Privacy Policy

Effective date: 28.05.2026
Last updated: 28.05.2026

This Privacy Policy explains how SIA 99articles ("99articles", "we", "us", "our") collects, uses, shares and protects personal data when you use our website https://99articles.io and the 99articles service (the "Service").

We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums), and other applicable laws.

 

1. Data controller and contact

The data controller is:
SIA 99articles  
Registration No:  40203703065 
Contact:  hi@99articles.io 

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. For all questions about this Policy, your data, or to exercise any of the rights described in Section 8, please contact hi@99articles.io.

 

2. The data we collect

2.1. Account data
When you create an Account, we collect your email address and a securely hashed password, together with any optional profile information you choose to provide, your Account creation date and your language preference.

2.2. Subscription and billing data
When you subscribe to a paid plan, the following data is processed via our payment provider Stripe: billing name and country, VAT number (for business customers), the last four digits, brand and expiry of your payment card (for display only), and your plan, Credits balance and invoice history. We do not store full paymentcard numbers or CVC — these are handled directly by Stripe (PCIDSS Level 1 certified).

2.3. User Content (Input and Output)

Input files (audio, video, YouTube URLs) you submit for processing are transmitted to our processing pipeline and to OpenAI for analysis, and are deleted immediately after processing. We do not retain Input files.

Output (the generated text/articles) is stored within your Account on our infrastructure.

We do not use User Content or Output to train AI models. Our AI processor, OpenAI, processes your Input under a Data Processing Agreement with Zero Data Retention enabled, meaning your Input is not retained by OpenAI after processing and is not used to train its models.

2.4. Technical and usage data

When you use the Service we automatically collect your IP address (truncated where feasible), device, browser type and operating system, referring URL, pages viewed, timestamps, Credits consumed, and request metadata (e.g., file duration, detected language — not the content itself), as well as error logs (which may contain technical identifiers but not User Content).

2.5. Communications

If you contact us, we keep a record of the correspondence (your email, message content and any attachments) for support, legal compliance and quality purposes.

2.6. Cookies

See Section 9.

 

3. Why we process your data and on what legal basis

 Purpose  Categories of data  Legal basis (GDPR Art. 6) 

 Creating and operating your Account; providing the Service  Account data, User Content, technical data  (b) performance of a contract 

 Processing payments and managing Subscriptions  Billing data  (b) contract; (c) legal obligation (tax/accounting) 

 Sending servicerelated (transactional) emails  Account data  (b) performance of a contract 

 Securing the Service, preventing fraud and abuse, debugging  Technical and usage data  (f) legitimate interests (operating a secure, reliable service) 

 Complying with legal obligations (tax, accounting, lawful requests)  Billing data, account data  (c) legal obligation 

 Defending or asserting legal claims  All relevant data  (f) legitimate interests; (c) legal obligation 

 Sending occasional product updates (only if you opt in)  Email address  (a) consent (withdrawable at any time) 

 Improving the Service through aggregated, nonidentifying analysis  Technical data (aggregated)  (f) legitimate interests 

Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interest does not override your rights. You may request information about that balancing test at hi@99articles.io and may object at any time (see Section 8).

 

4. How long we keep your data

Data  Retention 

Input files (audio, video, URLs)  Deleted immediately after processing. Not stored. 

Output (generated articles)  For as long as your Account exists; deleted within 30 days of Account deletion. 

Account data  For as long as your Account exists; deleted within 30 days of Account deletion, except where longer retention is legally required. 

Billing/invoice data Retained for 5 years after the relevant transaction, in accordance with Latvian accounting law. 

Technical/usage logs  Up to 12 months, then deleted or anonymised. 

Support correspondence  Up to 3 years after the matter is closed. 

Backups  Rotated and overwritten on a rolling basis (typically within 30 days). 

Where you exercise your right to erasure (Section 8) we will delete or anonymise your data within 30 days, except where mandatory legal retention obligations apply.

 

5. Who we share data with (recipients and processors)

We share personal data only with the following recipients, who act either as our processors (Article 28 GDPR) or as independent controllers in respect of their own processing.

