Privacy Policy
Last updated: September 1, 2026
1. Who we are
Backendbrains OÜ is an Estonia-based technology company that develops backend systems, automation platforms, AI-assisted workflows, and digital infrastructure for technical and industrial businesses.
Backendbrains OÜ is the data controller for the processing described in this policy. This policy also applies when Backendbrains operates or supplies digital infrastructure for its ventures, including SiempreTengoLuz, unless a separate notice is provided.
Company: Backendbrains OÜ
Registry code: 16682869
Address: Lasnamäe linnaosa, Lõõtsa tn 2a, 11415 Tallinn, Estonia
VAT: EE102592775
Privacy email: privacy@backendbrains.net
2. Information we may collect
We may collect information that you voluntarily provide when contacting us, requesting information, using our services, or interacting with our websites and digital systems. This may include your name, company name, email address, phone number, business information, project details, and communications with us.
If you contact Backendbrains or a Backendbrains-operated venture through WhatsApp, we may also process your WhatsApp phone number, profile information made available to us, message content, and files or images that you choose to send. Website and system operation may generate limited technical information such as IP address, browser or device information, timestamps, and security logs.
3. How we use information
We use information to respond to inquiries, assess and provide requested services, operate digital and conversational infrastructure, manage client relationships, improve and secure our systems, comply with legal obligations, and protect our business operations.
4. Meta and WhatsApp integrations
Business clients may authorize Backendbrains to connect to their WhatsApp Business accounts through Meta's official authorization process. When authorized, we may process Meta Platform Data needed to provide the requested service, including WhatsApp Business account and phone-number identifiers, account configuration, message content, attachments, contact information made available through the service, and message delivery or status events.
We use this information only to connect and operate the client's account, route and display conversations, send requested responses, support agreed automation and human-handoff workflows, provide delivery reporting, maintain security, and troubleshoot the service. We do not sell Meta Platform Data or use it for advertising. Each client retains ownership and control of its Meta business assets and may disconnect the integration.
5. Legal bases for processing
Depending on the context, we process personal information because it is necessary to take steps at your request before entering into a contract or to perform a contract; because we have legitimate interests in responding to business inquiries, operating and securing our services, and improving our systems; because you have given consent where consent is required; or because processing is necessary to comply with a legal obligation. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.
6. Service providers and recipients
We use trusted providers for website hosting, email, cloud infrastructure, messaging, automation, customer communication, and data processing. Depending on the service you use, these may include Netlify for website delivery and Twilio and Meta/WhatsApp for messaging. We may also disclose information to professional advisers, authorities where legally required, and clients or operating partners where necessary to provide an agreed service. Providers process information under their own terms or appropriate data-processing arrangements.
7. International processing
Because we operate digitally and may work with clients and providers in different countries, information may be processed outside the European Economic Area or your country of residence. Where required, we rely on an adequacy decision, contractual safeguards such as the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism.
8. Data retention
We retain inquiry and communication records until the inquiry is resolved and for as long as follow-up is reasonably expected. Client and transaction records are retained for the duration of the relationship and for applicable legal, accounting, contractual, and claims periods afterward. Technical and security records are retained only as long as needed to operate and protect our systems. We may retain specific information longer where required by law or necessary to establish, exercise, or defend legal claims.
9. Your rights and data deletion
Depending on your location and the applicable law, you may have rights to access, correct, delete, restrict, or object to the processing of your personal information; request data portability; and withdraw consent. You may exercise these rights using the email address above. We may need to verify your identity before completing a request.
You also have the right to lodge a complaint with a data protection authority. In Estonia, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). You may also contact the authority in the country where you live or work where applicable.
Instructions for disconnecting an integration and requesting deletion are available on our Data Deletion page.
10. AI-assisted processing
We may use AI-assisted tools to organize information, support customer guidance, summarize communications, or help prepare responses. We do not use solely automated processing to make decisions that produce legal or similarly significant effects on individuals.
11. Security
We apply reasonable technical and organizational measures to protect information. However, no digital system can be guaranteed to be completely secure.
12. Cookies and website technologies
This website does not currently use non-essential analytics or advertising cookies. It may load resources such as web fonts from third-party infrastructure, which can receive limited technical information needed to deliver those resources. If we introduce non-essential cookies or analytics, we will update this policy and provide any consent controls required by law.
13. Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised date.