B
Buyervalues.ai
ProductHow it worksGrowth LabBuyer valueUse casesProofPricingBlog
Sign InAnalyse Your Company (free)
Legal

Privacy Notice

This page is provided for convenience and may be updated over time.

Privacy Notice

Effective date: Aug 11, 2026

This Privacy Notice explains how Lingonberry Island Ltd. processes personal data in connection with Buyervalues.ai and its related business-to-business services. It covers information collected directly from business users and information obtained from public sources.

1. Controller and contact details

  • Controller: Lingonberry Island Ltd.
  • Business ID: FI2912630-1
  • Address: Niittaajankatu 8B D23, FIN-00810 Helsinki, Finland
  • Privacy contact: info@lingonberryisland.com

Contact us at the address above to exercise a data-protection right or ask a privacy question.

2. Scope and our roles

This notice applies when a person:

  • visits our website;
  • signs in, requests business access, or uses the Service for an organization;
  • administers a Workspace, subscription, or billing relationship;
  • contacts sales, support, or security;
  • appears in business information collected from a public website; or
  • uses an optional integration or analytics feature.

We act as a controller when we determine why and how personal data is used, including for account administration, access review, security, billing, our website, support, and the public-source Company Database.

For Customer Proprietary Data, Customer Modifications, and Tool Outputs that a Customer processes in its Workspace for its own purposes, the Customer is normally the controller and we are its processor. The Data Processing Agreement governs that processing. Individuals whose data a Customer has placed in a Workspace should normally direct their request to that Customer first. We will assist the Customer as required by the DPA.

The ownership terms in the Terms of Service do not change controller and processor roles or data-subject rights under applicable law.

3. Personal data we process as controller

3.1 Business account and access data

  • name, work email address, Firebase and Google authentication identifiers, and email-verification status;
  • employer or represented organization, company website, business ID where supplied, Workspace membership, role, invitation, and access-review status;
  • records showing acceptance of legal terms and privacy-notice acknowledgement;
  • account, session, authentication, and security-event metadata; and
  • correspondence with Workspace administrators about access.

3.2 Public-source Company Database data

Public URL Runs and our own maintenance may collect and create:

  • public company and competitor URLs, page URLs, page titles, text excerpts, and source timestamps;
  • public business names, roles, work contact details, biographies, customer-story participants, and other professional information shown on public business websites;
  • crawl, routing, source-quality, and provenance metadata;
  • normalized facts, categories, labels, embeddings, scores, and reusable baseline dossier artifacts; and
  • automated summaries, classifications, comparisons, and other baseline analyses derived from public sources.

We do not intend the Company Database to contain private social-media content, special categories of personal data, criminal-conviction data, or information about a person's private life. Contact us if you believe public-source data about you is inaccurate, inappropriate, or should be removed.

3.3 Website, device, and usage data

  • IP address, approximate location derived from IP, browser and device type, referral information, request timestamps, and server logs;
  • authentication and necessary browser-storage data;
  • feature use, performance, error, and security telemetry; and
  • analytics identifiers and events, but only after consent where consent is required and analytics is enabled.

3.4 Billing and customer-relationship data

  • legal entity, business ID, VAT ID, billing address, billing contact, and Order Form details;
  • Stripe customer, checkout, invoice, and subscription identifiers and payment status, if Stripe billing is enabled; and
  • sales, support, security, and other business communications.

We do not receive or store full payment-card numbers.

3.5 Company-analysis intake data

  • submitted public company and competitor websites and selected market;
  • authenticated work email domain, domain-match outcome, eligibility reason, and manual-review status;
  • technical preparation status for each submitted public company website; and
  • provisional Workspace, preparation, and expiry metadata.

When the automatic preparation feature is enabled, technically valid public company websites submitted through the company-analysis intake may be processed before access review finishes to prepare and improve the public-source Company Database. A submitted competitor is not treated as relevant merely because it was submitted; any appearance in competitor suggestions follows the ordinary ranking. Customer identity, the submitted company grouping, Workspace-specific changes, and proprietary inputs are not published with the reusable public baseline.

4. Customer Personal Data processed on behalf of Customers

Depending on the features a Customer uses, its Workspace may contain names, work contact details, notes, tags, private prompts, interview answers, internal source documents and excerpts, manually curated signals, chat messages, settings, and Tool Outputs. We process that data on the Customer's documented instructions to provide, secure, maintain, troubleshoot, and support the Service.

