GDPR Compliance
Your rights under the General Data Protection Regulation
Last updated: November 18, 2025
Our Commitment to GDPR
Jaen Software is headquartered in Estonia, a member state of the European Union. We are fully committed to compliance with the General Data Protection Regulation (GDPR) and Estonian data protection laws.
This page explains your rights under GDPR, how we process your personal data, and how you can exercise your rights.
Data Controller Information
Company Name: Jaen Software
Location: Estonia, European Union
Data Protection Officer: reachable via the contact email below
Contact Email:
GDPR Inquiries: info@jaenworld.com
Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
1. Contractual Necessity (Article 6(1)(b))
Processing necessary to provide the Jaen service:
- Account creation and authentication
- Service delivery and feature access
- Payment processing and billing
- Customer support
2. Consent (Article 6(1)(a))
With your explicit consent for:
- Marketing communications and newsletters
- Status update notifications
- Non-essential cookies
- User research and feedback collection
You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
3. Legitimate Interests (Article 6(1)(f))
When necessary for our legitimate interests:
- Security and fraud prevention
- Service improvement and analytics
- Network and system security
- Business development
We carefully balance our interests with your rights and will not process data where your interests override ours.
4. Legal Obligation (Article 6(1)(c))
When required by law:
- Tax and accounting obligations
- Response to legal requests
- Regulatory compliance
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
π Right to Access (Article 15)
You have the right to obtain confirmation that we process your data and receive a copy of your personal data.
How to exercise: Request your data by emailing
Response time: Within 30 days
βοΈ Right to Rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data.
How to exercise: Update your profile in account settings or contact us
Response time: Immediate (via settings) or within 30 days
ποΈ Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data when:
- The data is no longer necessary
- You withdraw consent
- You object to processing
- Data was unlawfully processed
- Legal obligation requires deletion
How to exercise: Delete account in settings or email us
Response time: Within 30 days
β οΈ Note: Some data may be retained for legal/compliance reasons (e.g., billing records for tax purposes).
βΈοΈ Right to Restriction of Processing (Article 18)
You have the right to request we limit how we use your data when:
- You contest the accuracy of data
- Processing is unlawful but you oppose deletion
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification
How to exercise: Email
π¦ Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON, CSV).
How to exercise: Export data from account settings or request via email
Available formats: JSON, CSV, ZIP archive
β Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
How to exercise: Unsubscribe from emails or contact us
Marketing opt-out:Click "unsubscribe" in any marketing email
π€ Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or significant effects.
Jaen status: We do not make automated decisions with legal or significant effects without human review.
π Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
How to exercise: Adjust consent preferences in account settings
βοΈ Right to Lodge a Complaint (Article 77)
You have the right to lodge a complaint with a supervisory authority if you believe we have violated GDPR.
Estonian Data Protection Inspectorate:
Website: https://www.aki.ee/en
Email: info@aki.ee
Phone: +372 627 4135
We encourage you to contact us first so we can address your concerns directly.
Data Processing Activities
We maintain a Record of Processing Activities (ROPA) as required by GDPR Article 30. Here's a summary:
| Activity | Data Categories | Legal Basis | Retention |
|---|---|---|---|
| Account Management | Name, email, password hash | Contract | Until account deletion |
| Payment Processing | Billing details, transaction history | Contract, Legal | 7 years (tax law) |
| Service Delivery | Show configs, device settings | Contract | Until account deletion |
| Analytics | Usage patterns, device info | Legitimate Interest | 13 months |
| Marketing | Email, preferences | Consent | Until consent withdrawn |
| Customer Support | Correspondence, issue details | Contract | 3 years |
| Security Logs | IP addresses, access logs | Legitimate Interest | 12 months |
International Data Transfers
Your data is primarily stored and processed within the European Union. If we transfer data to countries outside the EU/EEA, we ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs): Legally binding data protection obligations for processors outside the EU
- Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
- Additional Safeguards: Technical measures like encryption and access controls
Current third-party processors with potential non-EU data flows:
- Cloud hosting: AWS (EU regions, with SCCs for support access)
- Email delivery: SendGrid (US, with SCCs)
- Error tracking: Sentry (US, with SCCs)
Data Breach Notification
In the unlikely event of a personal data breach, we will:
- Within 72 hours: Notify the Estonian Data Protection Inspectorate (as required by Article 33)
- Without undue delay: Notify affected users if there is a high risk to their rights and freedoms (as required by Article 34)
- Transparency: Publish incident details on our status page
Incident Response: We maintain a comprehensive incident response plan and conduct regular drills to ensure rapid, effective response to any security incidents.
Children's Data Protection
Jaen is not intended for individuals under 16 years of age (the minimum age for consent under GDPR in most EU countries).
We do not knowingly collect or process personal data from children under 16 without parental consent. If we become aware that we have collected data from a child under 16 without verification of parental consent, we will delete that information promptly.
If you believe we have collected data from a child under 16, please contact us immediately at
How to Exercise Your Rights
Contact Methods
Email (Primary):
Privacy Email: info@jaenworld.com
Data Protection Officer: Mikk Mengel
Company: Jaen Software
Location: Estonia, European Union
What to Include in Your Request
- Your name and email associated with your Jaen account
- Clear description of which right you want to exercise
- Any specific information or time periods relevant to your request
- Proof of identity (to prevent unauthorized access)
Response Timeline
- Acknowledgment: Within 3 business days
- Response: Within 30 days (can be extended to 60 days for complex requests)
- Fee: Free of charge (unless requests are manifestly unfounded or excessive)
π‘ Tip:For faster processing of data access requests, log in to your account and use the "Export My Data" feature in settings.
Related Policies
For more information about how we protect your data:
- Privacy Policy - Complete privacy information
- Security - Our security measures and practices
- Cookie Policy - How we use cookies
- Terms of Service - Usage terms and conditions