Privacy Policy

Effective date: 13 August 2026Last updated: 13 August 2026

Summary

This summary is here to be useful, not to replace the policy below. Where the two differ, the full policy governs.

  • Who we are. eminnt is a product built and owned by Tkxel, a company registered in the United States and based in Reston, Virginia.
  • We never train AI models on your content. Not our models, not anyone else's. We only work with AI providers whose terms contractually forbid it.
  • Your content stays yours. The brand knowledge, expert interviews, and drafts you put into eminnt belong to you. We process them to run the service and for nothing else.
  • We don't sell your personal information. If you consent to advertising cookies, our LinkedIn and Meta tags do something California law calls "sharing", you can opt out at any time, and nothing fires unless you consent.
  • We tell you who touches your data. Every company involved in running our website is named in here. Customers get the complete named list of platform sub-processors with our Data Processing Agreement.
  • You have real control. Access, correct, export, or delete your data by emailing privacy@eminnt.ai. We extend the same rights to every US resident, not only those in states that mandate them.
  • We connect to Google and LinkedIn. Only with your permission, only for the scopes you approve, and you can disconnect any time.

1. Who we are and what this policy covers

eminnt ("eminnt", "we", "us", "our") is a product created and owned by Tkxel, a company registered in the United States with its principal place of business at:

Tkxel 11921 Freedom Drive Reston, Virginia 20190 United States

Tkxel is the entity responsible for the personal data described in this policy. Contact us at privacy@eminnt.ai or at the postal address above.

This policy explains how we handle personal data when you:

  • visit eminnt.ai or any eminnt marketing page, blog, or landing page;
  • use our website assistant, request a demo, or fill in a form;
  • sign up for, evaluate, or use the eminnt platform;
  • connect a third-party service such as Google Search Console, Google Analytics, LinkedIn, or your website CMS;
  • take part in an expert or subject-matter-expert (SME) interview conducted through eminnt;
  • see one of our ads, or submit a LinkedIn Lead Gen Form;
  • receive marketing emails from us, or communicate with our team.

What this policy does not cover. It does not cover third-party websites we link to, the independent privacy practices of services you choose to connect, or the internal privacy practices of Tkxel's separate consulting and services business. Those are governed by their own policies.

2. Definitions

  • Personal data: any information relating to an identified or identifiable person. "Personal information" under US state laws means substantially the same thing, and we use the terms interchangeably.
  • Processing: anything done with personal data: collecting, storing, using, sharing, deleting, and so on.
  • Customer: the organization that has an agreement with us to use the eminnt platform.
  • Authorized User: an individual who accesses the platform under a Customer's account: a marketer, an expert/SME, a reviewer, an administrator.
  • Customer Content: everything a Customer or its Authorized Users put into or generate in eminnt: brand knowledge inputs, uploaded documents, expert interview transcripts, briefs, drafts, published content, and connected-account data. Customer Content may contain personal data.
  • Controller and Processor: a controller decides why and how personal data is processed; a processor acts on the controller's instructions. Which role we play depends on the data, as explained next.
  • Sub-processor: a third party we engage that may process personal data on our behalf. See point 10.

3. Our two roles: when we are a controller and when we are a processor

This distinction determines who you contact about your data, so it matters.

We act as a controller for personal data we decide the purposes of ourselves:

  • website visitors, prospects, and people who request a demo or download a resource;
  • account and billing contacts;
  • marketing and sales communications;
  • platform usage and telemetry data we use to secure and improve the service.

For this data, this policy is the full description of what we do, and you can exercise your rights with us directly.

We act as a processor for Customer Content. When a Customer uploads a document, connects an analytics property, records an expert interview, or generates a draft, that Customer is the controller. We process it under our agreement with them, typically a Data Processing Agreement (DPA), and only on their instructions.

If you are an individual whose personal data appears inside a Customer's eminnt workspace (for example, you were interviewed for a case study, or you are named in one) and you want to access or delete that data, contact that Customer directly. If you contact us instead, we will pass your request to them within a reasonable time and support them in responding, but we cannot act on Customer Content unilaterally.

To request our DPA, email privacy@eminnt.ai.

4. What personal data we collect

We collect what we reasonably need for the purposes described in point 5, and no more. We do not collect personal data "just in case", and we do not buy personal data from data brokers.

