Privacy Policy
1 July 2026. Please read this document carefully. If anything is unclear, contact us at [email protected].
This Privacy Policy explains how WebAdmin OÜ (registry code 14698205, address Hauka 13, 11315 Tallinn, Eesti) - “Husly”, “we”, “us” - processes personal data when you use our website husly.app and our website-building service (the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (EU 2016/679, “GDPR”) and applicable Estonian law.
1. Controller and contact
The controller of your personal data is WebAdmin OÜ, registry code 14698205, Hauka 13, 11315 Tallinn, Eesti. For any privacy matter, including exercising your rights, email [email protected].
2. Scope and roles
This policy covers data we process as a controller - about our own customers, visitors and user accounts.
Important distinction. When you, as a customer, build a website with Husly and collect data about your visitors (e.g. through contact forms or analytics), you are the controller of that data and Husly is a processor acting on your instructions. In that case a separate Data Processing Agreement (DPA) applies, and you are responsible for providing privacy information to your site visitors and obtaining any required consents.
3. Data we collect
- Account and profile data: name, email address, password (hashed) or Google sign-in identifier, language preference.
- Billing data: chosen plan, billing history, VAT number and invoice contact. We never see or store card numbers - these are handled directly by Stripe.
- Content you create: page text, images, form configurations and other material you add to the Service.
- Usage and technical data: IP address, device and browser data, logs, page views and feature usage, used to secure, troubleshoot and improve the Service.
- Communications: emails, support requests and feedback you send us.
- Cookies and similar technologies: see section 5.
4. Purposes and legal bases
- Providing the Service (account creation, hosting your pages, running features) - legal basis: performance of a contract (GDPR art. 6(1)(b)).
- Billing and accounting - legal basis: contract and legal obligation (art. 6(1)(b) and (c)).
- Security, abuse prevention and improvement - legal basis: legitimate interest (art. 6(1)(f)).
- Support and communication - legal basis: contract and legitimate interest.
- Analytics/marketing cookies and newsletters - legal basis: consent (art. 6(1)(a)), which you can withdraw at any time.
5. Cookies and analytics
We use strictly necessary cookies required for the Service to work (e.g. your login session) and, with your consent, analytics cookies. To understand product usage we use the analytics tool PostHog. Non-essential cookies are activated only after your consent in the cookie banner; you can change or withdraw consent at any time. You can also manage most cookies in your browser settings.
6. Processors (sub-processors)
To provide the Service we use carefully selected providers that process personal data on our behalf and under our instructions. The main ones are:
- Stripe - payment and subscription processing.
- Resend - sending transactional and notification emails.
- Cloudflare (R2 and CDN) - storing and delivering uploaded media.
- Google - “Sign in with Google” authentication (if you use it).
- Anthropic - processing AI features (content and design generation, AI chatbot). See also section 12.
- Our hosting provider - hosting of servers and database in the European Union.
An up-to-date list of sub-processors is available on request at [email protected]. We do not sell your personal data.
7. International transfers
We prefer to process data within the EU/EEA. Where a provider processes data outside the EEA, we ensure protection through appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and additional security measures.
8. Retention
We retain personal data for as long as necessary for the purposes described in this policy. Account and content data are kept for the duration of the customer relationship; after account deletion we delete or anonymise data within a reasonable period, except where retention is required by law (e.g. accounting records, kept for the statutory period).
9. Your rights
You have the following rights regarding your personal data:
- access your data and receive a copy;
- rectify inaccurate data;
- request erasure (“right to be forgotten”);
- request restriction of processing;
- receive your data in a portable format (data portability);
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting the lawfulness of earlier processing.
To exercise your rights, email [email protected]. If you believe we breach data protection rules, you may lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee) or the supervisory authority in your country of residence.
10. Security
We apply appropriate technical and organisational measures to protect personal data, including encrypted connections (TLS), password hashing and access controls. No system is entirely secure; please keep your login credentials confidential.
11. Children
The Service is not directed at persons under 16 and we do not knowingly collect their data. If we learn we have collected a child’s data without the required consent, we will delete it.
12. AI features
When you use Husly’s AI features, your prompt and the necessary context are sent to our AI provider Anthropic to generate a result. Our AI provider does not use this data to train its models. Do not enter sensitive personal data into AI fields that you do not want processed.
13. Changes to this policy
We may update this policy from time to time. We will notify you of material changes in the Service or by email. The current version is always available on this page with its update date.
14. Contact
For questions, email [email protected] or use our contact form.