Privacy Policy
Last Updated: August 9, 2026
Version 2.2.0 · Effective Date: August 9, 2026
GDPR & UK GDPR
EU/EEA & UK data protection rights
CCPA / CPRA
California consumer rights honored
B2B Transparent
Plain-language data handling
Operator & Data Controller
- ShiftNode Digital s.r.o. (operator of the EM3A service at em3a.ai)
- Registered office: Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
- Company ID (IČO): 249 06 123
- Privacy contact: privacy@em3a.ai
- Legal / procurement contact: legal@em3a.ai
English legal version controls. Localized routes may include summaries for visitor convenience, but the English text controls unless a separately signed agreement says otherwise.
1. Introduction
This Privacy Policy explains how ShiftNode Digital s.r.o. ("we," "our," or "us"), the operator of the EM3A service available at em3a.ai (the "Service"), collects, uses, protects, retains, and shares personal data when you visit the marketing site, request the free Intelligence Brief, create an account, use free or paid features, integrate third-party tools, or contact us.
EM3A is a B2B intelligence platform intended for use by businesses and their authorized personnel. We process personal data in compliance with the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and applicable Czech data protection law.
2. Controller and Contact Details
Controller: ShiftNode Digital s.r.o.
Registered office: Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
Company ID (IČO): 249 06 123
Privacy contact: privacy@em3a.ai (mirrored to privacy@shiftnodedigital.com)
Legal / procurement contact: legal@em3a.ai
We are not required to appoint a Data Protection Officer under GDPR Article 37, but the privacy contact above is the single point of contact for all privacy and data subject rights requests.
We are the controller where we decide the purposes and means of processing (for example, marketing, account management, billing, and the business contact data our research surfaces from public sources on our own legitimate-interest basis — see section 4). In some customer engagements we act as a processor for personal data that the customer uploads or imports into EM3A — that processing is governed by our Data Processing Agreement.
3. Personal Data We Process
Depending on how you interact with the Service, we may process:
- Account data: name, business email, password hash, company name, role, profile photo, locale, timezone.
- Billing data: billing address, VAT ID, and invoice history for enterprise workspace agreements. Billing is handled by contract and invoice; we do not collect or store payment card details.
- Usage & telemetry: pages viewed, features used, credit consumption, API/MCP calls, device type, browser, approximate location derived from IP address, error logs.
- AI prompts and outputs: the queries you submit to EM3A workers, the AI-generated responses returned to you, and associated metadata needed to reproduce or improve the result.
- Voice-rehearsal data: when you expressly start the optional Sales Simulator, live microphone audio, an AI-generated buyer voice, transcript turns, call duration, and technical quality metadata. The provider receives an opaque session identifier rather than your account identity.
- Public-signal inputs: company URLs, project keywords, sector filters, and other instructions you provide that drive public-web research.
- Discovered B2B contact data: work emails, job titles, professional profiles, and company affiliations surfaced from public sources or from licensed enrichment providers, processed on behalf of you as the customer.
- Customer-imported data: CRM contacts, prospect lists, uploaded documents, and other personal data that you choose to bring into the platform.
- Lead-magnet submissions: the email, company, and targeting information you submit to receive the free Intelligence Brief PDF.
- Communications: support tickets, sales conversations, survey responses, and webinar registrations.
- Marketing & analytics: consent records, cookie preferences, campaign attribution, and email engagement signals.
We do not intentionally collect special-category personal data (GDPR Article 9), government identifiers, payment card numbers, children's data, or precise geolocation. Please do not submit such data through the Service unless a signed agreement specifically authorizes it.
4. Purposes and Legal Bases
- Providing the Service (Art. 6(1)(b) — contract): creating and managing your account, delivering features you request, processing AI workflows, generating reports, billing, and customer support.
- B2B prospect discovery (Art. 6(1)(f) — legitimate interest): we process publicly available business contact data so customers can identify appropriate professional contacts. A documented balancing test concluded that the limited business-context processing, combined with opt-out and suppression mechanisms, does not override the rights of data subjects. Individuals may object at any time via privacy@em3a.ai.
- Security & abuse prevention (Art. 6(1)(f)): logging, rate limiting, fraud detection, and incident investigation.
- Product analytics & improvement (Art. 6(1)(f) or consent): aggregated, where possible de-identified usage analysis to improve quality and performance.
- Marketing communications (consent or Art. 6(1)(f) for existing customers): product updates, newsletters, and event invitations. You can unsubscribe at any time.
- Lead-magnet delivery (Art. 6(1)(b) — pre-contract step at your request): sending the Intelligence Brief and related follow-up that you requested when submitting the form.
- Compliance with legal obligations (Art. 6(1)(c)): tax, accounting, anti-money-laundering, and responses to lawful authority requests.
5. AI-Assisted Processing
EM3A uses large language models and grounded-search providers to generate intelligence outputs. Provider categories currently include:
- Hosted AI gateway routing requests to multiple model providers.
- Grounded web-search providers used for cited research.
- Web-scraping providers used to extract content from public URLs.
- A realtime voice provider used only when an authorized user starts the Sales Simulator. The simulated buyer is disclosed as AI and does not imitate a real contact.