4.1 Website and marketing data (we are controller)

DataExamplesHow we get it
Contact detailsName, work email, company, job title, phone (if you provide it)You give it to us via forms, demo requests, or the website assistant, or by submitting a LinkedIn Lead Gen Form, in which case LinkedIn passes us the profile details you agreed to share (see point 8.5)
CommunicationsEmails, assistant conversations, demo notes, support ticketsYour interactions with us
Marketing engagementEmails opened, links clicked, pages viewed, content downloadedAnalytics and email tooling
Event and campaign dataWebinar registrations, campaign source, referring adForms, ad platforms, UTM parameters
Cookie and device dataPseudonymous identifiers, IP address, browser and device, pages viewed, interaction eventsCookies and tags: see point 7

4.2 Account and platform data (we are controller)

DataExamples
Account identityName, work email, password hash, role and permissions, workspace membership
ProfileJob title, expert profile details, avatar, notification preferences
BillingBilling contact, billing address, plan, invoice history. Card details are handled entirely by our payment processor, we never see or store full card numbers.
Usage and telemetryFeatures used, actions taken, timestamps, approximate location derived from IP, device/browser, log and error data
SupportCorrespondence with our team, and: with your permission, session recordings or screen shares used to diagnose an issue

4.3 Customer Content (we are processor)

DataExamples
Brand knowledge inputsWebsite content we scan at your direction, ICP and positioning notes, brand voice, proof points, uploaded documents, expert profiles
Expert and SME materialInterview responses, transcripts, and: where you enable it, audio recordings captured during a case study interview; review comments, claim verifications, and approvals
Content in progressIdeas, briefs, drafts, revisions, SEO and answer-engine scores, calendar entries, published output
Collaboration dataAssignments, comments, approval history, shared links

4.4 Connected integration data (role depends on the integration)

When you connect a third-party service, we receive only what the scopes you approve permit. See point 8 for detail.

IntegrationWhat we receive
Google Search ConsoleQuery, impression, click, position, and page-level performance data for properties you select
Google Analytics (GA4)Aggregated traffic and engagement metrics for properties you select
LinkedInProfile/page identifiers, access tokens, and publishing permissions for the accounts you authorize
Website / CMSPublishing credentials or API tokens, plus existing content we read to audit or update

4.5 Data we do not want

Please don't put special-category or sensitive data into eminnt, health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, precise geolocation, immigration status, government ID numbers, or financial account numbers. eminnt is not designed or configured for it, and doing so may breach your agreement with us.

We do not collect sensitive personal information in order to infer characteristics about anyone, and we never sell or share sensitive personal data, a point some US state laws, including Maryland's, address directly.

5. Why we use personal data, and our legal basis

Under the GDPR and UK GDPR we must have a legal basis for each purpose. Here they are.

PurposeLegal basis
Providing the eminnt platform and its featuresPerformance of a contract
Sending your content to an AI provider to generate the output you requestedPerformance of a contract
Creating and administering accounts, authentication, permissionsPerformance of a contract
Billing, invoicing, collectionsPerformance of a contract; legal obligation
Support, onboarding, integration setup (we are a managed software service)Performance of a contract; legitimate interests
Securing the service: abuse prevention, fraud detection, logging, backupsLegitimate interests; legal obligation
Improving the service through aggregated and de-identified usage analysisLegitimate interests
Direct marketing to business contactsConsent where required (EEA/UK); legitimate interests where permitted, always with an opt-out
Analytics, session recording, and advertising cookiesConsent
Responding to enquiries, demo requests, and assistant conversationsLegitimate interests; steps prior to entering a contract
Complying with law, responding to lawful requests, establishing or defending legal claimsLegal obligation; legitimate interests

6. AI, machine learning, and your content

This section states our commitments plainly, because it is the question every prospect asks.

We do not use your content to train AI models. Not our own models, and not third-party models. Brand knowledge inputs, uploaded documents, expert interviews, drafts, and published content are never used as training or fine-tuning data.

We only use AI providers that are contractually barred from training on your data. eminnt uses third-party large language model providers to power its features. It is our standing procurement requirement that any such provider is engaged under enterprise or API terms that (a) prohibit the use of customer inputs and outputs to train or improve their models, and (b) limit retention to what is needed to return a response and meet the provider's own abuse-monitoring obligations. We do not opt in to any programme, preview, or free tier that would permit training on your data. If we could not obtain those terms from a provider, we would not use that provider.

How your content reaches an AI model. When you run a feature that researches, drafts, optimizes, audits, or builds a case study, the relevant context from your workspace is sent to an AI provider to generate the output you asked for. It is processed to fulfil that request and returned to your workspace.

Content between customers is never mixed. One Customer's brand knowledge, proof, or drafts are never used to generate output for another Customer.