Recipient  Role  Purpose  Location 

OpenAI Ireland Limited (with U.S. affiliate OpenAI, L.L.C.)  Processor  AI processing of Input via Whisper and language models; Zero Data Retention; no training on your data  EU / U.S. (with SCCs) 

Stripe Payments Europe, Ltd.  Independent controller for payments  Payment processing  EU (Ireland) / U.S. (with SCCs) 

Hetzner Online GmbH  Processor  Application hosting and data storage  Germany (EU) 

Tax authorities, courts, lawenforcement  Independent controllers  Where required by law  Latvia / EU 

Professional advisors (lawyers, accountants)  Bound by confidentiality  Legal / accounting  EU 

We do not currently use any other subprocessors (for email delivery, analytics, monitoring, support or backups). If this changes, we will update this Policy and the list above before the new recipient begins processing. We do not sell personal data and do not share personal data with advertisers for advertising purposes.

A current list of subprocessors is available on request at hi@99articles.io.

 

6. International data transfers

Our hosting (Hetzner) is located within the EU, so no transfer outside the EEA occurs for storage. However, some processors (in particular OpenAI, and possibly Stripe) may process personal data outside the EEA, including in the United States.

Where personal data is transferred outside the EEA to a country without a European Commission adequacy decision, we put in place appropriate safeguards under Article 46 GDPR, including the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914/EU), supplemented by additional technical and organisational measures where appropriate, and, where applicable, reliance on the EU–U.S. Data Privacy Framework for certified recipients. A copy of the relevant safeguards is available on request at hi@99articles.io.

 

 7. Security

We implement appropriate technical and organisational measures to protect personal data (Article 32 GDPR), including:

TLS encryption in transit and encryption at rest;

access controls and the principle of least privilege;

regular, encrypted backups;

logging and monitoring of administrative access;

vetting of processors and contractual security commitments; and

prompt patching of dependencies and infrastructure.

Please note: the Service does not use end-to-end or "zero-knowledge" encryption. This means that, although your data is encrypted at rest and access is restricted to authorized personnel on a need-to-know basis, our authorized personnel and processors are technically able to access stored data where necessary to operate, secure, support or provide the Service, or to comply with law. No system is perfectly secure.

In the event of a personal data breach likely to result in a risk to your rights, we will notify the Latvian Data State Inspectorate (Datu valsts inspekcija) within 72 hours and, where required, notify affected Users without undue delay (Articles 33–34 GDPR).

 

8. Your rights

Under the GDPR you have the right to: access your data (Art. 15); rectification of inaccurate or incomplete data (Art. 16); erasure in certain circumstances (Art. 17); restriction of processing (Art. 18); data portability (Art. 20); object to processing based on our legitimate interests, including at any time to direct marketing (Art. 21); withdraw consent at any time where processing is based on consent, without affecting prior lawful processing (Art. 7(3)); and not to be subject to solely automated decisions with legal or similarly significant effects (Art. 22). We do not make such automated decisions about you; the generation of Output by AI is not a decision producing legal effects concerning you.

How to exercise your rights. Email hi@99articles.io. We will respond within one (1) month (extendable by two months for complex requests, with notice). We may ask you to verify your identity. There is no charge unless your request is manifestly unfounded or excessive.

Right to complain. You may lodge a complaint with a supervisory authority, in particular in your Member State of habitual residence, place of work or place of the alleged infringement. The Latvian authority is:

> Datu valsts inspekcija (Data State Inspectorate)

> Elijas iela 17, Riga, LV1050, Latvia

> Email: pasts@dvi.gov.lv — https://www.dvi.gov.lv/

 

9. Cookies and similar technologies

Our website uses strictly necessary cookies (for authentication, session management, security and load balancing), which do not require consent. We may also use nonessential cookies (for example, to remember preferences or to measure usage). Where we do, we request your consent first through our cookie consent banner, and you can change or withdraw your choice at any time via the cookie settings on our website.

We do not currently use advertising or thirdparty tracking cookies for marketing purposes. If this changes, we will update this Policy and our consent banner accordingly.

 

10. Children

The Service is not directed at children under 16 years of age, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact hi@99articles.io and we will delete it.

 

11. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date will reflect the latest version. We will notify you of material changes by email and/or inapp notice at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

 

12. Contact

> SIA 99articles

> Email: hi@99articles.io