Privacy
AutomateIndex privacy policy
Last updated: 1 August 2026. This policy explains how AutomateIndex handles launch-list, account, workspace, website, monitoring, generated-file, billing, support, and optional paid-access data.
Who is responsible
Enstellis SRL operates AutomateIndex as the platform provider. For privacy, legal, security, account, billing, or support requests, contact support@automateindex.com.
- Controller: Enstellis SRL
- Registered office: Frunzei Street, No. 11, Galati Municipality, Galati County, Romania
- Contact email: support@automateindex.com
- Romanian Trade Register / ONRC: J2026032702008
- Company tax identification code (CUI/CIF): 54719618
- Special EU VAT identification code (Article 317; not normal Romanian VAT registration): RO55264107
- Supervisory authority: National Supervisory Authority for Personal Data Processing (ANSPDCP)
AutomateIndex acts as controller for account, billing, website, support, security, and product administration data. For crawler event data, generated-file operations, and integration data processed for a publisher site, the publisher is usually the controller and AutomateIndex acts as processor unless agreed otherwise.
Launch list
The public AutomateIndex launch list is separate from account signup. Joining it does not create an account, workspace, preview, subscription, or billing relationship. We use double opt-in, so an address remains pending until the person who can access it follows the confirmation link.
After confirmation, Enstellis SRL keeps the address and consent evidence in AutomateIndex records, and the company support mailbox receives an enrollment notice. We use the address only to administer the list, send its required confirmation or unsubscribe messages, and send the AutomateIndex launch announcement described when the address was submitted.
Every subscriber-facing launch-list email includes an unsubscribe path. Withdrawing consent stops launch-list email and removes the raw address from the active list. We may keep a minimal pseudonymised suppression record and limited delivery or security evidence where reasonably needed to honor that choice, prevent abuse, resolve consent or delivery questions, and comply with law.
What we process
- Launch-list data: email address, pending, confirmed, or unsubscribed status, request and consent timestamps, submission source, applicable privacy and consent version, delivery status, hashed action-token proof, and minimized abuse-prevention evidence.
- Account and workspace data: email, name, current legal-document versions and acceptance evidence, including acceptance of the 18+ eligibility term, role, workspace details, plan state, settings, and support messages.
- Website and audit data: domain, public policy files, visibility-readiness checks, generated-file previews, recommendations, submitted lead details, and report history.
- Provider and install data: selected host, non-secret setup receipts, integration status, heartbeat proof, provider identifiers, setup errors, and owner-approved install context.
- Crawler event data: request path, user agent, bot classification, timestamp, action, status code, country if available, hashed or minimized IP data where possible, and related monitoring metadata.
- Optional paid structured-access data: the publisher receiving wallet and configured price; payment reference, requested resource, amount, network, and asset; payer wallet and transaction or settlement identifiers when the payment provider returns them; a cryptographic hash of the payment authorization rather than the raw authorization; user-agent; and reconciliation, delivery, security, and activation records. AutomateIndex does not treat unauthenticated proxy headers as payer or buyer IP evidence and does not record them in paid-access accounting. AutomateIndex uses the retained records to orchestrate and verify direct, non-custodial settlement and does not receive, hold, forward, or withdraw the funds.
- Billing data: individual or business name, billing address and country, tax or VAT identifier when supplied, Stripe customer, Checkout, subscription, invoice, and payment-method identifiers, selected plan and price, 14-day preview eligibility and status, accepted legal-document versions and checkout consent evidence, amount due, invoice, payment, first-successful-payment, refund, credit-note, cancellation, renewal, failed-payment, and tax status, limited payment-method evidence returned by Stripe, tax/accounting context, and billing support correspondence.
- Consumer-withdrawal evidence: customer name, an AutomateIndex contract reference, exact withdrawal statement, server submission time, legal-flow version, a keyed hash of the verified acknowledgement email, encrypted pending-email content, delivery state, subscription-cancellation outcome, refund assessment, and fiscal-correction status. The pending email destination and body are redacted from the delivery outbox after final delivery or terminal failure; the minimum legal evidence remains separately.
- Technical and security logs: authentication, abuse prevention, rate limits, errors, uptime, diagnostic data, and security events needed to operate and protect the service.
- Answer-surface data: configured questions, sampled provider responses, citations or mentions, and evidence summaries when the owner enables AI answer-surface measurement.
Stripe processes full card or other payment credentials for Checkout. AutomateIndex does not receive or store the full card number, card security code, or online-banking credentials. AutomateIndex may receive limited payment-method metadata from Stripe, such as a provider identifier, card brand, last four digits, fingerprint, and whether a reusable payment method was collected, where Stripe supplies it.