Customer Proprietary Data, Customer Modifications, and Tool Outputs are not copied into the Company Database or another Customer's Workspace. Public-source baseline artifacts may be reused across Workspaces only through the guarded Company Database process, with Customer-specific provenance and manual modifications removed.

AI-assisted features may send the minimum text and metadata reasonably needed for the requested task to OpenAI. Depending on the feature, this can include public page excerpts, Customer prompts, Workspace chat text, internal source excerpts, manually entered content, structured tool context, and text used to create embeddings. This processing does not make that Customer Personal Data part of the Company Database.

5. Sources of personal data

We obtain personal data:

  • from the individual or their organization;
  • from Workspace administrators and invited Users;
  • from Firebase Authentication and Google sign-in;
  • from publicly accessible company and organization websites submitted by a Customer or selected by us for lawful business-intelligence processing;
  • from Service infrastructure, security logs, and browser/device interactions;
  • from Stripe when billing is enabled; and
  • from other integrations a Customer deliberately enables.

6. Purposes and legal bases

PurposeTypical personal dataLegal basis
Create and administer business accounts, Workspaces, access, and subscriptionsAccount, organization, role, access, and billing dataPerformance of a contract or steps requested before a contract; legitimate interests in administering organizational customers
Verify B2B eligibility and review access requestsWork email domain, company website, domain-match and review dataSteps requested before a contract; legitimate interests in operating a business-only service and preventing abuse
Build, verify, maintain, refresh, and license the public-source Company DatabasePublic professional and company-site data, sources, metadata, and baseline analysesLegitimate interests in providing accurate B2B intelligence, avoiding unnecessary repeat crawling, maintaining source traceability, and improving the Service
Provide support and communicate about the customer relationshipContact and communication dataContract; legitimate interests in support and relationship management
Secure, monitor, troubleshoot, and defend the Service and legal claimsAccount, device, log, audit, and security-event dataLegitimate interests in security, fraud prevention, service reliability, and legal claims; legal obligations where applicable
Bill, collect payment, keep accounts, and meet tax dutiesBilling, invoice, subscription, and payment-status dataContract and legal obligations
Measure website use and improve the websiteConsented analytics dataConsent where required; otherwise legitimate interests where applicable law permits
Send product or business communicationsBusiness contact and preference dataConsent where required; otherwise legitimate interests for permitted B2B communications
Comply with authorities and lawRelevant account, transaction, content, and log dataLegal obligations; legitimate interests in establishing, exercising, or defending legal claims

Our legitimate-interest assessment for public-source processing considers the business context and public nature of the source, data minimization, source traceability, expected impact on individuals, access restrictions, correction and objection rights, and the fact that the Service is not intended for decisions producing legal or similarly significant effects about individuals. You may object as described in Section 11.

Where we ask for consent, providing consent is voluntary. Withdrawal does not affect processing that occurred lawfully before withdrawal.

7. Automated processing

The Service uses algorithms and AI to crawl, classify, summarize, compare, score, and generate business-intelligence results. These results can be inaccurate and must be reviewed by Users.

Our access-intake flow may automatically compare an authenticated work-email domain with a submitted company website. A mismatch or consumer email domain is routed to manual review rather than used as the sole basis for a decision that produces legal or similarly significant effects. The Service is not intended to make solely automated legal, credit, employment, insurance, or similarly significant decisions about individuals.

8. Recipients and subprocessors

We disclose personal data only as needed to operate the Service, follow instructions, complete transactions, protect rights and security, or comply with law. Current and feature-dependent providers are listed in the Subprocessor List. They include:

  • HD-decor Oy, using the Tietokettu trade name, for Finland-hosted VPS infrastructure used by the backend and PostgreSQL database;
  • Google for Firebase Hosting, Firebase Authentication, Google sign-in, and business email/support tools;
  • OpenAI for AI model, embedding, and enabled web-search processing;
  • Stripe for payment and subscription processing, if billing is enabled; and
  • Google Analytics, if configured and activated after the required consent.

We may also disclose data to professional advisers, auditors, insurers, authorities, courts, or a transaction counterparty where legally justified and subject to appropriate safeguards.

Public-source Company Database data may be made available to Customers through the Service. We do not disclose the identity of the Customer that initiated a Public URL Run, Customer-specific request context, Customer Proprietary Data, Customer Modifications, or Tool Outputs as part of that reuse.

9. International transfers

The current backend and primary PostgreSQL database topology is hosted in Finland. Firebase, OpenAI, Google Workspace, Google Analytics, and Stripe may process data in the EEA and in other countries through their global operations and subprocessors.

