences such as language, and keeps the website assistant's conversation together | Yes |
| Analytics | Tells us which pages and campaigns work, and how people navigate | Yes |
| Advertising | Measures our LinkedIn and Meta ad campaigns and reaches relevant business audiences | Yes |
7.3 Strictly necessary
These cookies do not identify you and are not used for analytics or advertising. Because the exact names are set by our hosting and consent tooling and change when those tools are updated, we describe them by function, your browser's cookie inspector will always show you the current names, and our cookie settings panel lists them in full.
| Purpose | Set by | Typical duration |
|---|---|---|
| Storing your cookie choices so we don't ask you again on every page | eminnt.ai | Up to 12 months |
| Keeping your connection secure and routing your request to the right server | eminnt.ai and our hosting provider | Session |
| Balancing load and protecting the site from automated abuse | Our hosting provider | Session to 24 hours |
7.4 Analytics: Google Analytics 4
We use Google Analytics 4 (property G-KG2TFHL1KS), loaded through Google Tag Manager (container GTM-TNSL3CJK), to understand how our site is used in aggregate.
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
| _ga | eminnt.ai (first-party) | Distinguishes one browser from another so visits can be counted | 2 years |
| _ga_KG2TFHL1KS | eminnt.ai (first-party) | Maintains session state for this specific Analytics property | 2 years |
7.5 Analytics and session recording: Microsoft Clarity
We use Microsoft Clarity (project xsy9cp47q1) to see how visitors actually experience our pages, where they hesitate, what they click, where they give up.
What this means in practice: Clarity records interaction events during your visit (mouse movement, clicks, scrolling, and page navigation) and reconstructs them as a playback, together with heatmaps showing where visitors click and how far they scroll. This is more intrusive than counting page views, so we're describing it plainly rather than burying it in a table.
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
| _clck | eminnt.ai (first-party) | Keeps a persistent Clarity user ID so repeat visits can be linked | 1 year |
| _clsk | eminnt.ai (first-party) | Links the page views within a single visit into one recording | 1 day |
| CLID, MUID, ANONCHK, SM, MR | Microsoft (clarity.ms, c.bing.com) | Third-party identifiers Microsoft uses to operate Clarity | Session to 1 year |
7.6 Advertising
We use advertising tags to measure whether our campaigns work and to reach relevant business audiences.
These tags load only after you consent to advertising cookies. If you decline, or have not consented, none of the cookies below are set and no data about your visit reaches LinkedIn or Meta. You can withdraw consent at any time from Cookie settings in our footer.
LinkedIn Insight Tag
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
| li_fat_id | eminnt.ai (first-party) | Indirect member identifier used for conversion tracking and retargeting | 30 days |
| bcookie | linkedin.com (third-party) | Browser identifier | 1 year |
| bscookie | linkedin.com (third-party) | Secure browser identifier used for authentication features | 1 year |
| lidc | linkedin.com (third-party) | Routes the request to the right LinkedIn data centre | 1 day |
| li_sugr | linkedin.com (third-party) | Probabilistic browser matching | 90 days |
| UserMatchHistory | linkedin.com (third-party) | Synchronizes LinkedIn Ads identifiers | 30 days |
| AnalyticsSyncHistory | linkedin.com (third-party) | Records when a sync with lms_analytics occurred | 30 days |
| lms_ads / lms_analytics | linkedin.com (third-party) | Identifies LinkedIn members off LinkedIn for advertising and analytics | 30 days |
| li_gc | linkedin.com (third-party) | Stores consent for non-essential cookies | 6 months |
| Cookie | Set by | Purpose | Duration |
| _fbp | eminnt.ai (first-party) | Identifies a browser so Meta can attribute a conversion to an ad | 3 months |
| _fbc | eminnt.ai (first-party) | Stores the click identifier from a Meta ad you arrived from | 3 months |
| fr | facebook.com (third-party) | Encrypted account and browser identifier used to deliver and measure ads | 3 months |
7.7 Functional
| Purpose | Set by | Stored as | Duration |
|---|---|---|---|
| Keeping your conversation with our website assistant connected as you move between pages | eminnt.ai and our assistant provider | Cookie or browser local storage | For the conversation, and up to 30 days so you can pick it up again |
| Remembering interface preferences such as language | eminnt.ai | Cookie | Up to 12 months |
7.8 How to control cookies
On our site. Use the Cookie settings link in the footer to review and change your choices at any time. We ask before setting anything beyond strictly necessary cookies, and withdrawing consent is as easy as giving it.
