charlie

Privacy Policy

Last updated: March 19, 2026

1. Who We Are

Charlie OÜ ("Charlie", "we", "us") is the data controller for the personal data processed through the Charlie email marketing service and the website charlieai.co.

Charlie OÜ
Lahepea 9, 10617 Tallinn, Estonia
Reg. 17461722 | VAT: EE102966275
Email: hello@charlieai.co

2. What Data We Collect

When you join our waitlist or sign up: email address, name (if provided), and the timestamp of your signup.

When you become a client: phone number (for WhatsApp communication), business name, Shopify store URL, Klaviyo API credentials, brand assets (logos, colors, images), campaign briefs (text, voice notes, images sent via WhatsApp), and billing information processed by Stripe.

When you visit our website: standard analytics data collected via Google Analytics (pages visited, browser type, approximate location) and cookies set by our analytics and marketing tools (SalesManago).

When using WhatsApp: message content (text, voice notes, images), phone number, and conversation history necessary to deliver the Service.

3. How We Use Your Data

We use your data to deliver the email marketing service you subscribe to, generate email campaigns based on your briefs and product data, communicate with you via WhatsApp, email, and dashboard, process payments through Stripe, monitor your competitors' public newsletters (if subscribed to this add-on), improve our service quality, and send you service-related communications.

4. Legal Basis for Processing

Contract performance: processing your data is necessary to deliver the Service you have subscribed to.

Legitimate interest: analytics, service improvement, and fraud prevention.

Consent: marketing communications and waitlist signup. You can withdraw consent at any time by contacting us or unsubscribing.

5. Data Sharing

We share data only with service providers necessary to deliver the Service:

Stripe — payment processing (Stripe, Inc., USA). Stripe's privacy policy applies to payment data.

Twilio — WhatsApp messaging (Twilio, Inc., USA). Message content is transmitted through Twilio's infrastructure.

Anthropic — AI content generation (Anthropic, PBC, USA). Campaign briefs and product data are sent to generate email content. Anthropic does not retain this data for training purposes under our commercial agreement.

SalesManago — marketing automation and analytics (Benhauer sp. z o.o., Poland).

Google — website analytics (Google LLC, USA) via Google Analytics.

We never share your campaign data, strategies, content, or business information with other clients, competitors, or any party not listed above. Your data is never sold.

6. International Transfers

Some of our service providers are based in the United States. Data transfers to the US are protected by Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework, as applicable. Our servers are hosted in the EU (DigitalOcean, Amsterdam, Netherlands).

7. Data Retention

Active clients: data is retained for the duration of your subscription plus 30 days after cancellation.

Waitlist subscribers: email addresses are retained until you unsubscribe or for a maximum of 24 months from signup.

Campaign data: email designs, briefs, and conversation history are retained for 12 months after your subscription ends, then deleted.

Billing data: retained as required by Estonian tax law (7 years for invoices and transaction records).

8. Your Rights (GDPR)

As a data subject under GDPR, you have the right to:

Access — request a copy of your personal data.

Rectification — correct inaccurate data.

Erasure — request deletion of your data ("right to be forgotten").

Restriction — restrict processing of your data.

Portability — receive your data in a structured, machine-readable format.

Object — object to processing based on legitimate interest.

Withdraw consent — at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at hello@charlieai.co. We will respond within 30 days.

9. Cookies

Essential cookies: necessary for the website to function (session management).

Analytics cookies: Google Analytics (_ga, _gid) to understand how visitors use our website. You can opt out via your browser settings or Google's opt-out tool.

Marketing cookies: SalesManago (smclient) to track visitor interactions for marketing purposes. Set when you submit the waitlist form.

10. Security

We protect your data using HTTPS encryption for all communications, encrypted storage for API credentials and tokens, access controls limiting data access to authorized personnel, and regular security reviews of our infrastructure. While we implement industry-standard security measures, no system is completely secure. We will notify you promptly in the event of a data breach affecting your personal data.

11. Children

Our Service is not directed at individuals under 18. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or WhatsApp at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

13. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee, or with your local supervisory authority.

14. Contact

For any privacy-related questions or requests:

Charlie OÜ
Lahepea 9, 10617 Tallinn, Estonia
Email: hello@charlieai.co