Skip to content

Legal information

Privacy Notice

Last updated: July 28, 2026

This notice describes how Annota processes the personal data of people who visit the Annota.ai website, request a demo, join the waitlist, create an account, use the platform, make purchases, or contact us. It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).

Annota acts as controller for data relating to its relationship with users and customers, including account, security, service usage, support, and billing data. Where it processes personal data contained in datasets or other content uploaded by a customer for purposes determined by that customer, Annota generally acts as processor pursuant to Article 28 GDPR.

The Italian version of this Privacy Notice is the only legally valid and authoritative version. Translations are provided solely for convenience.

1. Controller and contact details

The data controller is Annota S.r.l., with registered office at Via Davide Lazzeretti 2/P, 58100 Grosseto, EU VAT No. IT01783380536, Italian Tax Code 01783380536, Grosseto Companies Register (REA) No. GR-236295, fully paid-up share capital of €10.000,00, certified email (PEC) annotasrl@pec.it.

  • Privacy email: team@annota.ai
  • Certified email (PEC): annotasrl@pec.it

Annota has not currently appointed a Data Protection Officer (DPO). Privacy-related requests may be sent using the contact details above.

2. Scope of this notice and privacy roles

Annota acts as controller when it determines the purposes and means of processing data relating to the website, Accounts, contractual relationship, platform management, billing, communications, and the security of its systems.

This notice does not govern processing carried out by third-party websites or services reached through links, which operate under their own notices. Providers appointed by Annota to deliver parts of the website or communications are instead listed in the section on recipients.

The contractual conditions governing the website and services are available in the Terms and Conditions.

3. Data processed and sources

We process only data relevant to the activities described in this notice. Data may come from the data subject, the organization for which they work, the systems used to access the Service and, for identity, payment, and security data, from providers used by Annota.

  • Identification, contact, and authentication data: name, email address, identity identifier, sessions, and information required to verify access.
  • Profile and onboarding data: avatar, language, role, use case, team size, referral source, and other optional information provided by the user.
  • Organization and collaboration data: workspace name and logo, memberships, roles, invitations, and member or invitee email addresses.
  • Contractual and usage data: Plan, subscription status, credits, features used, operations performed, requests, identifiers, and dates of application events.
  • Billing and payment data: customer and subscription identifiers, amounts, currency, payment status and, at the payment provider, name or business name, billing email, address, tax code or VAT number, tax ID, and payment instrument data.
  • Customer content: datasets, files, images, documents, text, names and descriptions, labels, annotations, instructions, output, OCR results, and exports.
  • Preferences and consents: waitlist segment, subscription, withdrawal or unsubscribe status, and interface preferences.
  • Communications data: content of requests sent to Annota and subsequent replies.
  • Technical and security data: IP address, date and time, requested URL, technical headers, request or session identifiers, browser or device type, logs, and events required to prevent abuse and diagnose errors.

Annota does not receive complete card details used through the payment system. We also do not ask users to enter special categories of personal data, data relating to criminal convictions or offenses, credentials, or identity documents in public forms. Please do not submit such information through website forms.

