Privacy Notice
Last updated on:8 July 2026
This English translation is provided for convenience only. The Bulgarian version of this Privacy Notice is the legally binding version. In the event of any discrepancy, the Bulgarian text prevails.
This privacy notice (hereinafter referred to as the "Notice", the "Policy" or the "Privacy Policy") is intended to inform you about the way in which we process your personal data.
We collect and use your personal data when you visit our website www.pravenintelekt.com (hereinafter referred to as the "Site") and/or when you use the services of our AI-powered legal assistant at app.pravenintelekt.com, including for legal research, answering questions, and creating and reviewing documents (hereinafter referred to as the "Services"). We also process your personal data when you contact us by email, phone, or through social media.
1. Who are we?
In this privacy policy, "we" means PravenAI EOOD - a single-member limited liability company incorporated under Bulgarian law, UIC 208863384, with registered office and management address at 58 Alabin St., Triaditsa District, 1000 Sofia, Bulgaria.
We are the controller of your personal data and are responsible for collecting and using your personal data as described in this privacy policy. If you have any questions, you can contact us at the email address: [email protected].
In certain cases, third parties may also be controllers of your personal data. In such situations, we recommend that you review their privacy policies.
2. What personal data do we process and about whom?
Within the scope of this Policy, the categories of individuals whose personal data we process, as well as the types of data, can be classified as follows:
2.1. Website visitors
People who visit our Site. We process the following categories of personal data:
Contact data - We collect information such as first name, last name, email address, and other related information when you use our contact form or subscribe to our newsletter. We also collect such data when you register to receive a demo or a free version of any of our Services.
2.2. Users
People who use our Services. We process:
Profile information - If you create an account to use our Services, we process your first name, last name, email address, phone, workplace, password, and a unique user identifier.
Logs and analytics data - We collect information about how you use our Services - for example, how many times you have accepted or rejected suggestions, downloaded reports, viewed documents, asked questions in the chat, etc. We also collect technical information about your device - IP address, browser, operating system, and so on.
Uploaded personal data - This includes any personal data that you yourself share or upload while using the Services - for example, personal data contained in messages sent to our legal research assistant.
Other personal data - When you send us feedback or contact us, we may process additional personal data provided by you for the purpose of improving the Services or responding to your inquiry.
Applicant data - When you apply for a job through the Site or by email, we process the data you provide in your CV, portfolio, short profile, and cover message, for the purposes of reviewing your application and communicating with you.
2.3. Other individuals
This includes potential clients and partners, social media followers, and others. We process:
Contact data - May include first and last name, the name of a legal entity, job title, email address, social media username, and others.
Other personal data - This may be data you have made publicly available (for example on social media or websites), as well as any additional information you provide when communicating with us.
3. What data sources do we use?
We primarily process personal data that you yourself provide to us when you use our Site and/or Services, or when you contact us by email. In addition, we may also collect information from publicly available sources - for example social media, other web pages, commercial registers, and others.
In connection with the transfer of the Praven Intelekt product to PravenAI EOOD as of 8 July 2026, we may receive and process personal data, client files, client case data, client archives, email correspondence, and related records transferred or migrated from CuratedAI B.V. to PravenAI EOOD in compliance with applicable personal data protection law.
4. Why do we process your data and on what legal basis?
We process personal data for the following purposes and on the following legal bases:
Provision and maintenance of the Services - We process personal data in order to provide, administer, maintain, and protect our Services, as well as to fulfil our obligations under the relevant contracts and terms. The legal basis for this processing is the performance of a contract.
Security and operation of the Site and Services - We use personal data to maintain the security and stability of our Site and Services - including to detect and prevent malware, illegal content, abuse, and other harmful activity. We also use your data to respond to inquiries, to notify you about service-related matters, to invite you to provide feedback or opinions, as well as for the purpose of improving and developing the Services and for statistical analysis. The legal basis here is our legitimate interest.
Applications and recruitment - We process data from submitted applications in order to assess professional profile, experience, and potential collaboration. For applications submitted through the Site, the primary legal basis is your explicit consent given in the application form. If you contact us directly about a role, we may also process the data to take steps at your request before a possible contract.
Marketing and communication - We process personal data in order to promote our brand and Services, including by sending marketing messages and newsletters and analysing user activity. The legal basis for this processing is your consent. You can withdraw your consent at any time through the cookie settings or via the unsubscribe link in any marketing email.
Compliance with legal obligations - We process personal data in order to comply with our legal obligations, for example to comply with court decisions, orders, or requests from competent authorities, applicable legislation, and others. The legal basis is compliance with a legal obligation to which we are subject.
Other purposes - For any purpose other than those listed above (including the use of personal data for training and fine-tuning our AI model), we will request your explicit consent.
5. With whom do we share your personal data?
As a rule, we do not share your personal data with third parties, except for providers who assist us in processing it. Anyone who has access to your personal data is bound by strict legal or contractual obligations to ensure its security and confidentiality.
