Privacy Notice

Simple Commenter Privacy Notice

Ander Digital OÜ is committed to protecting your privacy. This Privacy Notice explains how we handle and safeguard the personal data you provide when using our Simple Commenter, subscribing to our newsletter, or interacting with us in any other way. We process your data in accordance with applicable data protection laws, including the GDPR.

Last Updated: 10 September 2026

Simple Commenter feedback and AI connections

This section explains how the privacy notice applies to Simple Commenter feedback and external AI connections.

Website feedback and connected AI tools

Simple Commenter stores feedback submitted to a company’s projects, including comment text and titles, replies, author names and email addresses where provided, page addresses, timestamps, statuses, priorities, and tags. Depending on project settings and the evidence submitted, feedback may also include screenshots, uploaded files, the selected page element and its position, browser and device information, and captured JavaScript error messages. This information helps project participants locate, understand, and resolve reported problems.

When you connect an external AI tool, such as ChatGPT, Codex, or Claude, using Model Context Protocol (MCP), that tool can request information from the projects included in its authorization. Requested information can include the feedback and evidence described above, project names and workflow settings, reports, exports, and the connected account’s current plan and permissions. Administrative information, such as project configuration and team assignments, additionally requires an owner-authorized settings grant. Our MCP tools do not request your complete AI conversation history. They receive the specific inputs sent with a tool request, such as a search term, a project or comment identifier, reply text, or requested changes.

We use MCP connection information to authenticate requests, enforce company and project boundaries, perform requested actions, produce reports and downloads, prevent duplicate writes, record operation outcomes, and limit abusive request rates. Connection records include the authorizing identity, the connected client, approved projects and permissions, token hashes, and connection activity dates. Operational records can include requested tool arguments, results, affected project or comment identifiers, and processing dates. The retention of these records is addressed below.

Who receives information

The AI client you authorize receives the requested tool results. If you use a hosted AI service, its operator may process those results under its own terms, privacy notice, and the settings of your account with that service. Review those policies before connecting. Information already received or saved by an AI service is subject to that service’s controls and retention practices.

If you grant write permission, the AI client can submit feedback, reply, update status or priority, and perform other permitted feedback actions. These actions are visible to people who can access the affected feedback and may also trigger the project’s configured email notifications or external integrations. An owner’s separate settings permission allows the administrative operations shown during authorization.

Your controls

A hosted connection belongs to one company. Owners choose selected projects or explicitly grant access to all current and future projects. Members can authorize only their assigned projects, with read and optional write permissions. Member connections cannot obtain settings or workspace-wide access. We recheck membership and project assignments on subsequent requests; removing access also prevents access to saved results through that connection.

Use MCP & AI connections in the dashboard to disconnect a client. Members can disconnect their own clients, and owners can disconnect clients in their company. Disconnecting invalidates the connection and its authorized download access. It does not erase copies that an AI client or another authorized recipient already received. Contact that recipient to use its deletion controls. Contact us using the details in the main privacy notice for requests concerning data held by Simple Commenter.

MCP report and operation retention

Generated MCP report/export artifacts and background job records are scheduled for expiry after 24 hours. Download links normally expire after 15 minutes; an eligible background job can issue a replacement link while its underlying artifact is available. Records used to prevent repeated writes are scheduled for expiry after seven days. MCP operation audit records are scheduled for expiry after 30 days. Expired database records are removed by automated cleanup, which may run after their expiry time.

These periods apply to the generated MCP records, not to original project feedback, screenshots, or attachments, which follow the service’s applicable retention settings and the main privacy notice. Disconnecting does not by itself delete original feedback.

1. Data Controller

The controller of your personal data is Ander Digital OÜ, who is responsible for ensuring that your personal data is processed in accordance with this Privacy Notice and applicable data protection laws, in particular with the General Data Processing Regulation (EU) 2016/679 (“GDPR”). The contact details of the data controller are as follows:

  • Ander Digital OÜ
  • Registry code: 16227026
  • Email: aleksander@ander.ee

2. Personal Data We Process and use

We usually collect personal data directly from data subjects when they visit our events or otherwise interact with us, or from our business partners when the respective representatives also interact with us. The data we collect depends on the context of your relationship and interactions with us and the choices you make, and applicable data protection laws.

Depending on the nature of the legal relationship between us, we may process the following personal data of the data subjects and our business partners’ representatives and employees:

  1. General personal data and contact details: such as your first and last name, e-mail address and phone number;
  2. Data on the company associated with the data subject: such as name and details of the company, work position, title or work profile of the data subject;
  3. Data on transactions: such as information about your payments and transactions, as well as other information associated with the transaction such as used payment method, amounts paid, etc.
  4. Your image, voice and transcripts/extracts in text form or any other similar captured content: for instance, when you are photographed or filmed at our events, or if you have separately agreed to participate in our marketing products; and
  5. Data provided by you or our partners by interacting with us: such as data required for establishing and maintaining a contractual or business relationship, information about our correspondence (including information communicated to us through our website contact form), feedback data and other content collected via inquiries, or any other information that you or our partners voluntarily provide to us.

