Skip to content

Legal information

Privacy Notice

Last updated: September 10, 2026

This notice describes how Annota AI processes the personal data of people who visit the Annota AI website, request a demo, join the waitlist, create an account, use the platform, make purchases, or contact us. It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).

Annota AI acts as controller for data relating to its relationship with users and customers, including account, security, service usage, support, and billing data. Where it processes personal data contained in datasets or other content uploaded by a customer for purposes determined by that customer, Annota AI generally acts as processor pursuant to Article 28 GDPR.

The Italian version of this Privacy Notice is the only legally valid and authoritative version. Translations are provided solely for convenience.

1. Controller and contact details

The data controller is Annota S.r.l., with registered office at Via Davide Lazzeretti 2/P, 58100 Grosseto, EU VAT No. IT01783380536, Tax code / Companies Register no.: 01783380536 - Maremma e Tirreno, REA No. GR-236295, fully paid-up share capital of €10.000,00, certified email (PEC) annotasrl@pec.it.

  • Privacy email: team@annota.ai
  • Certified email (PEC): annotasrl@pec.it

Annota AI has not currently appointed a Data Protection Officer (DPO). Privacy-related requests may be sent using the contact details above.

2. Scope of this notice and privacy roles

Annota AI acts as controller when it determines the purposes and means of processing data relating to the website, Accounts, contractual relationship, platform management, billing, communications, and the security of its systems.

This notice does not govern processing carried out by third-party websites or services reached through links, which operate under their own notices. Providers appointed by Annota AI to deliver parts of the website or communications are instead listed in the section on recipients.

The contractual conditions governing the website and services are available in the Terms of Service.

3. Data processed and sources

We process only data relevant to the activities described in this notice. Data may come from the data subject, the organization for which they work, the systems used to access the Service and, for identity, payment, and security data, from providers used by Annota AI.

  • Identification, contact, and authentication data: name, verified email address, Account identifier, linked Google or GitHub identities, passkey public keys and metadata, sessions, and information required to verify access.
  • Profile and onboarding data: avatar, language, role, use case, team size, referral source, and other optional information provided by the user.
  • Organization and collaboration data: workspace name and logo, memberships, roles, invitations, and member or invitee email addresses.
  • Contractual and usage data: Plan, subscription status, credits, features used, operations performed, requests, identifiers, and dates of application events.
  • Billing and payment data: customer and subscription identifiers, amounts, currency, payment status and, at the payment provider, name or business name, billing email, address, tax code or VAT number, tax ID, and payment instrument data.
  • Customer content: datasets and their immutable versions, files, images, documents, text, names and descriptions, labels, annotations, instructions, output, OCR results, exports, training configurations and history, metrics, and customer-requested model versions.
  • Preferences, consents, and authorizations: waitlist segment, subscription, withdrawal or unsubscribe status, interface preferences, and authorizations granted to external applications, including client identifiers, permissions, and approval or revocation dates.
  • Communications data: content of requests sent to Annota AI and subsequent replies.
  • Technical and security data: IP address, date and time, requested URL, technical headers, request or session identifiers, browser or device type, logs, and events required to prevent abuse and diagnose errors.

Authentication and sessions are managed directly by Annota AI. You can sign in with a one-time email code, a passkey, or, if you choose, Google or GitHub. For these latter methods, we receive the identification and profile data required to sign in and link your Account from the provider. From your Account, you can manage linked methods, sessions, and authorized applications.

Annota AI does not receive complete card details used through the payment system. We also do not ask users to enter special categories of personal data, data relating to criminal convictions or offenses, credentials, or identity documents in public forms. Please do not submit such information through website forms.

4. Purposes, legal bases, and retention

Demo request

Data processed
First name, last name, email and, if provided, company, industry, and message.
Purpose and legal basis
Handling the request, arranging the demo, and taking pre-contractual steps requested by the data subject (Art. 6(1)(b) GDPR).
Retention
Up to 24 months after the last substantive contact. If a contractual relationship is established, the data becomes part of the relevant documentation and follows the applicable retention periods.

Waitlist and updates

Data processed
Email, professional segment, subscription date, and subscription status.
Purpose and legal basis
Sending launch and product updates on the basis of consent (Art. 6(1)(a) GDPR). Consent is optional and may be withdrawn at any time.
Retention
Until consent is withdrawn or the user unsubscribes, and in any event no longer than 24 months after subscription or the latest relevant confirmation or interaction.

