Privacy Policy

Last updated: 9 August 2026

This Privacy Policy explains how Mystery Tech OÜ processes personal data in connection with Subsidy Scoop under the EU General Data Protection Regulation (GDPR) and other applicable data-protection law.

1. Controller

Mystery Tech OÜ
Pärnu mnt. 139c - 14
Tallinn 11317
Estonia

Register code: 16176764
VAT number: EE102570111
Privacy contact: contact@mysterytech.io

2. Personal Data We Process

Depending on how you use the Service, we may process: contact/account data such as email address and login identifiers; business-profile data such as company name, website, location, employee range, revenue range, company age, industry, project plans and budget; publicly accessible website information; scan inputs and generated report data; transaction and billing metadata received from Stripe; correspondence and support messages; and technical/security data such as IP address, browser/device information, timestamps, session identifiers, consent preferences and security logs.

3. Sources of Data

We receive data directly from you; from public company websites you ask us to analyse; from official or other identified funding sources used to produce the Service; and from service providers such as Stripe where necessary to confirm or administer a transaction.

4. Purposes and Legal Bases

Contract: to analyse your business, perform the requested scan, generate and deliver a report, maintain access to purchased content, and provide support.

Legitimate interests: to secure the Service, prevent fraud and abuse, diagnose errors, maintain audit trails, improve reliability, understand aggregate product performance and administer our business, where those interests are not overridden by your rights.

Legal obligation: to retain and disclose records required for accounting, tax, legal and regulatory purposes.

Consent: where required for non-essential cookies, optional analytics/marketing technologies, or marketing communications. You may withdraw consent at any time.

5. Automated Analysis and Profiling

We use automated rules and AI-assisted systems to interpret business information, classify project characteristics, calculate profile-match scores, estimate potentially relevant funding amounts and rank opportunities. These outputs do not make a legal or similarly significant decision about you. They are recommendations for business information purposes; the relevant funding body makes the actual funding decision.

6. Recipients and Service Providers

We disclose personal data only where necessary to operate the Service, comply with law, or protect legitimate interests. Relevant providers include Stripe for payment processing and fraud prevention, and Lovable and the technical infrastructure configured through the application for development, hosting, deployment or related platform functions. We may also use database, hosting, transactional-email, security, error-monitoring or analytics providers. We do not sell personal data.

7. Stripe

For European payment processing, Stripe may act as a processor and/or independent controller depending on the activity. Payment data may include identity/contact information, billing details, IP/device information, transaction details and fraud-prevention signals. Full payment-card details are ordinarily collected and processed by Stripe rather than stored by Mystery Tech OÜ.

8. International Transfers

Some service providers may process data outside Estonia or the European Economic Area. Where required, transfers are protected by an applicable adequacy decision, the EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where valid and applicable, or another lawful transfer mechanism.

9. Retention

We apply the following operational retention periods unless a longer period is required by law, needed to establish or defend legal claims, or you request earlier deletion where legally available:

  • Funding scans and reports: up to 24 months after the last relevant account or report activity.
  • Account/profile data: while the account is active; after deletion, removed from active systems within approximately 30 days, subject to limited backup/security retention.
  • Support correspondence: generally up to 24 months after resolution.
  • Security and technical logs: generally up to 90 days, unless longer retention is necessary to investigate abuse or security incidents.
  • Cookie/consent records: for the period reasonably necessary to demonstrate and respect your preferences.
  • Accounting and transaction records: retained for the period required by Estonian law; accounting source documents and relevant business records are generally preserved for seven years from the end of the relevant financial year.

10. Your Rights

Where the GDPR applies, you may have rights to access your data, correct inaccurate data, request deletion, restrict processing, object to processing based on legitimate interests, receive portable data where the legal conditions apply, and withdraw consent at any time where consent is the legal basis. You also have the right to lodge a complaint with a competent supervisory authority. To exercise a right, contact contact@mysterytech.io. We may request reasonable information to verify your identity.

For privacy or deletion requests: contact@mysterytech.io.

11. Supervisory Authority

In Estonia, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Complaints may be submitted in accordance with the Inspectorate's procedures. You may also be entitled to contact another competent supervisory authority in the EEA depending on your circumstances.

12. Requirement to Provide Data

Certain information is necessary to perform the requested scan or complete a purchase. If you do not provide information required for matching, billing or account access, we may be unable to provide the relevant feature. Optional data is identified as such where practical.

13. Security

We use reasonable technical and organisational measures intended to protect personal data, including access controls, secure service-provider integrations and server-side handling of sensitive credentials. No internet service can guarantee absolute security.

14. Data Breaches

Where a personal-data breach creates notification obligations under applicable law, we will follow the applicable GDPR breach-assessment and notification requirements.

15. Children

Subsidy Scoop is a B2B service and is not directed to children.

16. Changes to this Policy

We may update this Privacy Policy when our processing, providers, Service or legal obligations change. The current version and effective date will be available on the website.

17. Contact

For privacy requests, questions or complaints, contact contact@mysterytech.io.