Human review. Our staff do not read Customer Content routinely. Access is limited to specific circumstances: you ask us for support and grant access; we need to investigate a security incident or suspected abuse; or the law requires it. Such access is role-restricted, granted on a least-privilege basis, and logged.

Automated decision-making. eminnt generates and scores content. It does not make decisions that produce legal or similarly significant effects about individuals, so the GDPR Article 22 rules on solely automated decision-making do not apply. Content and scores produced by eminnt are drafts and recommendations for a person to review, the expert review step exists precisely so a human stays in the loop.

AI transparency. Where the EU AI Act applies to us, we meet its transparency requirements:

  • Our website assistant tells you that you are interacting with an AI system, not a person.
  • Content produced by eminnt is AI-generated or AI-assisted, and our platform makes that visible to the people working on it. Customers remain responsible for reviewing, approving, and (where their own obligations or local law require it) disclosing AI involvement in what they publish.
  • We do not use AI to infer emotions, categorize people by biometric data, or perform any of the practices the AI Act prohibits.

Aggregated and de-identified data. We may create aggregated or de-identified statistics (such as how often a feature is used across all accounts) to operate and improve the service. This data cannot identify you or your organization, we maintain it in de-identified form, and we do not attempt to re-identify it.

7. Cookies and similar technologies

This section is our full cookie policy. eminnt.ai/cookies links here.

7.1 What cookies and similar technologies are

A cookie is a small text file a website stores on your device so it can recognize your browser on a later visit or later page. Cookies set by eminnt.ai are first-party; cookies set by another domain through content on our pages are third-party.

We also use a few things that behave like cookies:

  • Local storage: data held in your browser, similar to a cookie but not sent with every request.
  • Tags and pixels: small pieces of code, often loaded through a tag manager, that record that an event happened, such as a page view.
  • Session recording: a script that captures interaction events like mouse movement, clicks, and scrolling to reconstruct an anonymized playback of a visit. Ours is explained in point 7.5, because it deserves more than a line in a table.

Throughout this section, "cookies" means all of the above.

7.2 How we categorize them

CategoryWhat it doesConsent required
Strictly necessaryRuns the site: security, load balancing, and remembering your cookie choicesNo: the site can't work without them
FunctionalRemembers preferences such as language, and keeps the website assistant's conversation togetherYes
AnalyticsTells us which pages and campaigns work, and how people navigateYes
AdvertisingMeasures our LinkedIn and Meta ad campaigns and reaches relevant business audiencesYes

7.3 Strictly necessary

These cookies do not identify you and are not used for analytics or advertising. Because the exact names are set by our hosting and consent tooling and change when those tools are updated, we describe them by function, your browser's cookie inspector will always show you the current names, and our cookie settings panel lists them in full.

PurposeSet byTypical duration
Storing your cookie choices so we don't ask you again on every pageeminnt.aiUp to 12 months
Keeping your connection secure and routing your request to the right servereminnt.ai and our hosting providerSession
Balancing load and protecting the site from automated abuseOur hosting providerSession to 24 hours

7.4 Analytics: Google Analytics 4

We use Google Analytics 4 (property G-KG2TFHL1KS), loaded through Google Tag Manager (container GTM-TNSL3CJK), to understand how our site is used in aggregate.

CookieSet byPurposeDuration
_gaeminnt.ai (first-party)Distinguishes one browser from another so visits can be counted2 years
_ga_KG2TFHL1KSeminnt.ai (first-party)Maintains session state for this specific Analytics property2 years

7.5 Analytics and session recording: Microsoft Clarity

We use Microsoft Clarity (project xsy9cp47q1) to see how visitors actually experience our pages, where they hesitate, what they click, where they give up.

What this means in practice: Clarity records interaction events during your visit (mouse movement, clicks, scrolling, and page navigation) and reconstructs them as a playback, together with heatmaps showing where visitors click and how far they scroll. This is more intrusive than counting page views, so we're describing it plainly rather than burying it in a table.

CookieSet byPurposeDuration
_clckeminnt.ai (first-party)Keeps a persistent Clarity user ID so repeat visits can be linked1 year
_clskeminnt.ai (first-party)Links the page views within a single visit into one recording1 day
CLID, MUID, ANONCHK, SM, MRMicrosoft (clarity.ms, c.bing.com)Third-party identifiers Microsoft uses to operate ClaritySession to 1 year

7.6 Advertising

We use advertising tags to measure whether our campaigns work and to reach relevant business audiences.