3. Purposes and legal bases for the processing of personal data

We may process the personal data of the relevant data subjects for the following purposes and on the legal bases:

  1. Establishing contractual relationships. Depending on the identity of the person, the legal basis for processing the personal data is the implementation of pre-contractual measures prior to the conclusion of the contract with you (Article 6(1)(b) of the GDPR) or our legitimate interest in enabling you to take the necessary steps to enter into a contract (Article 6(1)(f) of the GDPR).
  2. Performance of contractual relationships. Depending on the identity of the person with whom we have a contractual relationship, the legal basis for processing the personal data is either the performance of the contract we have with you (Article 6(1)(b) of the GDPR) or our legitimate interest in performing our contractual obligations (Article 6(1)(f) of the GDPR).
  3. Management of contractual and business relationships. For these purposes, the legal basis for the processing of your personal data is our legitimate interest in maintaining contractual and business relationships, including by managing databases of our customers, and other business partners (Article 6(1)(f) of the GDPR).
  4. Managing and responding to inquiries and request. Depending on the nature of the communication and the identity of the person who communicates with us, the legal basis for processing the personal data is either the performance of the contract we have with you (Article 6(1)(b) of the GDPR) or our legitimate interest in managing and responding to communications concerning the app and other activities (Article 6(1)(f) of the GDPR).
  5. Establishing, exercising and defending any potential legal claims. Where necessary for taking action on such legal claims, and for compliance, regulatory and investigative purposes, which all may derive from legal relationships data subjects or with our partners as legal entities, the legal basis for the processing of your personal data is our legitimate interest (Article 6(1)(f) of the GDPR).
  6. Complying with our legal obligations deriving from applicable law. For these purposes, the legal basis for the processing of your personal data is the respective legal provision obliging us to process the relevant data (in accordance with Article 6(1)(c) of the GDPR). Such legal obligations may derive, for example, from accounting and tax laws.

4. Disclosure and transfer of personal data

We put our best efforts to keep your personal data safe and always require a high level of security and confidentiality from our employees and partners. Access to your personal data is restricted to our employees and partners only to the extent necessary for the performance of their specified tasks.

  • - with our trusted services providers when they provide services to us or to you, on behalf of us and under our instructions, such as cloud-based service providers, accounting service providers, etc. We will control and shall remain responsible for the use of your personal data in such cases;
  • - to public authorities if we are required to disclose personal data by applicable law or to comply with a lawful request of authorities;
  • - other third parties where it may be necessary to protect our property or rights, or defend against legal claims.

We may transfer your personal data outside of the European Economic Area in limited cases. In such a case, we use adequate safeguards to protect your personal data, such as the standard contractual clauses for transfers established by the European Commission. You can contact us to get more information about the transfers of your personal data by using the contact details in Section 1 of this Privacy Notice.

5. Retention of your personal data

We process your personal data only for as long as necessary for the fulfilment of the original purposes of personal data processing, which are described above, or as long as required to fulfil our legal obligations. We determine the appropriate retention period for personal data on the basis of the amount, nature, and sensitivity of the personal data being processed, the potential risk of harm from unauthorised use or disclosure of the personal data, whether we can achieve the purposes of the processing through other means, and on the basis of applicable legal requirements (such as applicable statutes of limitation).

When the retention of your personal data is no longer necessary to achieve the purposes of processing, your data will be permanently removed, unless you instruct us otherwise and we agree on the terms on longer storage of your data.

6. Your rights as a data subject

You may exercise your rights as the data subject to the extent permitted under applicable law, including the following rights:

  • You may request access to your personal data
  • To the extent permitted under applicable law, you may request us to correct, update, change or erase your personal data. In some cases you may also have a right to object to processing of your personal data;
  • If you request the erasure of your personal data, please note that certain personal data is strictly necessary in order to fulfil the purposes defined in this Privacy Notice and the processing of which may also be required by applicable law. If personal data is erased under your request, we will only retain such copies of the information as are necessary for us to protect our or third parties’ legitimate interests, comply with governmental orders, resolve disputes, troubleshoot problems, or enforce any agreement you have entered into with us. Therefore, such personal data may not be erased in full;
  • You may withdraw your consent regarding the processing of your personal data, where the legal basis for processing is your consent. Please note that withdrawal of consent does not affect the lawfulness of the processing of personal data carried out on the basis of consent before withdrawal;
  • You may use your right to data portability. In some cases we may limit or deny your request if we are required or permitted by applicable law to do so, e.g., if it is necessary for the purpose of our legitimate interest to protect our trade secrets or any other confidential information; and
  • To the extent permitted under applicable law, you may request more information about our legitimate interest and why we think our legitimate interest overrides your rights and interests as a data subject. This applies where the legal basis for the processing of your personal data is our legitimate interest.

To exercise your rights or if you have any privacy-related questions, please contact us by using the contact details in Section 1 of this Privacy Notice. We will respond to your requests and to provide you with additional privacy-related information within the timeframes specified in applicable personal data protection law. Please note that we may ask you for additional information to adequately verify your identity before taking action on your request to exercise your rights as a data subject.

If you are not satisfied with our response or have a concern that your privacy rights have been infringed, you have the right to lodge a complaint with your local supervisory authority. List and contact details of European supervisory authorities can be found here.

7. Security Measures

We use reasonable technical and organisational measures (including physical, electronic and administrative) to protect your personal data from loss, destruction, misuse and unauthorised access or disclosure. Please note that no method of transmission over the Internet, or method of electronic storage, is fully secure. While we use all reasonable efforts to protect your personal data from loss, destruction, unauthorised access, misuse, or disclosure, we cannot fully guarantee the security of your personal data.

8. Updates

From time to time, we may update this Privacy Notice in order to adapt it to any updates that might arise. In case of making any substantial update, we will notify you via the e-mail that you have, or the company on behalf of whom you interact with us, communicated us. This Privacy Notice was last updated as of the “Last updated” date indicated above.