Account, authentication, sessions, and authorized applications

Data processed
Verified email, Account identifier, linked identities, passkey public keys and metadata, sessions, application authorizations, and security data.
Purpose and legal basis
Creating and managing the Account, authenticating the User, and performing the contract (Art. 6(1)(b) GDPR); preventing unauthorized access and protecting the Service on the basis of the legitimate interests of Annota AI and its users (Art. 6(1)(f) GDPR).
Retention
For the duration of the Account. Upon closure, access is disabled; identifying profile data is normally deleted or anonymized within 30 days once the User no longer belongs to any organization, subject to legal, security, or legal-defense requirements.

Profile and onboarding

Data processed
Name, avatar, language, role, use case, team size, referral source, and preferences.
Purpose and legal basis
Configuring the experience, providing requested features, and performing the contract (Art. 6(1)(b) GDPR); understanding and improving onboarding and the Service on the basis of Annota AI's legitimate interest (Art. 6(1)(f) GDPR).
Retention
For the duration of the Account and normally up to 30 days after its closure, except for aggregated or effectively anonymous data.

Organizations, roles, and invitations

Data processed
Workspace name and logo, memberships, roles, invitee email addresses, and invitation status.
Purpose and legal basis
Creating and administering workspaces, managing access and collaboration, and performing the contract (Art. 6(1)(b) GDPR); ensuring access security and traceability on the basis of legitimate interest (Art. 6(1)(f) GDPR).
Retention
For the duration of the workspace. Open invitations normally expire after 7 days; essential access information may be retained longer for security, contractual obligations, or protection of legal rights.

Platform delivery

Data processed
Plan, credits, usage events, datasets and their versions, files, images, documents, labels, annotations, instructions, output, OCR results, exports, training configurations and history, metrics, and customer-requested model versions.
Purpose and legal basis
Providing, maintaining, and supporting the requested Service and performing the contract (Art. 6(1)(b) GDPR). For personal data contained in customer materials, Annota AI normally acts as processor and the legal basis is determined by the customer acting as controller.
Retention
For the duration of the relationship and according to customer deletion choices, the Terms, and any applicable DPA. Temporary exports normally expire after 7 days; deletions, backups, and legal obligations may follow different technical timelines.

Subscriptions, credits, payments, and invoices

Data processed
Plan, customer and subscription identifiers, credits, amounts, currency, transaction status, and tax or billing data.
Purpose and legal basis
Entering into and performing the contract (Art. 6(1)(b) GDPR), complying with tax and accounting obligations (Art. 6(1)(c)), and preventing fraud or protecting legal rights (Art. 6(1)(f) GDPR).
Retention
For the duration of the relationship; tax, accounting, and contractual documents are normally retained for 10 years. The payment provider also applies its own retention periods for financial, anti-fraud, and legal obligations.

Operational email and support

Data processed
Email, name, organization, and information strictly necessary to describe the event, request, or outcome of an operation.
Purpose and legal basis
Sending invitations, Account notices, export notices, and notices concerning requested operations; providing support; and performing the contract (Art. 6(1)(b) GDPR). Reliability and support are also pursued on the basis of legitimate interest (Art. 6(1)(f) GDPR).
Retention
For the time required to deliver and manage the event; support correspondence is normally retained for up to 24 months after closure, subject to contractual, legal, or security requirements.

Direct communications

Data processed
Contact details and the content of the communication.
Purpose and legal basis
Responding to data subject requests: pre-contractual measures (Art. 6(1)(b)) or legitimate interest in managing correspondence (Art. 6(1)(f) GDPR), depending on the content.
Retention
Up to 24 months after the request is closed, unless the communication must be retained for a contractual relationship or dispute.

Website and platform delivery and security

Data processed
IP address, technical data, logs, events, and request or session identifiers.
Purpose and legal basis
Providing the systems, maintaining reliability, preventing abuse and incidents, and diagnosing errors; performance of the contract for requested features (Art. 6(1)(b)) and Annota AI's legitimate interest in security and proper system operation (Art. 6(1)(f) GDPR).
Retention
Technical logs are normally retained for up to 30 days; authentication security events for 180 days. Data relating to an incident may be isolated and retained for up to 12 months or longer if necessary to comply with an obligation or protect legal rights.