We share your personal data, in whole or in part, with the following third parties, while always taking the necessary measures to protect your privacy:
Azure OpenAI Service - Your questions, generated content, and uploaded documents are processed through Azure OpenAI for the purpose of providing the Services. The service is hosted and managed by Microsoft within the Azure environment, with servers in Sweden, and has no connection to other OpenAI services such as ChatGPT or the OpenAI API. To be clear: your data (personal and non-personal):
- are NOT shared with other customers;
- are NOT accessible to OpenAI and are not used to train OpenAI models;
- are NOT used to train or improve the underlying Azure OpenAI models;
- are NOT used to improve products or services of Microsoft or third parties without your explicit consent or instruction.
For more information, see: Data, privacy, and security for Azure OpenAI Service and Microsoft Products and Services Data Protection Addendum.
Posthog - We use Posthog, with servers based in Frankfurt, Germany, to understand how users interact with our Site and Services. They help us collect data on behaviour, page visits, session duration, and other interactions. This information is generally anonymised and does not identify you directly. You can find more information at Posthog Privacy Policy.
Newsletters and marketing - If you have consented to receive our newsletters or marketing materials, we may share your email address and the necessary data with our email marketing service provider. These providers are bound by data protection agreements and are entitled to use your information solely for the purpose of sending communications on our behalf, without sharing it with other parties. You can unsubscribe at any time via the unsubscribe link included in every email, or by contacting us directly.
6. International data transfers
We process and store your personal data within the European Economic Area (EEA), using servers located in Germany and Sweden.
If a transfer of personal data outside the EEA becomes necessary, we will use appropriate transfer mechanisms that ensure compliance with the applicable personal data protection legislation. Such mechanisms include:
- (i) transferring data to a country for which the European Commission has adopted an adequacy decision, or
- (ii) transferring to a recipient who has signed Standard Contractual Clauses approved by the European Commission.
You can request access to the relevant transfer documentation by contacting us at [email protected].
7. Security measures
We take the security of your personal data seriously and have implemented comprehensive technical and organisational measures for its protection. All data is stored and processed solely within the European Union, in accordance with the requirements of the General Data Protection Regulation (GDPR).
Our infrastructure is hosted by Microsoft Azure - Sweden, which holds ISO 27001, SOC 1, 2, and 3 certifications, guaranteeing a high level of security in the storage and processing of data. You can learn more about Microsoft's security standards at the following link: Data Protection and Security in Microsoft Azure.
To protect data "at rest" we use AES-256 encryption, and for data "in transit" - SSL/TLS protocols. We also apply multi-factor authentication (MFA) and continuous 24/7 monitoring to detect potential threats. For enterprise clients, we offer separate and isolated environments that ensure complete data segregation and prevent unauthorised access between different clients.
8. How long do we keep your personal data?
We process your personal data only for as long as is necessary to fulfil the purposes described in this policy, or - where processing is based on consent - until the moment you withdraw it. Personal data collected through other channels - for example our website, social media, or email correspondence - is kept for as long as is necessary to maintain our relationship with you, to respond to inquiries, or in view of future communications.
Once these purposes no longer apply, the data will be de-identified, unless we are required by law to retain it for a longer period.
9. Your rights regarding your personal data
You have the following rights in relation to your personal data, which you can exercise at any time:
Right of access - You have the right to obtain information about whether we process your personal data, as well as a copy of it.
Right to rectification - If the data we hold about you is inaccurate or incomplete, you can request its correction.
Right to erasure ("right to be forgotten") - You can request the deletion of your personal data when it is no longer needed or when you have withdrawn your consent.
Right to data portability - You have the right to receive your data in a structured and machine-readable format and/or to have us transfer it to another controller, where technically feasible.
Right to object - You can object to the processing, particularly where it is carried out on the basis of our legitimate interest. Upon objection, we will cease the processing, unless we demonstrate that we have compelling grounds to continue it.
Right to restriction of processing - You can request a temporary suspension of the processing under certain circumstances (for example, when contesting the accuracy of the data).
Right to withdraw consent - If we process your data on the basis of consent, you have the right to withdraw it at any time. This does not affect the lawfulness of the processing carried out before the withdrawal.
If you wish to exercise any of the rights described above, you can contact us at the email address: [email protected].
If you believe that we are processing your personal data in breach of the applicable personal data protection legislation, you have the right to lodge a complaint with the national personal data protection supervisory authority.
In Bulgaria, this is the Commission for Personal Data Protection (CPDP / КЗЛД). You can contact the CPDP using the following details:
Address: 2 Prof. Tsvetan Lazarov Blvd, 1592 Sofia
Phone: +359 2 91 53 518
Email: [email protected]
Website: www.cpdp.bg
10. Changes to the Privacy Notice
We reserve the right to amend this Notice at any time. All updates will be published on our Site, and where necessary we will also notify you by email.
If you have any questions or requests related to the processing of personal data, please do not hesitate to contact us at [email protected].
Ready to start working faster and more efficiently?
Your expertise is too valuable to be consumed by repetitive work. Cut the routine and free up time for what truly matters: strategic thinking, practical advice, and building trust.