B
Buyervalues.ai
ProductHow it worksGrowth LabBuyer valueUse casesProofPricingBlog
Sign InAnalyse Your Company (free)
Legal

GDPR Customer FAQ

This page is provided for convenience and may be updated over time.

GDPR Customer FAQ

Effective date: Aug 10, 2026

This FAQ summarizes common data-protection questions for business Customers. The DPA and Privacy Notice control if this summary conflicts with them.

1. Who is controller and who is processor?

Customer is normally controller for Customer Personal Data it places in its Workspace, and Lingonberry Island Ltd. is Customer's processor. If Customer is itself a processor for another controller, Lingonberry Island Ltd. acts as its subprocessor.

Lingonberry Island Ltd. is an independent controller for account administration, security, billing, legal compliance, and the public-source Company Database. The statutory role always depends on the actual processing, not on contractual ownership language.

2. What belongs to Customer, and what belongs to Company?

As between the parties, Customer retains rights in its non-public proprietary data and manual Workspace modifications and owns Tool Outputs to the extent such rights can exist. Those items remain Workspace-private.

Company owns its rights in the selection, arrangement, investment, and Company-generated elements of the Company Database. Underlying public facts and third-party source material remain subject to third-party rights. See Section 7 of the Terms.

3. Does a Customer-run URL analysis contribute to the Company Database?

Yes. Public URLs and public-source baseline artifacts from a Public URL Run may be incorporated into and reused through the Company Database, including in other Workspaces. The requesting Customer's identity and request context are not shared as part of that reuse.

Customer Proprietary Data, Customer Modifications, and Tool Outputs are not included. Cross-workspace baseline artifacts are sanitized to remove Customer-specific provenance and manual curation.

4. How do I respond to a data-subject request?

Use available search, correction, export, and deletion features and contact info@lingonberryisland.com if assistance is needed. Tell us enough to identify the Workspace and data, but do not email unnecessary sensitive content.

If the request concerns Company-controlled public-source data rather than Customer Personal Data, direct the person to info@lingonberryisland.com or forward the request promptly.

5. How can I export Customer Content?

Use the export formats available for the relevant feature. After termination, Customer has 30 days to request or complete an available export. Export coverage varies by feature; contact support before termination if a specific format or additional assistance is required.

6. How is Customer Content deleted after termination?

Unless Customer gives another lawful instruction, active-system deletion begins after the 30-day export window and is completed within 90 days after termination, subject to legal holds, legal duties, and backup expiration. See the Retention and Deletion Policy.

Company Database data is retained under Company's independent purposes and is not deleted merely because the Customer that initiated a Public URL Run terminates.

7. Does Company access a Workspace?

Authorized personnel may access a Workspace when reasonably necessary to provide support, maintain or repair the Service, investigate security or abuse, troubleshoot, perform approved data operations, or comply with law. Access is limited by role and purpose and should be logged where the production controls provide it.

8. Are manual edits or Tool Outputs reused for other Customers?

No. Manually added or changed labels, hidden items, notes, interview material, internal sources, Workspace chat, and Tool Outputs remain in the Customer's Workspace and are not copied into the Company Database or another Workspace.

Public-source baseline data is a separate category and may be reused as described above.

9. What is sent to OpenAI?

The minimum text and metadata reasonably needed for the requested AI or embedding feature may be sent to OpenAI. Depending on the feature, this can include public page excerpts, Customer prompts, Workspace chat, internal source excerpts, manually entered text, structured context, and text used to create embeddings.

OpenAI API data is not used to train OpenAI models by default. Under default API controls, some API request and response data may be retained by OpenAI for up to 30 days. Customer should not submit prohibited or unnecessary sensitive data.

10. What about third-party integrations?

Customer is responsible for enabling integrations lawfully and informing affected people. A Customer-selected integration may be a separate third-party service; Company providers that act as subprocessors are listed in the Subprocessor List.

11. How are international transfers handled?

The primary backend and PostgreSQL topology is in Finland. Global providers may process data elsewhere. Where required, Company uses safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures.

12. Where can I find the DPA?

The DPA is available at Data Processing Agreement. Contact info@lingonberryisland.com if a signed copy or procurement information is needed.

© 2026 Lingonberry Island Ltd. · Buyervalues.ai
ContactTermsPrivacyGDPR FAQCookiesDPA