We instruct providers contractually not to use customer prompts or outputs to train their base models, and we do not authorize such training. Outputs are informational business-support material — they may contain errors, omissions, or outdated assumptions and are not legal, financial, procurement, security, or investment advice. A human must review AI-generated content before relying on it for decisions.
We do not use AI to make decisions that produce legal or similarly significant effects about individuals without meaningful human review (GDPR Article 22).
6. Sharing and Sub-Processors
We do not sell personal data. We share data only where necessary to operate the Service, deliver requested features, or comply with law. Sub-processor categories include:
- Cloud hosting, database, storage, and edge-function infrastructure.
- Email delivery (transactional and marketing).
- Invoicing, tax, and accounting tooling.
- AI model providers and grounded-search providers (see section 5).
- Realtime speech, synthetic voice, and transcription for voice rehearsals.
- Analytics, product telemetry, and error monitoring.
- Demo scheduling for visitors who request a sales conversation.
- CRM and customer-support tooling.
- Accounting, tax, legal, and professional advisers.
The specific sub-processors we engage are listed in Annex 3 of our Data Processing Agreement; processing locations and transfer mechanisms are available on request from privacy@em3a.ai. We provide advance notice of material sub-processor changes as described in the DPA.
7. International Transfers
Some providers may process personal data outside the European Economic Area or the United Kingdom. Where this happens we rely on appropriate safeguards, including:
- European Commission adequacy decisions where available.
- EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 or 3 as applicable.
- The UK International Data Transfer Addendum to the EU SCCs.
- The Swiss addendum where Swiss data is involved.
- The EU-US Data Privacy Framework for certified US providers.
- Supplementary technical and organizational measures (encryption in transit, pseudonymization, access controls) where appropriate.
8. Retention
We retain personal data only as long as needed for the purpose, unless a longer period is required by law:
- Account & usage data: while your account is active and for up to 24 months after closure for security, abuse-prevention, and dispute purposes.
- AI prompts and outputs: retained per workspace settings; deleted on account closure unless needed for legal claims.
- Sales Simulator data: EM3A retains the transcript and evidence-only coaching under the configured platform retention period, currently 90 days. ElevenLabs provider-side audio storage is disabled and provider-side transcripts are configured for deletion after one day; short-lived signed webhook payloads are scrubbed after processing.
- Lead-magnet submissions and marketing contacts: until you unsubscribe, withdraw consent, or object — with a suppression record retained to honor your opt-out.
- Support tickets: up to 36 months after resolution.
- Invoices, contracts, accounting records: up to 10 years as required by Czech tax and commercial law.
- Security and access logs: typically 12 months, longer for incident investigations.
9. Your Rights (GDPR & UK GDPR)
Subject to applicable law you may:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure where legally available;
- request restriction of processing;
- object to processing based on legitimate interests or direct marketing;
- request portability of data you provided;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a supervisory authority, including Úřad pro ochranu osobních údajů (ÚOOÚ), Czech Republic — www.uoou.cz or Information Commissioner's Office (ICO), United Kingdom — www.ico.org.uk.
To exercise your rights, email privacy@em3a.ai. We respond within one month and may extend by two further months for complex requests. We may require proof of identity before acting.
10. Your Rights (California — CCPA/CPRA)
If you are a California resident, you have the right to know, delete, correct, and limit use of your personal information, and to opt out of "sale" or "sharing" as defined by the CCPA. We do not sell personal information for monetary consideration. We do not "share" personal information for cross-context behavioral advertising unless you have given consent through our cookie banner.
We honor browser-based opt-out signals such as the Global Privacy Control (GPC) for cookie-based sharing. To submit a verifiable consumer request, email privacy@em3a.ai. We will not discriminate against you for exercising any CCPA right. You may complain to the California Attorney General — oag.ca.gov/privacy.
11. Cookies and Tracking
See our Cookie Policy for the categories of cookies we use, the third parties involved, and how to manage your preferences. You can reopen cookie settings at any time from the footer.
12. Children
The Service is intended for business users aged 16 or older. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact privacy@em3a.ai and we will delete it.
13. Security
We use technical and organizational measures designed to protect personal data, including HTTPS/TLS in transit, encryption at rest provided by our cloud infrastructure, row-level security in our database, role-based access control, mandatory MFA for administrative access, least-privilege operational practices, audit logging, and provider-level security controls. Our security posture is inspired by, but does not currently claim certification under, ISO/IEC 27001 or SOC 2.
No internet service is completely secure. If you believe data connected to EM3A has been exposed or misused, contact security@em3a.ai.
14. Breach Notification
We notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, where required by GDPR Article 33. Where the breach is likely to result in a high risk to affected individuals, we notify those individuals as required by GDPR Article 34. Customer notifications for processor-side breaches are governed by our DPA.
15. Changes to this Policy
We may update this Privacy Policy when our services, providers, legal obligations, or processing activities change. We will post the updated version with a new "Last Updated" date and, for material changes, notify customers by email or in-product banner.
16. Contact
ShiftNode Digital s.r.o.
Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
Privacy: privacy@em3a.ai
Legal: legal@em3a.ai
Security: security@em3a.ai