Global Privacy Control. We honour the GPC browser signal as an opt-out of sale and sharing, and of targeted advertising, wherever it is offered, not only in the states that require us to. We do not respond to the older "Do Not Track" header, because no common standard for it was ever agreed.
In your browser. You can block or delete cookies in your browser settings, Chrome, Safari, Firefox, Edge. Blocking strictly necessary cookies will break parts of the site.
Opting out of specific tools.
- Google Analytics: the browser opt-out add-on.
- Microsoft Clarity: the choices Microsoft offers in its privacy statement, and declining analytics cookies here.
- LinkedIn: your LinkedIn ad settings.
- Meta: your Meta ad preferences and off-Facebook activity settings.
Declining cookies here stops these tags from firing on our site in the first place, which is the more complete option.
8. Third-party APIs and integrations
You choose which services to connect. We ask for the narrowest scopes that make the feature work, and you can disconnect at any time from your eminnt settings, which revokes our access going forward.
8.1 Google API Services: Limited Use disclosure
eminnt connects to Google Search Console and Google Analytics so our performance reporting and SEO audit features can show you how your content is doing.
eminnt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the features you connected it for.
- We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or to comply with applicable law.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data unless we have your explicit consent, it is necessary for security or to comply with law, or the data has been aggregated and de-identified.
- We do not use Google user data to develop, improve, or train generalized AI or machine learning models.
You can revoke eminnt's access at any time in your Google Account permissions.
8.2 LinkedIn publishing
When you authorize LinkedIn, we receive the profile or page identifiers and publishing permissions needed to post reviewed content on your behalf. We use this only for publishing and the reporting tied to it, and never to build a profile of you or to contact your connections. Revoke access in your LinkedIn account settings or in eminnt.
8.3 Website and CMS connections
To publish to your site, we store the credentials or API tokens you provide, encrypted. We use them only to read content you ask us to audit and to publish or update content you have approved.
8.4 Advertising platforms: LinkedIn and Meta
We advertise on LinkedIn and Meta, and we place their measurement tags on our marketing pages so we can tell which campaigns work. These tags are set only if you consent to advertising cookies; the specific cookies, durations, and opt-outs are in point 7.6.
Joint controllership. In the EEA and UK, we and each platform act as joint controllers for the collection of data through their tag and its use for audience building and campaign reporting, LinkedIn under its Ads joint-controller arrangement, Meta under its Business Tools terms. Each platform is solely responsible for what it subsequently does with that data under its own privacy policy. You can exercise your rights against either us or the platform; contact us at privacy@eminnt.ai and we will help you reach the right place. The essence of each arrangement is available from the platform, and we will send you our copy on request.
We do not send your contact details to these platforms. Meta's Advanced Matching, which would transmit hashed email addresses and phone numbers, is switched off.
8.5 LinkedIn Lead Gen Forms
If you submit a Lead Gen Form attached to one of our LinkedIn ads, that form is hosted by LinkedIn, not by us, and is pre-filled from your LinkedIn profile. When you submit it, LinkedIn passes us the details you agreed to share, typically name, work email, job title, and company, plus answers to any questions we added.
We receive that data in LinkedIn Campaign Manager and our CRM, and handle it exactly as we handle any other demo or contact request: to respond to you and, where permitted, to send you relevant marketing you can opt out of at any time. We become the controller of that data once we receive it. LinkedIn's handling before that point is governed by the LinkedIn Privacy Policy.
To have it deleted, email privacy@eminnt.ai.
8.6 Other third-party services
Services you connect to are controlled by you and governed by their own privacy policies. We encourage you to read them. We are not responsible for how those services handle data once it leaves eminnt at your instruction.
9. How we share personal data
We do not sell personal data. We share it only in these situations:
Sub-processors and service providers. Vendors that help us run eminnt, each under a written contract requiring confidentiality, appropriate security, and processing only on our instructions.