Sources of data
- Directly from you when you request, confirm, or leave the public launch list.
- Directly from you when you create an account, add a website, contact support, configure settings, configure optional paid features, or approve an install.
- From public website scans, verified domains, generated-file checks, crawler events, supported-host integrations, and provider callbacks.
- From service providers when they return operational, billing, delivery, integration, or measurement data needed to provide the service.
Purposes and legal bases
- Contract: providing accounts, the 14-day preview, paid dashboards, audits, generated files, install flows, monitoring, reports, AgentToll features, billing access, export, withdrawal and cancellation handling, and support.
- Legitimate interests: securing the service, preventing abuse, enforcing one-preview eligibility, honoring launch-list suppression choices, debugging, proving install state, maintaining reliability, understanding crawler activity, and improving product quality.
- Legal obligation: tax, accounting, billing, fraud, security, compliance, sanctions, lawful requests, and record-retention duties where applicable.
- Consent: confirming and administering the public launch list and sending its launch announcement, plus optional communications or non-essential cookies if AutomateIndex adds them later.
Retention
- An unconfirmed launch-list enrollment expires after 30 days. Its pending subscriber record is then deleted by the next scheduled cleanup.
- A confirmed launch-list address is kept until you unsubscribe or the list closes. After unsubscribe, the raw address is removed from the active list; a minimal keyed address hash and limited consent, delivery, security, or company-mailbox evidence may be kept only as reasonably needed for suppression, abuse prevention, legal claims, and compliance.
- Account, workspace, site, generated-file, monitoring, report, and integration records are generally kept while the workspace is active or as needed to provide export, offboarding, support, security, and legal evidence.
- Workspace deletion and account closure may retain minimal records needed for billing, tax, fraud prevention, preview-abuse prevention, security, legal claims, support evidence, and preventing repeated use of a one-time preview.
- A customer-facing closure export is a temporary service-delivery record, not automatically an accounting record. Its download access and underlying service snapshot must follow a finite, purpose-specific expiry and purge policy; records that are independently required for tax, accounting, legal claims, security, or an active legal hold are segregated and follow their own approved periods.
- Consumer-withdrawal statements, timestamps, acknowledgement-delivery proof, cancellation outcomes, refunds, and related fiscal corrections are retained only for the applicable legal, accounting, tax, and claims periods, under the approved retention schedule.
- Stripe, accounting, invoice, tax, payment, cancellation, and failed-payment records may be retained by Stripe and AutomateIndex where required by law or legitimate billing/legal interests.
- Rate-limit and abuse-prevention windows are kept only as long as reasonably needed for safety and reliability.
- Provider backups, logs, and point-in-time restore history may retain deleted data until the provider backup or log-retention window expires.
- Support, privacy, legal, security, and billing correspondence may be retained as long as needed to answer requests, comply with law, or establish, exercise, or defend legal claims.
Cookies and similar technologies
AutomateIndex should use only essential cookies or local storage required for authentication, security, dashboard operation, and install flows at launch. If analytics, advertising, or other non-essential tracking is added later, AutomateIndex should add an appropriate consent flow before enabling it for EU visitors.
International transfers
Some providers may process data outside the EU/EEA. Where this happens, AutomateIndex relies on an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses where required.
Security
AutomateIndex minimizes raw personal data where possible, hashes or limits IP data where feasible, signs event ingestion, avoids exposing provider secrets, and separates monitor-only collection from enforcement. No system is perfectly secure, but AutomateIndex is designed to avoid collecting data that is not needed for the service.
Your rights
- Access the personal data we hold about you.
- Ask us to correct inaccurate or incomplete data.
- Ask us to delete data where the law allows it.
- Ask us to restrict or object to certain processing.
- Ask for portability of data you provided to us.
- Withdraw consent where processing is based on consent.
- Complain to the Romanian supervisory authority or another competent EU/EEA supervisory authority.
To exercise rights, contact support@automateindex.com. Include the affected account email, workspace, website domain, and enough context for AutomateIndex to verify the request. AutomateIndex aims to respond without undue delay and normally within one month, subject to GDPR and any lawful extension right.
Automated decision-making
AutomateIndex does not use personal data for solely automated decisions or profiling that produce legal effects or similarly significant effects on individuals. Product scores and recommendations are technical support signals for site owners, not automated legal or financial decisions.
Authority
Privacy complaints may be sent to the National Supervisory Authority for Personal Data Processing (ANSPDCP) or your local EU/EEA supervisory authority where applicable.