Preferences and technical browser storage

Data processed
Language, theme, editor preferences, tutorial progress, last-used sign-in method, and technical identifiers for a session or pending invitation.
Purpose and legal basis
Remembering requested settings, maintaining the session, and completing initiated flows; performance of the contract (Art. 6(1)(b)) and legitimate interest in proper interface operation (Art. 6(1)(f) GDPR).
Retention
Depending on the function: for the session; until expiry or sign-out; for 7 days for the sidebar preference; or until the user changes the setting or clears website data.

Legal obligations and protection of rights

Data processed
Data required to respond to privacy requests, authorities, or disputes.
Purpose and legal basis
Complying with legal obligations (Art. 6(1)(c)) and establishing, exercising, or defending legal claims (Art. 6(1)(f) GDPR).
Retention
For the period required by law. Privacy requests and related evidence are normally retained for 5 years; accounting and contractual documents, where applicable, for 10 years.

5. Provision of data and withdrawal of consent

Fields marked as mandatory in the demo form are necessary to respond to the request; without them we cannot handle it. Data required to create and protect the Account, use contractual features, or complete a purchase is necessary to provide the relevant Service. Other profile and onboarding data is optional unless otherwise indicated in the interface.

Joining the waitlist is optional and requires consent to receive updates. Withdrawal does not affect the lawfulness of processing carried out before withdrawal and does not prevent use of other parts of the website.

The customer decides which content to upload to the platform and is responsible for having a valid legal basis, providing required information to data subjects, and complying with restrictions under the Terms and any applicable DPA. Not providing content does not prevent use of the Account but makes the relevant operations impossible.

To withdraw consent, use the unsubscribe link in our messages or write to team@annota.ai. Contact form

6. Recipients and processors

Data is accessible to authorized Annota AI personnel and contractors within the limits required by their duties. It may also be disclosed to the following recipients:

  • Scaleway S.A.S., for the primary cloud infrastructure, including compute, database, and object storage configured in European Union regions.
  • Cloudflare, Inc., for DNS, content delivery, network protection, edge functions, and protected transit of requests and files.
  • Google and GitHub, only when the User chooses to use them to sign in or link an identity to their Account, for the data required by the relevant authentication flow under their respective privacy notices.
  • Stripe Payments Europe, Limited and the relevant Stripe group companies, for checkout, subscriptions, credits, invoicing, tax calculation, fraud prevention, and payment management.
  • Sinch Email, including Mailjet services, for demos, the waitlist, one-time sign-in codes, and operational platform email such as security notices, invitations, and the results of exports or requested processing.
  • Legal, tax, or technical advisers bound by confidentiality, where necessary.
  • Public authorities, supervisory bodies, or entitled parties where required by law.

When they process data on Annota AI's behalf, providers act as processors under an agreement compliant with Article 28 GDPR. Some providers may process data as independent controllers for their own legal or security obligations; in those cases, their own privacy notices apply.

For more information about cloud infrastructure, see the Scaleway privacy notice.

For optional Google sign-in, see the Google privacy notice.

For optional GitHub sign-in, see the GitHub privacy notice.

For more information about payments, see the Stripe privacy notice.

For more information about email services, see the Mailjet privacy policy.

For more information about the network and traffic protection, see the Cloudflare privacy policy.

7. Transfers outside the European Economic Area

Customer content, the primary platform database, and object storage are configured on Scaleway infrastructure in European Union regions. Mailjet states that it stores data for its email services in the European Union. These choices do not, however, mean that all processing connected with the Service takes place exclusively within the European Economic Area.

If you choose Google or GitHub sign-in, those providers may process authentication and technical data outside the European Economic Area under their respective privacy notices. Cloudflare's global network may process technical and traffic data in several countries; Stripe and financial network participants may process payment, billing, and anti-fraud data through international organizations. Authorized personnel or provider group companies may also access data from other countries to the extent necessary.

Where processing involves a transfer to a country not covered by an adequacy decision, Annota AI requires appropriate safeguards under Articles 44 et seq. GDPR, such as the European Commission's Standard Contractual Clauses and, where applicable, participation in the Data Privacy Framework, together with supplementary measures proportionate to the risk.

Information about applicable safeguards may be requested by writing to team@annota.ai. Contact form

8. Cookies and local browser storage

Annota AI does not currently use profiling, advertising, or analytics cookies and does not track users across different websites. For this reason, no cookie consent banner is displayed.

The website and platform use cookies or equivalent technologies to provide requested functions and protect access. Annota AI directly manages protected authentication and session cookies that cannot be accessed by page JavaScript (HttpOnly), are transmitted over HTTPS (Secure), and use SameSite protection. Sessions may last up to 90 days and expire after 30 days of inactivity; temporary cookies protect sign-in and linking flows for up to 10 minutes. The platform also uses a functional cookie to remember sidebar state for 7 days.

