Privacy Policy
Version 2.1 — effective 2 October 2026
1. Introduction
Eurobase ("we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website at eurobase.app (the "Website") or use our backend-as-a-service platform (the "Service").
As a European-operated platform, we are fully committed to compliance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and other applicable European data protection laws.
2. Data Controller
The data controller responsible for the processing of your personal data is:
Eurobase OÜ
Ahtri 12, Tallinn 15551
Registry number: 17557586
VAT: Not VAT-registered (below Estonian €40,000 threshold)
E-Mail: contact@eurobase.app
Data Protection Officer: dpo@eurobase.app
3. Data We Collect
3.1 Website Visitors
When you visit our Website, we may collect:
- IP address (anonymized where possible)
- Browser type and version
- Operating system
- Referral source and page visit history
- Date and time of access
3.2 Signup
When you create an account, we collect:
- Email address
- Password (stored only as a bcrypt hash)
- Timestamp, IP address, and User-Agent of your click-through acceptance of the Terms and DPA (recorded to the
legal_acceptancestable for the audit trail required under GDPR Article 7)
3.3 Platform Users
When you use the Eurobase Service, we additionally process:
- Account information (display name, organisation, if provided)
- Session tokens issued on sign-in
- Usage data and service logs (retained per the retention schedule below)
- Billing information — processed by Mollie B.V. (Netherlands, EU) once paid tiers are active
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
- Consent (Art. 6(1)(a)): For marketing communications, the onboarding email drip, and any optional analytics.
- Contractual necessity (Art. 6(1)(b)): To provide the Service you requested.
- Legitimate interest (Art. 6(1)(f)): For platform security, fraud prevention, and service improvement.
- Legal obligation (Art. 6(1)(c)): To comply with applicable tax and commercial laws under Estonian and EU law.
5. Data Storage & Sovereignty
All personal data is stored exclusively on European infrastructure operated by EU-owned providers. We do not transfer personal data to countries outside the European Economic Area (EEA) in the ordinary course of providing the Service. Our infrastructure providers (Scaleway, France) are selected specifically to ensure EU-only data residency.
6. Data Retention
We retain your personal data only for as long as necessary for the purposes outlined in this policy. Specifically:
- Website access logs: 90 days
- Waitlist entries: until the public launch or until you request deletion
- Account data: for the duration of your account plus 30 days after deletion
- Billing data: as required by Estonian commercial and tax law (up to 7 years for accounting records)
- Legal-acceptance audit rows: 6 years, matching the GDPR Article 7 evidence window
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of your personal data
- Right to rectification (Art. 16): Correct inaccurate personal data
- Right to erasure (Art. 17): Request deletion of your personal data
- Right to restrict processing (Art. 18): Limit how we use your data
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)): Withdraw consent at any time without affecting prior processing
To exercise any of these rights, contact dpo@eurobase.app. We will respond within 30 days.
8. Cookies
Our Website uses only technically necessary cookies to ensure proper functionality. We do not use tracking cookies, advertising cookies, or third-party analytics tools that process personal data outside the EU. If we introduce optional cookies in the future, we will obtain your explicit consent before setting them.
9. Sub-processors
We use the following sub-processors, all of which are EU-based or contractually bound by EU-adequate transfer mechanisms:
- Scaleway SAS (France) — hosting, storage, transactional email, compute, Redis
- Mollie B.V. (Netherlands) — billing (once paid tiers are active)
- Google LLC (US) and GitHub Inc. (US) — OAuth identity verification, only if you choose to sign in via those providers; covered by the EU-US Data Privacy Framework
The current sub-processor list is available on request from dpo@eurobase.app; a self-service copy will be published at /sub-processors alongside the general-availability launch. We notify existing customers 30 days before adding or replacing a sub-processor.
10. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay, in accordance with GDPR Articles 33 and 34.
11. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. Given our establishment in Estonia, the competent authority for us is:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39
10134 Tallinn, Estonia
www.aki.ee/en
You may also lodge a complaint with the supervisory authority in the EU Member State where you habitually reside.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email at least 30 days before they take effect and by updating the version at the top of this page.
13. Contact
For questions about this Privacy Policy or your personal data, contact us at:
Eurobase OÜ
Ahtri 12, Tallinn 15551
General: contact@eurobase.app
Data protection: dpo@eurobase.app