// privacy
Privacy notice
Last updated
TOntoN is built by TeOnto. This notice explains what we collect when you use the app, why, on what legal basis, how long we keep it, and what you can require of us. If TOntoN has analysed a company and written about you as one of its founders or executives — rather than you being a user — the notice for you is at /notice-to-individuals.
Who is responsible for your data
The controller is TeOnto, the registered commercial name of Pooyan Ramezani Besheli, a Belgian sole trader. Full registration details, including the enterprise and VAT numbers and the registered address, are set out at the foot of this page. Write to hello@teonto.com about anything in this notice. We have not appointed a data protection officer; that address reaches the person responsible.
When you are the controller, not us
Where you use TOntoN to process personal data of your own — for example material about a company's staff that you upload — you are the controller for that data and we act as your processor on your instructions. Our data processing agreement governs that relationship and is available at /dpa.
What we collect
We collect what you give us when you create an account, what your browser sends when you use the app, and the public-source material the pipeline analyses on your behalf:
- Account fields: email, display name, organisation name, password (stored as a salted bcrypt hash).
- Companies you add: name, root URL, and any sources you choose to attach (links, pasted text, uploaded files, LinkedIn URLs you provide).
- Analysis output: scores, evidence quotes, reports, PDFs, and the JSON payloads our pipeline produces from your sources.
- Operational logs: HTTP request lines, response status, and error traces. We retain these for up to 30 days for debugging.
- Email-verification + password-reset tokens — single-use, expire automatically, stored as sha256 hashes (never the raw token).
What we do with it
We use your data to run the product you signed up for: render the dashboard, run Vision analyses, generate reports, deliver transactional emails. We do not sell your data. We do not train third-party AI models on your account contents or your analysis outputs.
Why we process it, and on what legal basis
Each purpose has a basis under Article 6 of the GDPR:
- Creating and running your account, rendering the dashboard, running analyses, generating reports and sending transactional email — performance of our contract with you.
- Billing, invoicing and keeping accounting and tax records — compliance with a legal obligation.
- Security, abuse prevention and rate limiting — our legitimate interest in keeping an invite-gated service from being abused.
- Operational logging and debugging — our legitimate interest in running a reliable service.
- Aggregate, de-identified product statistics that cannot identify you or your workspace — our legitimate interest in improving the product.
- Emailing existing customers about the service — our legitimate interest, with an opt-out in every message.
- Establishing, exercising or defending legal claims — our legitimate interest.
Who else sees it
Your account data and analyses are visible only inside your workspace, which is enforced at the API layer and verified by an automated test suite on every deploy. The full list of providers that process data on our behalf, what reaches each of them and where they are established, is at /subprocessors. In summary: the language-model provider that performs extraction and scoring, the search provider used for source discovery, our hosting and database provider, the transactional email provider, the payment processor, and internal alerting. We also disclose data where the law requires it, and to professional advisers under a duty of confidence.
Transfers outside the EEA
Several of those providers are established in the United States. Where personal data reaches them, the transfer is governed by that provider's data processing terms, which incorporate the European Commission's Standard Contractual Clauses and, for some providers, certification under the EU–US Data Privacy Framework. The per-provider detail is at /subprocessors.
How long we keep it
- Account, company and analysis data — while your workspace is active.
- After your subscription ends — deleted or irreversibly anonymised within 90 days.
- A company you delete — removed immediately, with its sources, runs and reports.
- Your whole account, on request — removed within 14 days.
- Operational logs — 30 days.
- IP address and browser user-agent — 90 days.
- Verification and password-reset tokens — until used or expired.
- Billing, accounting and tax records — 10 years, as Belgian law requires.
- Backups age out on their own cycle; deleted data is not restored to live systems.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, object to our using it where we rely on legitimate interests, or send it to another provider in a portable format. Use the export and account-deletion routes in Settings, or write to us from the address on your account. We answer within one month, and will tell you if a complex request needs longer. You can complain to the Belgian Data Protection Authority — Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be — or to the authority where you live or work.
Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects by automated means. The product does generate automated assessments of companies and the people associated with them — that is what it is for — and /notice-to-individuals explains what that means for the people concerned. Reports are intended for human review, and our customers are prohibited from using one as the sole basis for a decision with a legal or similarly significant effect on an individual.
Is any of this required?
Account fields are necessary to have an account, and billing details are necessary to be invoiced. Without them we cannot provide the service.
Cookies + analytics
We use one localStorage entry to hold your session token. We do not run third-party analytics, ad pixels, or session-replay tooling. The marketing landing fires a single first-party telemetry event when you click a major CTA (page + placement). When you submit a marketing form or that event fires, we record your IP address and browser user-agent for spam and abuse prevention and rate-limiting. We keep those for up to 90 days and never use them to build an advertising profile.
Changes to this notice
If we change anything material, we will update the "Last updated" date below and notify active users by email before the change applies.
Contact
Questions or requests, reach us at hello@teonto.com.
Who operates this service
TeOnto is the registered commercial name of Pooyan Ramezani Besheli. The enterprise is registered with the Banque-Carrefour des Entreprises (BCE/KBO).
- Legal form
- Entreprise personne physique (registered sole trader, Belgium)
- Registered address
- Avenue de Roodebeek 89, boîte b0021030 SchaerbeekBelgium
- Enterprise number
- 1035.444.514
- VAT number
- BE 1035.444.514
- Establishment unit
- 2.386.198.812
- hello@teonto.com