Advertising and analytics partners. Where you consent to advertising cookies, LinkedIn and Meta receive online identifiers and browsing activity from our marketing pages, so we can measure campaigns and build audiences. In the EEA and UK we are joint controllers with each platform for that collection (see point 8.4. In the US this is "sharing" or "targeted advertising") see point 17. Google and Microsoft receive analytics data on the same consent basis.
Within Tkxel. eminnt is operated by Tkxel. Tkxel personnel (engineering, support, security) may access data where needed to run the service, under the same restrictions described in this policy. See point 10.4.
At your direction. To services you connect, or to people you share content with.
Legal and safety. Where we must comply with law, a court order, or a valid government request; or to protect the rights, property, or safety of eminnt, our Customers, or the public. We assess every request for validity and scope, we push back on requests that are overbroad, and we will notify affected Customers of legal requests unless legally prohibited from doing so.
Business transfers. If eminnt or Tkxel is involved in a merger, acquisition, financing, or sale of assets, personal data may transfer as part of that transaction. We will notify you, and the recipient will remain bound by this policy or give notice before materially changing it.
10. Our sub-processors
This section is our sub-processor disclosure. eminnt.ai/subprocessors links here.
Last updated: 13 August 2026.
Every sub-processor is subject to due diligence before onboarding and a written contract requiring confidentiality, appropriate technical and organizational security measures, processing only on our documented instructions, and (where personal data leaves the EEA or UK) Standard Contractual Clauses or another valid transfer mechanism. We remain responsible to you for their performance.
Below, we name in full every third party that processes data from our public website and marketing (point 10.3), because you can see those in your browser and you are entitled to know who they are. For the platform sub-processors that may touch Customer Content (point 10.2), we set out each one's role, the data involved, and our commitments; the complete list of named vendors, with entity details and processing locations, forms part of our Data Processing Agreement and is available to Customers and to anyone evaluating eminnt, just email privacy@eminnt.ai and we will send it. We do this because that list changes as the product matures, and a stale name on a web page is worse than a current one you can actually rely on contractually.
10.1 Notice of changes
We may add or replace sub-processors as the product evolves.
Customers with a Data Processing Agreement receive advance notice. We give at least 30 days' notice, by email to the notice contact your organization nominated in the DPA, before a new sub-processor starts processing Customer Content. If you have a reasonable, documented objection on data protection grounds, tell us within 15 days and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
Changes to the website and marketing vendors in point 10.3 are recorded in the change log at point 10.5 and reflected on this page.
10.2 Platform sub-processors
Categories of provider that may process Customer Content, your brand knowledge, documents, expert interviews, drafts, and connected-account data. Named vendors are listed in our DPA and available on request from privacy@eminnt.ai.
| Category | Purpose | Data processed | Location |
|---|---|---|---|
| Cloud infrastructure and database | Primary application hosting, compute, and data storage | Account data, Customer Content | United States |
| Application hosting and edge delivery: Vercel Inc. | Hosting, edge network, and delivery for eminnt.ai and the application | Request metadata, IP addresses, log data | United States (origin region iad1), global edge network |
| Large language model providers | Powers the research, drafting, optimization, audit, and case study features | Prompts and context drawn from Customer Content | United States |
| Workflow orchestration | Runs long-running jobs such as site audits | Job metadata, Customer Content in transit | United States |
| Error monitoring and observability | Diagnostics and reliability | Log data, error traces, limited account identifiers | United States |
| Product analytics | Understanding in-product feature usage | Usage events, account identifiers | United States |
| Transactional email delivery | Invitations, notifications, password resets | Name, email address, message content | United States |
| Payment processing | Billing and invoicing | Billing contact and address; card data handled entirely by the processor, never by us | United States |
| Support tooling | Support tickets and correspondence | Name, email, ticket content | United States |
10.3 Website and marketing sub-processors
Named in full. These providers process data from our public website and marketing activity, and do not touch Customer Content.
