Privacy Policy

Last updated: July 30, 2026

Smith Business Solutions SRL (“STOICA”, “we”, “us”), Trade Register No. J29/1411/2014, CIF RO33734100, sat Predesti, com. Tinosu, nr. 28, Prahova, Romania, 107612, operates the https://noombat.ai website and the noombat platform (together, the “Service”). Questions about this policy or our practices: hello@noombat.ai.

We play two distinct roles. For the public website, our own marketing and the accounts of people who sign in, we are the data controller and this policy applies in full. For the business data that client organizations bring into their platform workspaces, we are a data processor acting on the client's instructions under our Data Processing Addendum — the client organization is the controller of that data.

Information we collect

Information you provide. When you sign in with a work email address, request a demo, or contact us, we collect what you give us: name, work email address, company name and role.

Log and device data. Collected automatically when you visit: IP address, browser and device characteristics, pages visited, and timestamps.

Website visitor identification. Our public website uses a third-party service that attempts to identify the company a visitor is browsing from, based on network and similar signals, so we can follow up with relevant companies. Where the service surfaces business contact details (name, role, work email), we process them as business-context data under our legitimate interest in reaching relevant businesses. This runs on the public homepage only — never inside client workspaces or on authenticated pages — and you can object at any time (see Your rights below).

Client data in the platform. Client organizations connect business data — CRM records, business contact details, engagement and intent signals — and the platform additionally obtains related data from third-party enrichment and signal providers on the client's behalf. We process this data to provide the Service to that client, as its processor. If your data appears in a client's workspace, that client is the controller; see “Exercising your rights” below.

How we use information

As controller, we use personal information to:

  • Provide, operate and secure the Service (legal basis: performance of a contract, legitimate interest)
  • Sign you in and administer your organization's workspace (contract)
  • Respond to requests and provide information or services you ask for (contract, consent)
  • Follow up with companies that show interest in noombat, and send marketing you can opt out of at any time (legitimate interest, consent)
  • Understand how the Service is used and improve it (legitimate interest)
  • Comply with legal obligations (legal obligation)

Cookies and analytics

The Service uses cookies and similar technologies to keep you signed in, remember preferences and understand usage. You can refuse cookies in your browser settings, but parts of the Service (such as staying signed in) may stop working.

We use PostHog for product analytics (pages visited, features used, aggregate usage). Analytics data is used to improve the product and is not sold to anyone.

Who we share information with

We do not sell personal information. We share it only with providers that process it on our behalf to run the Service, under contracts that restrict what they may do with it:

  • Hosting and infrastructure: Vercel (application hosting), Supabase (database, hosted in the EU — Frankfurt)
  • AI processing: Anthropic (Claude) — powers the Snout analyst; not used to train models on client data
  • Product analytics: PostHog
  • A website-visitor identification service (public site only)
  • Specialized data-enrichment and signal providers acting on our clients' behalf — the named list is provided to clients on request
  • Integrations a client chooses to connect, such as Slack and the client's own CRM (e.g. HubSpot)
  • Transactional email for sign-in links

International transfers

Client workspace data is stored in the EU (Supabase, Frankfurt). Some of our providers (for example Anthropic, PostHog and certain visitor-identification and enrichment providers) process data in the United States. Where personal data leaves the EEA we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.

Retention

We keep personal information only as long as needed for the purposes above, to comply with legal obligations, resolve disputes and enforce agreements. Client organizations control retention of the data in their workspaces; on termination, workspace data is exported on request and then deleted as described in our Terms and DPA.

Security

Access to client workspaces is organization-scoped and authenticated, data is stored with established cloud providers, transport is encrypted, and secrets are managed outside the codebase. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Security questions: hello@noombat.ai.

Your rights under GDPR

If your personal data is subject to the GDPR, you have the right to:

  • Object to processing — including direct marketing and processing based on legitimate interest (such as visitor identification)
  • Be informed about how your data is used
  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data where there is no compelling reason for continued processing
  • Restrict processing while a dispute is resolved
  • Port your data to another service
  • Withdraw consent at any time, where processing is based on consent
  • Complain to a supervisory authority — in Romania, ANSPDCP (dataprotection.ro), or your national regulator. We would appreciate the chance to address your concern first at hello@noombat.ai

Exercising your rights

Write to hello@noombat.ai with your request; we respond within the timelines the GDPR requires. If your data is in a client organization's workspace, the client is the controller: we will pass your request to them and assist them in fulfilling it.

Links to other sites

The Service may link to external sites we do not operate. Review the privacy policy of every site you visit; we are not responsible for third-party content or practices.

Children

The Service is for business use. We do not knowingly collect personal information from children, and clients may not bring data about children into the platform. If you believe a child's data has reached us, contact hello@noombat.ai and we will delete it.

Changes to this policy

We may update this policy from time to time; the current version is always at noombat.ai/privacy, with the date above. For material changes we will provide notice on the site or by email.

Contact

Smith Business Solutions SRL · Trade Register No. J29/1411/2014 · CIF RO33734100
sat Predesti, com. Tinosu, nr. 28, Prahova, Romania, 107612
hello@noombat.ai