Privacy Policy

Version 2.0Last updated: 29 July 2026Effective: 29 July 2026

This Privacy Policy explains how SharpAgent OÜ ("Sharpagent", "we", "us") collects, uses, and protects personal data when you visit sharpagent.io, book a call, or engage our services. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Estonian Personal Data Protection Act.

1. Who we are

SharpAgent OÜ, a private limited company registered in Estonia. Contact: hello@sharpagent.io.

2. What we collect

  • Contact data you submit through forms, the Sharpie chat, or the booking flow: name, email, phone (optional), company, budget range, and the message or brief you share.
  • Booking data: selected date and time, time zone, and any notes you add.
  • Technical data: standard server logs generated when you load the site (request URL, timestamp, device and browser type). We do not run third-party analytics or advertising trackers.
  • Cookies and similar technologies: see our Cookie Policy.
  • Website Audit data: the URL you submit, publicly available content of that page retrieved by our scanner, the generated scores and issue list, and a truncated/hashed IP address used for rate limiting. If you purchase the full report we also process your name and email address.
  • Payment data: purchases are processed by Stripe. Card, Apple Pay, Google Pay, PayPal and Link are offered where your device, browser and Stripe support them. We receive the transaction status, amount, and billing country. We never receive or store full card numbers.
  • Chat data: messages you send to our AI assistant Sharpie and any booking details (name, email, preferred time) you share with it.

2a. Audit reports and internal copies

A copy of every audit report generated on the site is also delivered to our internal address (hello@sharpagent.io) so we can improve the tool and prepare for your call. Audit records are kept in pseudonymised form for product improvement; you can ask us to delete your copy at any time.

3. Why we use it (legal bases)

  • To respond to enquiries and deliver services — performance of a contract or steps at your request (Art. 6(1)(b) GDPR).
  • To operate, secure and improve the site — our legitimate interest (Art. 6(1)(f)).
  • To send transactional emails (booking confirmations, project updates) — contract performance.
  • To send marketing only when you have opted in — consent (Art. 6(1)(a)).
  • To run the Website Audit and deliver the paid report — contract performance; scan results kept for tool improvement and abuse prevention rest on our legitimate interest.
  • To process payments and meet accounting duties — contract performance and legal obligation.
  • To comply with legal obligations such as tax and accounting — legal obligation (Art. 6(1)(c)).

4. Who we share it with

We share data with vetted processors that help us run Sharpagent, including our hosting and database provider, email delivery, calendar and video meeting tools, our payment processor (Stripe), the website-scanning service used by the audit tool, and the AI providers that power Sharpie and the audit analysis. We do not sell your personal data. Some processors are located outside the EEA; where that happens, transfers rely on EU Standard Contractual Clauses or an adequacy decision.

5. How long we keep it

  • Enquiries and chat transcripts: up to 24 months from last contact.
  • Booking records: up to 24 months.
  • Audit scans and reports: up to 24 months.
  • Payment and invoice records: 7 years, as required by Estonian law.
  • Client contracts and invoices: 7 years, as required by Estonian law.
  • Analytics: aggregated data retained up to 26 months.

6. Your rights

Under GDPR you can:

  • Access, correct, or delete your personal data.
  • Object to or restrict processing based on legitimate interests.
  • Withdraw consent at any time.
  • Receive a copy of your data in a portable format.
  • Lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

To exercise any right, email hello@sharpagent.io. We reply within 30 days.

7. Security

We use encryption in transit (HTTPS), access controls, and reputable cloud infrastructure. No system is 100% secure; if a breach occurs we will notify affected users and authorities as required by law.

8. Children

Sharpagent is a B2B service and is not directed to anyone under 16. We do not knowingly collect data from children.

9. Changes

We may update this Policy. Material changes will be posted on this page with a new "last updated" date.