These tags load only after you consent to advertising cookies. If you decline, or have not consented, none of the cookies below are set and no data about your visit reaches LinkedIn or Meta. You can withdraw consent at any time from Cookie settings in our footer.

LinkedIn Insight Tag

CookieSet byPurposeDuration
li_fat_ideminnt.ai (first-party)Indirect member identifier used for conversion tracking and retargeting30 days
bcookielinkedin.com (third-party)Browser identifier1 year
bscookielinkedin.com (third-party)Secure browser identifier used for authentication features1 year
lidclinkedin.com (third-party)Routes the request to the right LinkedIn data centre1 day
li_sugrlinkedin.com (third-party)Probabilistic browser matching90 days
UserMatchHistorylinkedin.com (third-party)Synchronizes LinkedIn Ads identifiers30 days
AnalyticsSyncHistorylinkedin.com (third-party)Records when a sync with lms_analytics occurred30 days
lms_ads / lms_analyticslinkedin.com (third-party)Identifies LinkedIn members off LinkedIn for advertising and analytics30 days
li_gclinkedin.com (third-party)Stores consent for non-essential cookies6 months
CookieSet byPurposeDuration
_fbpeminnt.ai (first-party)Identifies a browser so Meta can attribute a conversion to an ad3 months
_fbceminnt.ai (first-party)Stores the click identifier from a Meta ad you arrived from3 months
frfacebook.com (third-party)Encrypted account and browser identifier used to deliver and measure ads3 months

7.7 Functional

PurposeSet byStored asDuration
Keeping your conversation with our website assistant connected as you move between pageseminnt.ai and our assistant providerCookie or browser local storageFor the conversation, and up to 30 days so you can pick it up again
Remembering interface preferences such as languageeminnt.aiCookieUp to 12 months

7.8 How to control cookies

On our site. Use the Cookie settings link in the footer to review and change your choices at any time. We ask before setting anything beyond strictly necessary cookies, and withdrawing consent is as easy as giving it.

Global Privacy Control. We honour the GPC browser signal as an opt-out of sale and sharing, and of targeted advertising, wherever it is offered, not only in the states that require us to. We do not respond to the older "Do Not Track" header, because no common standard for it was ever agreed.

In your browser. You can block or delete cookies in your browser settings, Chrome, Safari, Firefox, Edge. Blocking strictly necessary cookies will break parts of the site.

Opting out of specific tools.

  • Google Analytics: the browser opt-out add-on.
  • Microsoft Clarity: the choices Microsoft offers in its privacy statement, and declining analytics cookies here.
  • LinkedIn: your LinkedIn ad settings.
  • Meta: your Meta ad preferences and off-Facebook activity settings.

Declining cookies here stops these tags from firing on our site in the first place, which is the more complete option.

8. Third-party APIs and integrations

You choose which services to connect. We ask for the narrowest scopes that make the feature work, and you can disconnect at any time from your eminnt settings, which revokes our access going forward.

8.1 Google API Services: Limited Use disclosure

eminnt connects to Google Search Console and Google Analytics so our performance reporting and SEO audit features can show you how your content is doing.

eminnt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We use Google user data only to provide and improve the features you connected it for.
  • We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or to comply with applicable law.
  • We do not use Google user data for advertising.
  • We do not allow humans to read Google user data unless we have your explicit consent, it is necessary for security or to comply with law, or the data has been aggregated and de-identified.
  • We do not use Google user data to develop, improve, or train generalized AI or machine learning models.

You can revoke eminnt's access at any time in your Google Account permissions.

8.2 LinkedIn publishing

When you authorize LinkedIn, we receive the profile or page identifiers and publishing permissions needed to post reviewed content on your behalf. We use this only for publishing and the reporting tied to it, and never to build a profile of you or to contact your connections. Revoke access in your LinkedIn account settings or in eminnt.

8.3 Website and CMS connections

To publish to your site, we store the credentials or API tokens you provide, encrypted. We use them only to read content you ask us to audit and to publish or update content you have approved.

8.4 Advertising platforms: LinkedIn and Meta

We advertise on LinkedIn and Meta, and we place their measurement tags on our marketing pages so we can tell which campaigns work. These tags are set only if you consent to advertising cookies; the specific cookies, durations, and opt-outs are in point 7.6.

Joint controllership. In the EEA and UK, we and each platform act as joint controllers for the collection of data through their tag and its use for audience building and campaign reporting, LinkedIn under its Ads joint-controller arrangement, Meta under its Business Tools terms. Each platform is solely responsible for what it subsequently does with that data under its own privacy policy. You can exercise your rights against either us or the platform; contact us at privacy@eminnt.ai and we will help you reach the right place. The essence of each arrangement is available from the platform, and we will send you our copy on request.