4. Purposes, legal bases, and retention

ActivityData processedPurpose and legal basisRetention
Demo requestFirst name, last name, email and, if provided, company, industry, and message.Handling the request, arranging the demo, and taking pre-contractual steps requested by the data subject (Art. 6(1)(b) GDPR).Up to 24 months after the last substantive contact. If a contractual relationship is established, the data becomes part of the relevant documentation and follows the applicable retention periods.
Waitlist and updatesEmail, professional segment, subscription date, and subscription status.Sending launch and product updates on the basis of consent (Art. 6(1)(a) GDPR). Consent is optional and may be withdrawn at any time.Until consent is withdrawn or the user unsubscribes, and in any event no longer than 24 months after subscription or the latest relevant confirmation or interaction.
Account, authentication, and sessionsEmail, identity identifier, access, session, and security data.Creating and managing the Account, authenticating the User, and performing the contract (Art. 6(1)(b) GDPR); preventing unauthorized access and protecting the Service on the basis of the legitimate interests of Annota and its users (Art. 6(1)(f) GDPR).For the duration of the Account. Upon closure, access is disabled; identifying profile data is normally deleted or anonymized within 30 days once the User no longer belongs to any organization, subject to legal, security, or legal-defense requirements.
Profile and onboardingName, avatar, language, role, use case, team size, referral source, and preferences.Configuring the experience, providing requested features, and performing the contract (Art. 6(1)(b) GDPR); understanding and improving onboarding and the Service on the basis of Annota's legitimate interest (Art. 6(1)(f) GDPR).For the duration of the Account and normally up to 30 days after its closure, except for aggregated or effectively anonymous data.
Organizations, roles, and invitationsWorkspace name and logo, memberships, roles, invitee email addresses, and invitation status.Creating and administering workspaces, managing access and collaboration, and performing the contract (Art. 6(1)(b) GDPR); ensuring access security and traceability on the basis of legitimate interest (Art. 6(1)(f) GDPR).For the duration of the workspace. Open invitations normally expire after 7 days; essential access information may be retained longer for security, contractual obligations, or protection of legal rights.
Platform deliveryPlan, credits, usage events, datasets, files, images, documents, labels, annotations, instructions, output, OCR results, and exports.Providing, maintaining, and supporting the requested Service and performing the contract (Art. 6(1)(b) GDPR). For personal data contained in customer materials, Annota normally acts as processor and the legal basis is determined by the customer acting as controller.For the duration of the relationship and according to customer deletion choices, the Terms, and any applicable DPA. Temporary exports normally expire after 7 days; deletions, backups, and legal obligations may follow different technical timelines.
Subscriptions, credits, payments, and invoicesPlan, customer and subscription identifiers, credits, amounts, currency, transaction status, and tax or billing data.Entering into and performing the contract (Art. 6(1)(b) GDPR), complying with tax and accounting obligations (Art. 6(1)(c)), and preventing fraud or protecting legal rights (Art. 6(1)(f) GDPR).For the duration of the relationship; tax, accounting, and contractual documents are normally retained for 10 years. The payment provider also applies its own retention periods for financial, anti-fraud, and legal obligations.
Operational email and supportEmail, name, organization, and information strictly necessary to describe the event, request, or outcome of an operation.Sending invitations, Account notices, export notices, and notices concerning requested operations; providing support; and performing the contract (Art. 6(1)(b) GDPR). Reliability and support are also pursued on the basis of legitimate interest (Art. 6(1)(f) GDPR).For the time required to deliver and manage the event; support correspondence is normally retained for up to 24 months after closure, subject to contractual, legal, or security requirements.
Direct communicationsContact details and the content of the communication.Responding to data subject requests: pre-contractual measures (Art. 6(1)(b)) or legitimate interest in managing correspondence (Art. 6(1)(f) GDPR), depending on the content.Up to 24 months after the request is closed, unless the communication must be retained for a contractual relationship or dispute.
Website and platform delivery and securityIP address, technical data, logs, events, and request or session identifiers.Providing the systems, maintaining reliability, preventing abuse and incidents, and diagnosing errors; performance of the contract for requested features (Art. 6(1)(b)) and Annota's legitimate interest in security and proper system operation (Art. 6(1)(f) GDPR).Normally up to 30 days. Data relating to a security event may be isolated and retained for up to 12 months or longer if necessary to comply with an obligation or protect legal rights.
Preferences and technical browser storageLanguage, theme, editor preferences, and technical identifiers for a session or pending invitation.Remembering requested settings, maintaining the session, and completing initiated flows; performance of the contract (Art. 6(1)(b)) and legitimate interest in proper interface operation (Art. 6(1)(f) GDPR).Depending on the function: for the session; until expiry or sign-out; for 7 days for the sidebar preference; or until the user changes the setting or clears website data.
Legal obligations and protection of rightsData required to respond to privacy requests, authorities, or disputes.Complying with legal obligations (Art. 6(1)(c)) and establishing, exercising, or defending legal claims (Art. 6(1)(f) GDPR).For the period required by law. Privacy requests and related evidence are normally retained for 5 years; accounting and contractual documents, where applicable, for 10 years.

