Privacy Policy

Effective from: July 19, 2026

1. Who we are

The platform juhiabi.ee / taskment.io / backline.ee / stagement.live is operated by 1/2 Mind OÜ (registry code 11550459; Keki tn 3, 76606 Keila, Estonia; VAT EE101298384). For privacy questions, write to info@juhiabi.ee.

2. Two roles: whose data?

There are two kinds of personal data on the platform, and our role differs for each:

  • Account and platform data (your name, email, logins, billing) — for this data we are the controller.
  • Workspace content data (your company’s customers, contacts, projects and documents that you enter into the Service) — for this data the controller is your company; we are the processor and process it only to provide the Service, according to your instructions (see the data processing agreement).

3. What data we collect

  • Account data: name, email address, password (hashed), language preference.
  • Usage data: login times, IP address, technical logs (security and troubleshooting).
  • Workspace data: the content that you or your users enter into the Service.

4. Purposes and legal bases of processing

  • Providing the Service and managing the account — performance of a contract (GDPR art 6(1)(b)).
  • Security, troubleshooting and preventing abuse — legitimate interest (art 6(1)(f)).
  • Service notices (e.g. information about important changes) — performance of a contract; marketing messages are sent only with consent (art 6(1)(a)).

5. Sub-processors and data transfers

We use the following service providers to provide the Service. Many integrations work on the principle that the workspace connects its OWN account — in that case the data flows to the provider under your own agreement with them.

  • Server hosting — the servers are located in the European Union.
  • Email delivery — platform notifications are sent via Google (Gmail SMTP); a workspace may configure its own SMTP server, in which case the workspace’s emails are sent through it.
  • Google — calendar and Meet synchronisation and the Gmail integration, if the user connects their own Google account.
  • Google Analytics 4 — visitor statistics on the public landing pages, ONLY with the visitor’s consent (see the cookie policy); GA4 does not store IP addresses.
  • Cloud storage: Google Drive, Dropbox, Microsoft OneDrive — if the workspace owner connects their own cloud account for file storage, files are stored in their own cloud service.
  • Brevo and Smaily (newsletters and marketing) — if the workspace enables the integration with its own account, the contacts it selects are synchronised to that service.
  • Finbite (Omniva) — sending e-invoices, if the workspace enables it.
  • Anthropic — AI features (e.g. reading data from an expense document); content is submitted only at the moment an AI feature is used and is not used to train AI models.
  • Push notifications — if you allow notifications in your browser, they are delivered via your browser’s push service (e.g. Google, Mozilla, Apple). The notification itself contains no content — the app fetches the content directly from our server.

Company background information (the analysis module): the data comes from public sources — the Estonian Business Register (ariregister.rik.ee, including Tax Board figures published via the Business Register), the public procurement register (riigihanked.riik.ee), the EU VAT register VIES (ec.europa.eu) and companies’ public websites. These sources also contain personal data: Business Register responses include names of management board members, and at the user’s request contact persons’ names, email addresses and phone numbers may be found on websites. We process such data to fulfil the user-initiated query (legitimate interest, GDPR art 6(1)(f)): general company data is stored in the platform’s shared cache, the contacts chosen by the user in their workspace. When an AI feature is used (e.g. finding contacts on a website, reading an expense document), the processed content is submitted to the Anthropic API; it is not used to train AI models. As the data is obtained from public sources, we do not notify each data subject individually (the GDPR art 14(5)(b) exemption); every person has the right to ask about their data and request erasure (info@juhiabi.ee).

Technology platform: the Service runs on the open-source WordPress software (GNU GPL v2 or later license), installed on our own servers. WordPress.org is not a sub-processor and has no access to your data; the software’s automatic update check sends api.wordpress.org only technical information (software versions, the site address and aggregate counts), never anyone’s personal data.

We do not sell or share your data for advertising purposes.

6. Retention

We keep account data for as long as the account exists. The platform database (including workspace data) is backed up once a day and backups are kept for up to 30 days. When important records (e.g. contacts, companies, projects, quotes, performers) are deleted, they first go to the trash, from which a user with the appropriate permission can restore them until they are permanently deleted from the trash. When an account or workspace is closed, we delete the data within a reasonable time (at the latest 90 days after closure), except for data we must retain by law (e.g. accounting documents).

7. Security

We protect data with encrypted connections (TLS), access restrictions, a role-based permission system and regular backups. Each workspace’s data is isolated from other workspaces.

8. Your rights

You have the right to access your data, have it corrected or deleted, restrict processing, data portability and to object (GDPR art 15–21). To exercise these rights, write to info@juhiabi.ee. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee).

9. Cookies

The use of cookies is described in the separate cookie policy.

10. Changes

We will announce material changes to this policy in the Service or by email.