| Provider | Purpose | Data processed | Entity location |
|---|---|---|---|
| Vercel Inc. | Hosting and delivery of eminnt.ai | Request metadata, IP addresses | United States |
| Google LLC | Google Analytics 4 (G-KG2TFHL1KS) and Google Tag Manager (GTM-TNSL3CJK) | Pseudonymous identifiers, page views, approximate location derived from IP, device and browser data | United States |
| Google LLC (Workspace) | Business email and productivity for our domains | Email correspondence, contact details | United States |
| Microsoft Corporation | Microsoft Clarity (xsy9cp47q1): heatmaps and session recording | Interaction events, clicks, scroll depth, pseudonymous identifiers, session recordings | United States |
| LinkedIn (LinkedIn Corporation / LinkedIn Ireland ULC) | Insight Tag: ad delivery, conversion measurement, audience building. Lead Gen Forms, collects your profile details on LinkedIn and passes them to us | Pseudonymous identifiers, browsing activity, conversion events; for Lead Gen Forms: name, work email, job title, company | United States / Ireland |
| Meta (Meta Platforms, Inc. / Meta Platforms Ireland Ltd) | Meta Pixel: ad delivery and conversion measurement | Pseudonymous identifiers, browsing activity, conversion events | United States / Ireland |
| CRM and marketing automation | Managing prospect and customer relationships, marketing email | Name, work email, company, engagement history | United States |
| Website assistant provider | The assistant on eminnt.ai | Conversation transcripts, any contact details you provide | United States |
| Consent management platform | Recording and honouring your cookie consent | Consent choices, pseudonymous identifier | United States |
10.4 Tkxel personnel and international access
eminnt is a product created and owned by Tkxel, an international company. Tkxel personnel in engineering, support, and security may access personal data where necessary to operate and support the service, and some of those personnel are located outside the United States, including in countries that do not have a European Commission adequacy decision.
We treat that access as an international data transfer and protect it accordingly:
- it is covered by the Standard Contractual Clauses and UK Addendum described in point 11;
- it is role-restricted, granted on a least-privilege basis, time-limited where possible, and logged;
- everyone with access is bound by written confidentiality obligations and receives data protection training;
- access to Customer Content specifically is limited to the circumstances in point 6 ("Human review").
If you are evaluating eminnt and need the current list of countries from which our personnel access data (a routine question in enterprise security reviews, and a fair one) email privacy@eminnt.ai and we will tell you.
10.5 Change log
| Date | Change |
|---|---|
| 13 August 2026 | Initial publication. |
11. International data transfers
We are based in the United States and use service providers and personnel in several countries. If you are in the EEA, the UK, or Switzerland, your personal data will be transferred outside your region.
We rely on the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission, together with the UK International Data Transfer Addendum and, for Switzerland, the FDPIC-recognized adaptations, in our contracts with Customers, sub-processors, and intra-group recipients;
- Transfer impact assessments where required, together with supplementary technical and organizational measures, including encryption in transit and at rest, access logging, and a policy of challenging overbroad government requests;
- Adequacy decisions, where the destination country has one.
We do not currently rely on the EU–US Data Privacy Framework for these transfers; our safeguards stand on the Standard Contractual Clauses and the measures above.
To request a copy of the relevant safeguards, email privacy@eminnt.ai.
12. How long we keep personal data
We keep personal data only as long as we need it for the purposes in this policy, or as long as the law requires.
| Data | Retention |
|---|---|
| Account and Customer Content | For the life of the account. On termination you have 30 days to export your Customer Content; we then delete or de-identify it within a further 30 days (so no later than 60 days after termination) subject to your agreement and to any legal hold |
| Backups | Purged on our standard backup cycle, within 90 days of deletion from live systems |
| Billing and tax records | As required by US tax and accounting law: 7 years |
| Marketing contacts | Until you unsubscribe or ask for deletion, or after 24 months of no engagement |
| Website analytics (Google Analytics 4) | 14 months |
| Session recordings and heatmaps (Microsoft Clarity) | Deleted on Microsoft's standard Clarity retention cycle; we do not export, download, or separately store recordings |
| Security and access logs | 12 months |
| Support correspondence | 24 months after the ticket closes |
| Demo requests and prospect records that do not convert | 24 months |
| Consent records | 24 months from the date consent was given or last updated, so we can demonstrate it |
| Cookies | As stated per cookie in point 7 |
13. Security
We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, and disclosure, proportionate to the risk. These include:
- Encryption in transit (TLS) and at rest;
- Access control: role-based permissions, least privilege, multi-factor authentication for staff, logged administrative access;
- Tenant isolation so one Customer's workspace cannot be accessed from another;
- Encrypted storage of integration tokens and credentials;
- Monitoring and logging, with alerting on anomalous activity;
- Backups and tested recovery procedures;
- Vendor due diligence before onboarding any sub-processor;
- Confidentiality obligations and security training for everyone with access;
- Change management and code review before changes reach production;
- Periodic review and testing of our controls, including third-party testing of the application before significant releases.