We do not send your contact details to these platforms. Meta's Advanced Matching, which would transmit hashed email addresses and phone numbers, is switched off.

8.5 LinkedIn Lead Gen Forms

If you submit a Lead Gen Form attached to one of our LinkedIn ads, that form is hosted by LinkedIn, not by us, and is pre-filled from your LinkedIn profile. When you submit it, LinkedIn passes us the details you agreed to share, typically name, work email, job title, and company, plus answers to any questions we added.

We receive that data in LinkedIn Campaign Manager and our CRM, and handle it exactly as we handle any other demo or contact request: to respond to you and, where permitted, to send you relevant marketing you can opt out of at any time. We become the controller of that data once we receive it. LinkedIn's handling before that point is governed by the LinkedIn Privacy Policy.

To have it deleted, email privacy@eminnt.ai.

8.6 Other third-party services

Services you connect to are controlled by you and governed by their own privacy policies. We encourage you to read them. We are not responsible for how those services handle data once it leaves eminnt at your instruction.

9. How we share personal data

We do not sell personal data. We share it only in these situations:

Sub-processors and service providers. Vendors that help us run eminnt, each under a written contract requiring confidentiality, appropriate security, and processing only on our instructions.

Advertising and analytics partners. Where you consent to advertising cookies, LinkedIn and Meta receive online identifiers and browsing activity from our marketing pages, so we can measure campaigns and build audiences. In the EEA and UK we are joint controllers with each platform for that collection (see point 8.4. In the US this is "sharing" or "targeted advertising") see point 17. Google and Microsoft receive analytics data on the same consent basis.

Within Tkxel. eminnt is operated by Tkxel. Tkxel personnel (engineering, support, security) may access data where needed to run the service, under the same restrictions described in this policy. See point 10.4.

At your direction. To services you connect, or to people you share content with.

Legal and safety. Where we must comply with law, a court order, or a valid government request; or to protect the rights, property, or safety of eminnt, our Customers, or the public. We assess every request for validity and scope, we push back on requests that are overbroad, and we will notify affected Customers of legal requests unless legally prohibited from doing so.

Business transfers. If eminnt or Tkxel is involved in a merger, acquisition, financing, or sale of assets, personal data may transfer as part of that transaction. We will notify you, and the recipient will remain bound by this policy or give notice before materially changing it.

10. Our sub-processors

This section is our sub-processor disclosure. eminnt.ai/subprocessors links here.

Last updated: 13 August 2026.

Every sub-processor is subject to due diligence before onboarding and a written contract requiring confidentiality, appropriate technical and organizational security measures, processing only on our documented instructions, and (where personal data leaves the EEA or UK) Standard Contractual Clauses or another valid transfer mechanism. We remain responsible to you for their performance.

Below, we name in full every third party that processes data from our public website and marketing (point 10.3), because you can see those in your browser and you are entitled to know who they are. For the platform sub-processors that may touch Customer Content (point 10.2), we set out each one's role, the data involved, and our commitments; the complete list of named vendors, with entity details and processing locations, forms part of our Data Processing Agreement and is available to Customers and to anyone evaluating eminnt, just email privacy@eminnt.ai and we will send it. We do this because that list changes as the product matures, and a stale name on a web page is worse than a current one you can actually rely on contractually.

10.1 Notice of changes

We may add or replace sub-processors as the product evolves.

Customers with a Data Processing Agreement receive advance notice. We give at least 30 days' notice, by email to the notice contact your organization nominated in the DPA, before a new sub-processor starts processing Customer Content. If you have a reasonable, documented objection on data protection grounds, tell us within 15 days and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.

Changes to the website and marketing vendors in point 10.3 are recorded in the change log at point 10.5 and reflected on this page.

10.2 Platform sub-processors

Categories of provider that may process Customer Content, your brand knowledge, documents, expert interviews, drafts, and connected-account data. Named vendors are listed in our DPA and available on request from privacy@eminnt.ai.