5. Provision of data and withdrawal of consent

Fields marked as mandatory in the demo form are necessary to respond to the request; without them we cannot handle it. Data required to create and protect the Account, use contractual features, or complete a purchase is necessary to provide the relevant Service. Other profile and onboarding data is optional unless otherwise indicated in the interface.

Joining the waitlist is optional and requires consent to receive updates. Withdrawal does not affect the lawfulness of processing carried out before withdrawal and does not prevent use of other parts of the website.

The customer decides which content to upload to the platform and is responsible for having a valid legal basis, providing required information to data subjects, and complying with restrictions under the Terms and any applicable DPA. Not providing content does not prevent use of the Account but makes the relevant operations impossible.

To withdraw consent, use the unsubscribe link in our messages or write to team@annota.ai.

6. Recipients and processors

Data is accessible to authorized Annota personnel and contractors within the limits required by their duties. It may also be disclosed to the following recipients:

  • Scaleway S.A.S., for the primary cloud infrastructure, including compute, database, and object storage configured in European Union regions.
  • Cloudflare, Inc., for DNS, content delivery, network protection, edge functions, and protected transit of requests and files.
  • Clerk, Inc., for identity, authentication, session management, and access security.
  • Stripe Payments Europe, Limited and the relevant Stripe group companies, for checkout, subscriptions, credits, invoicing, tax calculation, fraud prevention, and payment management.
  • Sinch Email, including Mailjet services, for demos, the waitlist, and operational platform email such as invitations, notices, and the results of exports or requested processing.
  • Legal, tax, or technical advisers bound by confidentiality, where necessary.
  • Public authorities, supervisory bodies, or entitled parties where required by law.

When they process data on Annota's behalf, providers act as processors under an agreement compliant with Article 28 GDPR. Some providers may process data as independent controllers for their own legal or security obligations; in those cases, their own privacy notices apply.

For more information about cloud infrastructure, see the Scaleway privacy notice.

For more information about identity and authentication, see the Clerk privacy notice.

For more information about payments, see the Stripe privacy notice.

For more information about email services, see the Mailjet privacy policy.

For more information about the network and traffic protection, see the Cloudflare privacy policy.

7. Transfers outside the European Economic Area

Customer content, the primary platform database, and object storage are configured on Scaleway infrastructure in European Union regions. Mailjet states that it stores data for its email services in the European Union. These choices do not, however, mean that all processing connected with the Service takes place exclusively within the European Economic Area.

Clerk is based in the United States; Cloudflare's global network may process technical and traffic data in several countries; Stripe and financial network participants may process payment, billing, and anti-fraud data through international organizations. Authorized personnel or provider group companies may also access data from other countries to the extent necessary.

Where processing involves a transfer to a country not covered by an adequacy decision, Annota requires appropriate safeguards under Articles 44 et seq. GDPR, such as the European Commission's Standard Contractual Clauses and, where applicable, participation in the Data Privacy Framework, together with supplementary measures proportionate to the risk.

Information about applicable safeguards may be requested by writing to team@annota.ai.

8. Cookies and local browser storage

Annota does not currently use profiling, advertising, or analytics cookies and does not track users across different websites. For this reason, no cookie consent banner is displayed.

The website and platform use only cookies or equivalent technologies required to provide requested functions and protect access. In particular, Clerk uses technical authentication and session cookies and identifiers; the platform uses a functional cookie to remember sidebar state for 7 days.

Language, theme, editor preferences, session tokens, and the identifier of a pending invitation may be stored in local storage. The PKCE security parameters and nonce required for the authentication flow are stored temporarily in session storage. Data remains according to its function: for the session, until expiry or sign-out, or until the user changes the setting or clears website data.