On certifications. We describe only the controls we actually operate, and we do not claim certifications we do not hold or list ones that are merely in progress. Our infrastructure runs on established cloud providers that maintain independently audited security programmes. If you need our current security documentation for a vendor review (architecture, controls, sub-processor list, or a completed questionnaire) email security@eminnt.ai and we will send you what we have, with an honest account of what we do not.
Reporting a vulnerability. If you believe you have found a security issue in eminnt, email security@eminnt.ai. We will acknowledge your report, keep you updated, and will not pursue legal action against anyone who reports a genuine issue in good faith and does not access, alter, or retain other people's data while doing so.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential and for who you invite into your workspace.
14. Data breach notification
If a personal data breach occurs:
- Where we act as controller and the breach is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, we will notify affected individuals directly, unless the data was rendered unintelligible (for example, by strong encryption) or notification would involve disproportionate effort, in which case we will make a public communication instead.
- Where we act as processor, we will notify the affected Customer without undue delay after becoming aware, so they can meet their own obligations, and we will support their investigation and notification.
- We will notify US state authorities and residents as required by applicable state breach-notification laws, including those of Virginia and California.
We maintain an internal record of breaches and our response to them, whether or not they are notifiable.
15. Children
eminnt is a business tool for adults. Our Terms of Service require users to be at least 18. We do not knowingly collect personal data from anyone under 18, we do not direct any part of our service or marketing at children, and we do not sell or share the personal information of anyone we know to be under 16. If you believe a child has provided us personal data, email privacy@eminnt.ai and we will delete it.
16. Your rights under the GDPR and UK GDPR
If you are in the EEA, the UK, or Switzerland, you have the following rights over personal data for which we are the controller.
16.1 Right of access. You can ask whether we process your personal data and, if so, receive a copy along with the purposes, the categories involved, who we share it with, how long we keep it, and where we obtained it. The first copy is free; we may charge a reasonable administrative fee for further copies, or for manifestly unfounded or excessive requests.
16.2 Right to rectification. You can ask us to correct inaccurate personal data and to complete incomplete data.
16.3 Right to erasure ("right to be forgotten"). You can ask us to delete your personal data where: it is no longer necessary for the purpose it was collected; you withdraw the consent we relied on and there is no other basis; you object and there is no overriding legitimate ground; it was processed unlawfully; or the law requires deletion. This right is not absolute, we may keep data where we must for legal claims or legal obligations.
16.4 Right to restriction of processing. You can ask us to restrict processing where: you contest the accuracy of the data (for as long as it takes us to verify); the processing is unlawful but you prefer restriction to deletion; we no longer need the data but you need it for legal claims; or you have objected and we are assessing whether our grounds override yours.
16.5 Right to data portability. Where processing is based on consent or on a contract and is carried out by automated means, you can receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible. We may decline where doing so would adversely affect the rights of others.
16.6 Right to object. You can object at any time to processing based on legitimate interests, on grounds relating to your particular situation. You can object to direct marketing at any time, for any reason, and we will stop.
16.7 Right to withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
16.8 Right to lodge a complaint. See point 19.
How to exercise these rights. Email privacy@eminnt.ai. We will respond within one month, extendable by two further months for complex requests, we will tell you if we need the extension and why. We may need to verify your identity first; we will only ask for what is necessary to do so, and we will not use that information for anything else. Exercising your rights is free of charge in normal circumstances, and we will not treat you differently for having done so.
17. Your rights in the United States
A growing number of US states have comprehensive privacy laws, and the list changes every few months. Rather than maintain a state-by-state table that goes out of date, we extend the rights in this section to every US resident, whatever state you live in and whether or not your state's law requires it.