CategoryPurposeData processedLocation
Cloud infrastructure and databasePrimary application hosting, compute, and data storageAccount data, Customer ContentUnited States
Application hosting and edge delivery: Vercel Inc.Hosting, edge network, and delivery for eminnt.ai and the applicationRequest metadata, IP addresses, log dataUnited States (origin region iad1), global edge network
Large language model providersPowers the research, drafting, optimization, audit, and case study featuresPrompts and context drawn from Customer ContentUnited States
Workflow orchestrationRuns long-running jobs such as site auditsJob metadata, Customer Content in transitUnited States
Error monitoring and observabilityDiagnostics and reliabilityLog data, error traces, limited account identifiersUnited States
Product analyticsUnderstanding in-product feature usageUsage events, account identifiersUnited States
Transactional email deliveryInvitations, notifications, password resetsName, email address, message contentUnited States
Payment processingBilling and invoicingBilling contact and address; card data handled entirely by the processor, never by usUnited States
Support toolingSupport tickets and correspondenceName, email, ticket contentUnited States

10.3 Website and marketing sub-processors

Named in full. These providers process data from our public website and marketing activity, and do not touch Customer Content.

ProviderPurposeData processedEntity location
Vercel Inc.Hosting and delivery of eminnt.aiRequest metadata, IP addressesUnited States
Google LLCGoogle Analytics 4 (G-KG2TFHL1KS) and Google Tag Manager (GTM-TNSL3CJK)Pseudonymous identifiers, page views, approximate location derived from IP, device and browser dataUnited States
Google LLC (Workspace)Business email and productivity for our domainsEmail correspondence, contact detailsUnited States
Microsoft CorporationMicrosoft Clarity (xsy9cp47q1): heatmaps and session recordingInteraction events, clicks, scroll depth, pseudonymous identifiers, session recordingsUnited States
LinkedIn (LinkedIn Corporation / LinkedIn Ireland ULC)Insight Tag: ad delivery, conversion measurement, audience building. Lead Gen Forms, collects your profile details on LinkedIn and passes them to usPseudonymous identifiers, browsing activity, conversion events; for Lead Gen Forms: name, work email, job title, companyUnited States / Ireland
Meta (Meta Platforms, Inc. / Meta Platforms Ireland Ltd)Meta Pixel: ad delivery and conversion measurementPseudonymous identifiers, browsing activity, conversion eventsUnited States / Ireland
CRM and marketing automationManaging prospect and customer relationships, marketing emailName, work email, company, engagement historyUnited States
Website assistant providerThe assistant on eminnt.aiConversation transcripts, any contact details you provideUnited States
Consent management platformRecording and honouring your cookie consentConsent choices, pseudonymous identifierUnited States

10.4 Tkxel personnel and international access

eminnt is a product created and owned by Tkxel, an international company. Tkxel personnel in engineering, support, and security may access personal data where necessary to operate and support the service, and some of those personnel are located outside the United States, including in countries that do not have a European Commission adequacy decision.

We treat that access as an international data transfer and protect it accordingly:

  • it is covered by the Standard Contractual Clauses and UK Addendum described in point 11;
  • it is role-restricted, granted on a least-privilege basis, time-limited where possible, and logged;
  • everyone with access is bound by written confidentiality obligations and receives data protection training;
  • access to Customer Content specifically is limited to the circumstances in point 6 ("Human review").

If you are evaluating eminnt and need the current list of countries from which our personnel access data (a routine question in enterprise security reviews, and a fair one) email privacy@eminnt.ai and we will tell you.

10.5 Change log

DateChange
13 August 2026Initial publication.

11. International data transfers

We are based in the United States and use service providers and personnel in several countries. If you are in the EEA, the UK, or Switzerland, your personal data will be transferred outside your region.

We rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, together with the UK International Data Transfer Addendum and, for Switzerland, the FDPIC-recognized adaptations, in our contracts with Customers, sub-processors, and intra-group recipients;
  • Transfer impact assessments where required, together with supplementary technical and organizational measures, including encryption in transit and at rest, access logging, and a policy of challenging overbroad government requests;
  • Adequacy decisions, where the destination country has one.

We do not currently rely on the EU–US Data Privacy Framework for these transfers; our safeguards stand on the Standard Contractual Clauses and the measures above.

To request a copy of the relevant safeguards, email privacy@eminnt.ai.

12. How long we keep personal data

We keep personal data only as long as we need it for the purposes in this policy, or as long as the law requires.