Users can clear cookies and local storage through browser settings; this may sign the Account out, interrupt an active flow, or reset preferences.

This section will be updated and, where required, consent will be obtained before introducing any analytics, advertising, or profiling tools that are not strictly necessary.

9. Data security

Annota adopts technical and organizational measures proportionate to the risks, including access control, data minimization, protection of communications in transit, system updates, credential management, and the use of contractually selected providers.

No Internet-connected system can be considered risk-free. In the event of a personal data breach, Annota will apply the procedures required by Articles 33 and 34 GDPR, including notification to the supervisory authority and data subjects where required.

10. Data subject rights

In the cases and within the limits provided by the GDPR, the data subject may request:

  • access to personal data and a copy of it;
  • rectification of inaccurate data or completion of incomplete data;
  • erasure of data;
  • restriction of processing;
  • portability of data provided, where processing is automated and based on consent or a contract;
  • to object, on grounds relating to their particular situation, to processing based on legitimate interest;
  • to object to direct marketing at any time;
  • to withdraw consent at any time.

To exercise these rights, write to team@annota.ai. We may request information necessary to verify the requester's identity.

Annota responds without undue delay and normally within one month. In complex cases or where there are numerous requests, the deadline may be extended by two months, with the data subject informed within the first month. Exercising rights is free of charge, except for manifestly unfounded or excessive requests in the cases permitted by law.

The data subject may also lodge a complaint with the Italian Data Protection Authority or with the supervisory authority of the country where they live or work or where they believe the infringement occurred.

11. Profiling and automated decisions

Annota does not use Account, website, or platform data to profile individuals for advertising purposes and does not make decisions based solely on automated processing that produce legal or similarly significant effects on the data subject within the meaning of Article 22 GDPR. AI-assisted features produce output that must be reviewed by the user and are not intended to make such decisions about individuals autonomously.

12. Third-party data, minors, and sensitive data

Anyone who provides another person's personal data must be authorized to do so and must provide that person with the necessary information. Where Annota receives data other than directly from the data subject, it complies with the information obligations under Article 14 GDPR where applicable.

The Annota website and services are intended for adults and organizations and are not directed to anyone under eighteen years of age. If we become aware of minors' data collected without a valid basis, we delete it or take any other measures required by law.

Do not submit health, biometric, genetic, political opinion, religious, sex life, ethnic origin, trade union membership, criminal conviction or offense data, or other information unnecessary to the request through public forms.

Customers may process third-party data on the platform only if they have a valid legal basis and comply with the DPA, instructions, and applicable measures. Special categories of data, criminal data, or other high-risk content must not be uploaded until the applicable DPA and Plan expressly authorize it and appropriate safeguards have been agreed.

13. Data processed on behalf of customers

Where a customer uses the platform to process personal data for its own purposes, the customer determines the purposes and essential means and normally acts as controller; Annota normally acts as processor and follows the customer's documented instructions.

Before uploading third-party personal data, the customer must enter into or accept a Data Processing Agreement compliant with Article 28 GDPR, covering, among other things, instructions, confidentiality, security measures, subprocessors, assistance, incidents, audits, transfers, and deletion or return of data. Data subjects must direct requests relating to customer datasets to the customer, without prejudice to the assistance Annota is required to provide.

14. Updates to this notice

Annota may update this notice to reflect regulatory, organizational, or technical changes. The current version is published on this page with the date of the latest update.

Material changes will be communicated through proportionate means, for example on the website or by email where we have the relevant contact details. If new processing requires consent, consent will be requested before it begins; continued browsing alone will not be treated as consent.

Before introducing new processing, data categories, or providers, Annota will assess the impact on this notice and update it where necessary. If the new processing requires consent, consent will be obtained before it begins.

The Italian version of this Privacy Notice is the only legally valid and authoritative version. In the event of any conflict, ambiguity, or difference in interpretation between it and a translation, the Italian text prevails.