For transfers from the EEA to a country without an adequacy decision, we use an applicable transfer mechanism such as the European Commission's Standard Contractual Clauses and supplementary measures where required. Some providers may also rely on an applicable adequacy framework. The Subprocessor List provides service-specific information.

Contact us to request information about the safeguards relevant to your data.

10. Retention

We retain personal data only for as long as needed for the purpose described, including applicable legal, security, dispute, and backup requirements.

Data categoryRetention approach
Active business account and Workspace administrationFor the customer relationship, then only as needed for closure, security, disputes, and legal duties.
Customer Content processed on Customer's behalfCustomer has a 30-day export window after access ends; deletion from active systems is completed within 90 days after termination, subject to Customer instructions, legal holds, legal duties, and backup expiration.
Public-source Company Database dataRetained and refreshed while relevant to the B2B intelligence purposes, source traceability, and protection of the database; reviewed, corrected, restricted, or removed when no longer necessary or following a valid request. It is not deleted merely because the Customer that initiated a Public URL Run terminates.
Unapproved company-analysis intakeUp to 30 days after submission unless a legal hold applies; safely removable provisional resources are removed on denial or expiry.
Approved company-analysis intakeBecomes part of the relevant account and Workspace records and follows their retention.
Sanitized public baseline prepared from an intakeFollows the Public-source Company Database retention above. Removing it from the shared database does not by itself delete the Customer's Workspace copy; Workspace data follows the applicable Customer Content retention and instructions.
Security, request, and operational logsFor the shortest period reasonably required for security, troubleshooting, service reliability, and claims, based on log type, severity, and configured storage capacity; longer only for an incident or legal requirement.
Support and sales communicationsWhile needed to handle the matter and thereafter for reasonable relationship, dispute, and legal-record purposes.
Invoices and accounting materialFor statutory Finnish accounting and tax periods: typically six years for vouchers and transaction correspondence and ten years for financial statements, ledgers, and specified accounting records, calculated as required by law.
Consent and legal-acceptance recordsFor as long as needed to demonstrate the relevant choice or agreement and resolve related claims.
OpenAI API request dataSubject to the configured OpenAI data controls. Under default API controls, certain prompts, responses, and metadata may be retained by OpenAI for up to 30 days, unless law requires longer retention.
BackupsUntil overwritten or expired under the applicable backup schedule; restored data remains subject to the original retention and deletion controls.

More detail is available in the Retention and Deletion Policy.

11. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • obtain confirmation and access to your personal data;
  • correct inaccurate or incomplete data;
  • request erasure;
  • restrict processing;
  • object to processing based on legitimate interests, including public-source Company Database processing;
  • object at any time to direct marketing;
  • receive data you provided in a portable format where the legal conditions are met;
  • withdraw consent at any time where processing relies on consent; and
  • lodge a complaint with a supervisory authority.

To exercise a right concerning processing for which we are controller, contact info@lingonberryisland.com. We may need to verify your identity and clarify the data concerned. If we deny a request, we will explain the reason and available remedies as required by law.

For Customer Personal Data in a Workspace, contact the relevant Customer first. If you contact us directly, we may refer the request to that Customer unless law requires a different response.

The Finnish supervisory authority is the Office of the Data Protection Ombudsman.

12. Security

We use technical and organizational measures designed for the nature and risk of the processing, including TLS, role-based and Workspace-scoped access controls, Firebase token verification, a private production database network, request validation, rate limits, audit logging, secrets controls, and documented deployment and incident procedures.

No system is completely secure. See the Security and TOMs Overview for more detail.

13. Cookies and browser storage

We use necessary browser storage for authentication, security, consent choices, and short-lived workflow state. Google Analytics storage is used only if analytics is configured and the required consent has been given. See the Cookie Notice.

14. Required information

Account, business-eligibility, authentication, and essential billing information is required to enter into or perform the business relationship. If it is not provided, we may be unable to approve access or provide paid Service features. Optional profile, marketing, and analytics information is not required.

15. Business-only service and children's data

The Service is not offered to Consumer Users or children. Users must be at least 18 and act for a business or other organization. We do not knowingly create accounts for children. Contact us if you believe a child has provided data to the Service.

16. Changes to this notice

We may update this notice as our processing or legal obligations change. We will post the current version and effective date. If a change materially affects how we use personal data, we will provide additional notice where required.

© 2026 Lingonberry Island Ltd. · Buyervalues.ai
ContactTermsPrivacyGDPR FAQCookiesDPA