Language, theme, editor preferences, tutorial progress, last-used sign-in method, and the identifier of a pending invitation may be stored in local storage. OAuth tokens and authentication-flow security parameters are not stored in the application's local storage or session storage. Preferences remain until the user changes them or clears website data; tutorial progress is removed on sign-out or when switching Accounts.

Users can clear cookies and local storage through browser settings; this may sign the Account out, interrupt an active flow, or reset preferences.

This section will be updated and, where required, consent will be obtained before introducing any analytics, advertising, or profiling tools that are not strictly necessary.

9. Data security

Annota AI adopts technical and organizational measures proportionate to the risks, including access control, data minimization, protection of communications in transit, system updates, credential management, and the use of contractually selected providers.

No Internet-connected system can be considered risk-free. In the event of a personal data breach, Annota AI will apply the procedures required by Articles 33 and 34 GDPR, including notification to the supervisory authority and data subjects where required.

10. Data subject rights

In the cases and within the limits provided by the GDPR, the data subject may request:

  • access to personal data and a copy of it;
  • rectification of inaccurate data or completion of incomplete data;
  • erasure of data;
  • restriction of processing;
  • portability of data provided, where processing is automated and based on consent or a contract;
  • to object, on grounds relating to their particular situation, to processing based on legitimate interest;
  • to object to direct marketing at any time;
  • to withdraw consent at any time.

To exercise these rights, write to team@annota.ai. We may request information necessary to verify the requester's identity. Contact form

Annota AI responds without undue delay and normally within one month. In complex cases or where there are numerous requests, the deadline may be extended by two months, with the data subject informed within the first month. Exercising rights is free of charge, except for manifestly unfounded or excessive requests in the cases permitted by law.

The data subject may also lodge a complaint with the Italian Data Protection Authority or with the supervisory authority of the country where they live or work or where they believe the infringement occurred.

11. Profiling and automated decisions

Annota AI does not use Account, website, or platform data to profile individuals for advertising purposes and does not make decisions based solely on automated processing that produce legal or similarly significant effects on the data subject within the meaning of Article 22 GDPR. AI-assisted features produce output that must be reviewed by the user and are not intended to make such decisions about individuals autonomously.

12. Third-party data, minors, and sensitive data

Anyone who provides another person's personal data must be authorized to do so and must provide that person with the necessary information. Where Annota AI receives data other than directly from the data subject, it complies with the information obligations under Article 14 GDPR where applicable.

The Annota AI website and services are intended for adults and organizations and are not directed to anyone under eighteen years of age. If we become aware of minors' data collected without a valid basis, we delete it or take any other measures required by law.

Do not submit health, biometric, genetic, political opinion, religious, sex life, ethnic origin, trade union membership, criminal conviction or offense data, or other information unnecessary to the request through public forms.

Customers may process third-party data on the platform only if they have a valid legal basis and comply with the DPA, instructions, and applicable measures. Special categories of data, criminal data, or other high-risk content must not be uploaded until the applicable DPA and Plan expressly authorize it and appropriate safeguards have been agreed.

13. Data processed on behalf of customers

Where a customer uses the platform to process personal data for its own purposes, the customer determines the purposes and essential means and normally acts as controller; Annota AI normally acts as processor and follows the customer's documented instructions.

Before uploading third-party personal data, the customer must enter into or accept a Data Processing Agreement compliant with Article 28 GDPR, covering, among other things, instructions, confidentiality, security measures, subprocessors, assistance, incidents, audits, transfers, and deletion or return of data. Data subjects must direct requests relating to customer datasets to the customer, without prejudice to the assistance Annota AI is required to provide.

14. Updates to this notice

Annota AI may update this notice to reflect regulatory, organizational, or technical changes. The current version is published on this page with the date of the latest update.

Material changes will be communicated through proportionate means, for example on the website or by email where we have the relevant contact details. If new processing requires consent, consent will be requested before it begins; continued browsing alone will not be treated as consent.

Before introducing new processing, data categories, or providers, Annota AI will assess the impact on this notice and update it where necessary. If the new processing requires consent, consent will be obtained before it begins.

The Italian version of this Privacy Notice is the only legally valid and authoritative version. In the event of any conflict, ambiguity, or difference in interpretation between it and a translation, the Italian text prevails.