DataRetention
Account and Customer ContentFor the life of the account. On termination you have 30 days to export your Customer Content; we then delete or de-identify it within a further 30 days (so no later than 60 days after termination) subject to your agreement and to any legal hold
BackupsPurged on our standard backup cycle, within 90 days of deletion from live systems
Billing and tax recordsAs required by US tax and accounting law: 7 years
Marketing contactsUntil you unsubscribe or ask for deletion, or after 24 months of no engagement
Website analytics (Google Analytics 4)14 months
Session recordings and heatmaps (Microsoft Clarity)Deleted on Microsoft's standard Clarity retention cycle; we do not export, download, or separately store recordings
Security and access logs12 months
Support correspondence24 months after the ticket closes
Demo requests and prospect records that do not convert24 months
Consent records24 months from the date consent was given or last updated, so we can demonstrate it
CookiesAs stated per cookie in point 7

13. Security

We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, and disclosure, proportionate to the risk. These include:

  • Encryption in transit (TLS) and at rest;
  • Access control: role-based permissions, least privilege, multi-factor authentication for staff, logged administrative access;
  • Tenant isolation so one Customer's workspace cannot be accessed from another;
  • Encrypted storage of integration tokens and credentials;
  • Monitoring and logging, with alerting on anomalous activity;
  • Backups and tested recovery procedures;
  • Vendor due diligence before onboarding any sub-processor;
  • Confidentiality obligations and security training for everyone with access;
  • Change management and code review before changes reach production;
  • Periodic review and testing of our controls, including third-party testing of the application before significant releases.

On certifications. We describe only the controls we actually operate, and we do not claim certifications we do not hold or list ones that are merely in progress. Our infrastructure runs on established cloud providers that maintain independently audited security programmes. If you need our current security documentation for a vendor review (architecture, controls, sub-processor list, or a completed questionnaire) email security@eminnt.ai and we will send you what we have, with an honest account of what we do not.

Reporting a vulnerability. If you believe you have found a security issue in eminnt, email security@eminnt.ai. We will acknowledge your report, keep you updated, and will not pursue legal action against anyone who reports a genuine issue in good faith and does not access, alter, or retain other people's data while doing so.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential and for who you invite into your workspace.

14. Data breach notification

If a personal data breach occurs:

  • Where we act as controller and the breach is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, we will notify affected individuals directly, unless the data was rendered unintelligible (for example, by strong encryption) or notification would involve disproportionate effort, in which case we will make a public communication instead.
  • Where we act as processor, we will notify the affected Customer without undue delay after becoming aware, so they can meet their own obligations, and we will support their investigation and notification.
  • We will notify US state authorities and residents as required by applicable state breach-notification laws, including those of Virginia and California.

We maintain an internal record of breaches and our response to them, whether or not they are notifiable.

15. Children

eminnt is a business tool for adults. Our Terms of Service require users to be at least 18. We do not knowingly collect personal data from anyone under 18, we do not direct any part of our service or marketing at children, and we do not sell or share the personal information of anyone we know to be under 16. If you believe a child has provided us personal data, email privacy@eminnt.ai and we will delete it.

16. Your rights under the GDPR and UK GDPR

If you are in the EEA, the UK, or Switzerland, you have the following rights over personal data for which we are the controller.

16.1 Right of access. You can ask whether we process your personal data and, if so, receive a copy along with the purposes, the categories involved, who we share it with, how long we keep it, and where we obtained it. The first copy is free; we may charge a reasonable administrative fee for further copies, or for manifestly unfounded or excessive requests.

16.2 Right to rectification. You can ask us to correct inaccurate personal data and to complete incomplete data.

16.3 Right to erasure ("right to be forgotten"). You can ask us to delete your personal data where: it is no longer necessary for the purpose it was collected; you withdraw the consent we relied on and there is no other basis; you object and there is no overriding legitimate ground; it was processed unlawfully; or the law requires deletion. This right is not absolute, we may keep data where we must for legal claims or legal obligations.

16.4 Right to restriction of processing. You can ask us to restrict processing where: you contest the accuracy of the data (for as long as it takes us to verify); the processing is unlawful but you prefer restriction to deletion; we no longer need the data but you need it for legal claims; or you have objected and we are assessing whether our grounds override yours.

16.5 Right to data portability. Where processing is based on consent or on a contract and is carried out by automated means, you can receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible. We may decline where doing so would adversely affect the rights of others.

16.6 Right to object. You can object at any time to processing based on legitimate interests, on grounds relating to your particular situation. You can object to direct marketing at any time, for any reason, and we will stop.

16.7 Right to withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

16.8 Right to lodge a complaint. See point 19.

How to exercise these rights. Email privacy@eminnt.ai. We will respond within one month, extendable by two further months for complex requests, we will tell you if we need the extension and why. We may need to verify your identity first; we will only ask for what is necessary to do so, and we will not use that information for anything else. Exercising your rights is free of charge in normal circumstances, and we will not treat you differently for having done so.

