Privacy Policy

Your Data, Your Control.

Effective: 07.03.2026 · Version 1.0 · Last updated: 07.03.2026

Our Promise: We collect minimal data needed to operate. Your data is encrypted, never sold, and you can delete it anytime. Navigator data never leaves your device. We comply with GDPR (EU 2016/679) and the Estonian Personal Data Protection Act.

1. Data Controller

Unilink Center MTÜ
Registry code: 80668249
Tallinn, Estonia
Email: info@unilinkcenter.com
Data Protection Officer: Otto Göcmen — info@unilinkcenter.com

2. Data We Collect

2.1 Unilink Platform Website

2.2 Navigator App

2.3 GrantOS Service

3. Legal Basis (GDPR Art. 6)

4. Special Category Data (GDPR Art. 9)

Epilepsy AI processes health data (seizure patterns) only with explicit consent. This data is processed on-device using ONNX inference. No health data is transmitted to our servers without user action. Federated learning ensures model improvement without centralizing personal health data.

Navigator may collect data related to crisis situations. This data is encrypted (AES-256) and stored exclusively on the user's device. The user controls all sharing decisions.

5. Children's Data (GDPR Art. 8)

Navigator's Child Mode (ages 8–12) collects minimal interaction data. No personal identifiers are collected from children. Parental/guardian consent is required for account creation for users under 16 years of age, in accordance with Estonian law.

6. Data Sharing

We do not sell, rent, or trade your personal data. We share data only with:

No data is transferred outside the EU/EEA without adequate safeguards (Standard Contractual Clauses or adequacy decisions).

7. Data Retention

8. Your Rights (GDPR Art. 15–22)

To exercise any right, email otto@unilinkcenter.com. We respond within 30 days.

9. Security Measures (GDPR Art. 32)

10. Cookies

This website does not use cookies for tracking or analytics. No third-party tracking scripts are loaded. Netlify may set essential technical cookies for security (DDoS protection). These are strictly necessary and do not require consent under GDPR.

11. Automated Decision-Making (GDPR Art. 22)

GrantOS uses AI (Claude API by Anthropic) to analyze grant compliance and generate recommendations. These are advisory outputs only — no automated decisions are made that produce legal effects. Final decisions rest entirely with the user.

12. EU AI Act Compliance

Full compliance documentation available by 02.08.2026.

13. Complaints

If your data protection rights have been violated:

Andmekaitse Inspektsioon (AKI)

Estonian Data Protection Inspectorate

Tatari 39, 10134 Tallinn, Estonia

Email: info@aki.ee · Web: www.aki.ee

14. Changes & Governing Law

We may update this policy to reflect changes in practices or legal requirements. Material changes will be communicated via our website. This Privacy Policy is governed by the laws of the Republic of Estonia. Disputes: Harju Maakohus (Tallinn District Court).

Data Protection Contact

Otto Göcmen — Data Protection Officer

Email: otto@unilinkcenter.com

Tallinn, Estonia

Questions about your data? We're transparent by design.

Contact Us →