Those rights are to:
- Know what personal information we collect, the sources, the purposes, how long we keep it, and the categories of third parties we disclose it to;
- Access a copy of the specific pieces of personal information we hold about you;
- Correct inaccurate personal information;
- Delete personal information, subject to exceptions we will explain if they apply;
- Obtain a portable copy in a usable format;
- Opt out of the sale or sharing of personal information and of targeted advertising;
- Limit the use of sensitive personal information, though as point 4.5 explains, we do not use it in the ways that trigger this right;
- Appeal if we deny a request (see below);
- Non-discrimination: we will not deny service, charge a different price, or provide a lesser quality of service because you exercised a right.
Categories collected. In the past 12 months we have collected the following categories: identifiers; commercial information; internet or other electronic network activity; professional or employment-related information; approximate geolocation derived from IP; and inferences drawn from the above. We collect these from you, from your device, from your connected integrations, and from our service providers. We disclose them to the recipients in point 9 and point 10, for the business purposes in point 5, and we retain them for the periods in point 12.
Sensitive personal information. We do not collect sensitive personal information in order to infer characteristics, we do not sell or share it, and we do not use or disclose it beyond the purposes permitted by law. Account credentials are collected solely to authenticate you.
Sale and sharing. We do not sell personal information for money, and we never have.
We do, however, share personal information for cross-context behavioral advertising (what other states call targeted advertising) when, and only when, you consent to advertising cookies. Our LinkedIn Insight Tag and Meta Pixel transmit online identifiers and browsing activity to those platforms so we can measure our campaigns and reach relevant business audiences. Under California law that is "sharing", and we are telling you so plainly rather than hiding behind the fact that no money changes hands.
- Categories shared: identifiers (including cookie IDs and device identifiers) and internet or other electronic network activity.
- Shared with: LinkedIn and Meta, for cross-context behavioral advertising.
- How to opt out: the "Do Not Sell or Share My Personal Information" link in our footer, our Cookie settings panel, or a Global Privacy Control signal, any of which stops these tags from firing. Because these tags require your opt-in consent in the first place, simply declining advertising cookies has the same effect.
We do not sell or share the personal information of anyone we know to be under 16.
A note on business contact data. Most of the personal information we hold is business contact data, your work email, job title, and employer. Several state privacy laws exclude that data from their scope; California's does not. We apply this section to it either way.
Authorized agents. You may use an authorized agent to submit a request, provided they give us written proof of authorization and we can verify your identity.
How to submit a request. Email privacy@eminnt.ai. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you.
How to appeal. If we deny your request, reply to our decision with "Appeal" in the subject line. We will review it and respond within 60 days. If we deny the appeal, we will tell you how to complain to your state attorney general.
If your data sits inside a Customer's workspace. If your personal information is in a Customer's eminnt account (because you were interviewed, quoted, or named) that Customer is the business or controller. Direct your request to them; see point 3.
18. Changes to this policy
We may update this policy as the product, our vendors, or the law change. When we do, we will update the "Last updated" date at the top.
If the change is material: a new purpose, a new category of sharing, a new category of data, a reduction in your rights, or a change in who we are, we will give you reasonable advance notice by email or in-product before it takes effect, and where the law requires consent for the new processing, we will ask for it rather than assume it.
Sub-processor changes are tracked separately in point 10.5 with their own dated change log and their own notice commitment in point 10.1, so routine vendor updates don't require you to re-read the whole policy.
We keep previous versions of this policy and will send you any of them on request.
19. Complaints, questions, and supervisory authorities
Contact us first. We would rather fix a problem than have you escalate it.
Privacy, data rights, and DPA requests: privacy@eminnt.ai Security questionnaires and vulnerability reports: security@eminnt.ai General enquiries: hello@eminnt.ai Post: Tkxel, 11921 Freedom Drive, Reston, Virginia 20190, United States
Who is accountable. privacy@eminnt.ai reaches the person at Tkxel responsible for data protection, and it is monitored. We have not appointed a Data Protection Officer under Article 37 of the GDPR, because our processing does not meet the criteria that require one we are not a public authority, and neither large-scale systematic monitoring of individuals nor large-scale processing of special category data is a core activity of ours. If that changes, we will appoint one and name them here.