17. Your rights in the United States

A growing number of US states have comprehensive privacy laws, and the list changes every few months. Rather than maintain a state-by-state table that goes out of date, we extend the rights in this section to every US resident, whatever state you live in and whether or not your state's law requires it.

Those rights are to:

  • Know what personal information we collect, the sources, the purposes, how long we keep it, and the categories of third parties we disclose it to;
  • Access a copy of the specific pieces of personal information we hold about you;
  • Correct inaccurate personal information;
  • Delete personal information, subject to exceptions we will explain if they apply;
  • Obtain a portable copy in a usable format;
  • Opt out of the sale or sharing of personal information and of targeted advertising;
  • Limit the use of sensitive personal information, though as point 4.5 explains, we do not use it in the ways that trigger this right;
  • Appeal if we deny a request (see below);
  • Non-discrimination: we will not deny service, charge a different price, or provide a lesser quality of service because you exercised a right.

Categories collected. In the past 12 months we have collected the following categories: identifiers; commercial information; internet or other electronic network activity; professional or employment-related information; approximate geolocation derived from IP; and inferences drawn from the above. We collect these from you, from your device, from your connected integrations, and from our service providers. We disclose them to the recipients in point 9 and point 10, for the business purposes in point 5, and we retain them for the periods in point 12.

Sensitive personal information. We do not collect sensitive personal information in order to infer characteristics, we do not sell or share it, and we do not use or disclose it beyond the purposes permitted by law. Account credentials are collected solely to authenticate you.

Sale and sharing. We do not sell personal information for money, and we never have.

We do, however, share personal information for cross-context behavioral advertising (what other states call targeted advertising) when, and only when, you consent to advertising cookies. Our LinkedIn Insight Tag and Meta Pixel transmit online identifiers and browsing activity to those platforms so we can measure our campaigns and reach relevant business audiences. Under California law that is "sharing", and we are telling you so plainly rather than hiding behind the fact that no money changes hands.

  • Categories shared: identifiers (including cookie IDs and device identifiers) and internet or other electronic network activity.
  • Shared with: LinkedIn and Meta, for cross-context behavioral advertising.
  • How to opt out: the "Do Not Sell or Share My Personal Information" link in our footer, our Cookie settings panel, or a Global Privacy Control signal, any of which stops these tags from firing. Because these tags require your opt-in consent in the first place, simply declining advertising cookies has the same effect.

We do not sell or share the personal information of anyone we know to be under 16.

A note on business contact data. Most of the personal information we hold is business contact data, your work email, job title, and employer. Several state privacy laws exclude that data from their scope; California's does not. We apply this section to it either way.

Authorized agents. You may use an authorized agent to submit a request, provided they give us written proof of authorization and we can verify your identity.

How to submit a request. Email privacy@eminnt.ai. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you.

How to appeal. If we deny your request, reply to our decision with "Appeal" in the subject line. We will review it and respond within 60 days. If we deny the appeal, we will tell you how to complain to your state attorney general.

If your data sits inside a Customer's workspace. If your personal information is in a Customer's eminnt account (because you were interviewed, quoted, or named) that Customer is the business or controller. Direct your request to them; see point 3.

18. Changes to this policy

We may update this policy as the product, our vendors, or the law change. When we do, we will update the "Last updated" date at the top.

If the change is material: a new purpose, a new category of sharing, a new category of data, a reduction in your rights, or a change in who we are, we will give you reasonable advance notice by email or in-product before it takes effect, and where the law requires consent for the new processing, we will ask for it rather than assume it.

Sub-processor changes are tracked separately in point 10.5 with their own dated change log and their own notice commitment in point 10.1, so routine vendor updates don't require you to re-read the whole policy.

We keep previous versions of this policy and will send you any of them on request.

19. Complaints, questions, and supervisory authorities

Contact us first. We would rather fix a problem than have you escalate it.

Privacy, data rights, and DPA requests: privacy@eminnt.ai Security questionnaires and vulnerability reports: security@eminnt.ai General enquiries: hello@eminnt.ai Post: Tkxel, 11921 Freedom Drive, Reston, Virginia 20190, United States

Who is accountable. privacy@eminnt.ai reaches the person at Tkxel responsible for data protection, and it is monitored. We have not appointed a Data Protection Officer under Article 37 of the GDPR, because our processing does not meet the criteria that require one we are not a public authority, and neither large-scale systematic monitoring of individuals nor large-scale processing of special category data is a core activity of ours. If that changes, we will appoint one and name them here.