Privacy Policy

edON.ai
Application URL: https://app.edon.ai
Effective Date: March 26, 2026
Last Updated: March 26, 2026

1. Purpose and Scope

    edON UAB (also referred to as we, us or the Company), company registration number 306150515, having its registered office at K. Donelaičio g. 60, A entrance, II floor, LT-44248 Kaunas, Lithuania, is committed to protecting and respecting your privacy.
    In this Privacy Policy (the Policy) we explain what kind of personal data we collect and for what purposes when providing you with our platform and services (the Services) at https://app.edon.ai, when you visit our website at https://www.edon.ai, and/or when you otherwise make contact with us.
    All personal data collected by us are processed in accordance with the EU General Data Protection Regulation No. 2016/679 (GDPR), the Law on the Legal Protection of Personal Data of the Republic of Lithuania, and other applicable legal acts.
    For any questions regarding this Policy or any requests regarding the processing of your personal data, please contact us at hello@edon.ai.

    3. How We Collect Your Personal Data

    We collect information you provide directly to us when you:
    • Register or sign in using Google OAuth or Single Sign-On (SSO)
    • Connect your Google Drive or Microsoft OneDrive account
    • Upload videos, slide decks, or other content to the platform
    • Fill out any forms on our website or platform (e.g., demo request form)
    • Communicate with our customer support team
    • Contact us via our website or other means of communication
    • Use our Services
    We may also receive your personal data from third parties, including:
    • Authentication providers (e.g., Google) — when you choose to sign in using their service
    • Cloud storage providers (e.g., Google Drive, Microsoft OneDrive) — when you connect your account to import or save content
    • Business partners and service providers — where relevant to providing the Services

    4. Google Drive & Microsoft OneDrive Integration

    If you choose to connect your Google Drive or Microsoft OneDrive account, edON.ai will request permission to:
    • Read and download videos and slide files you select for import or generation
    • Create and save output files (translated videos, slides) in folders you choose
    • Edit slide files stored in your Drive through the edON.ai interface
    • Browse your folder structure so you can select a destination for saved outputs
    Google Authentication scopes requested at login:
    • openid — to verify your identity with Google
    • userinfo.email — to retrieve your Google email address
    • userinfo.profile — to retrieve your name and profile picture
    Google Drive scopes requested:
    • https://www.googleapis.com/auth/drive.readonly — to read and download files and folders you select for import or generation
    • https://www.googleapis.com/auth/drive.file — to create, edit, and save output files in folders you choose. This scope only grants access to files that you open or create through edON.ai — we cannot access any other files in your Drive
    Microsoft OneDrive scopes requested:
    • Files.Read — to read and download files you select for import or generation
    • Files.ReadWrite — to create, edit, and save output files in folders you choose
    • offline_access — to obtain a refresh token that keeps your authorization active across sessions
    Refresh Token & Long-Lived Access:
    When you connect your Google Drive or OneDrive, edON.ai stores a refresh token on our servers. This token allows us to maintain your authorization across sessions without requiring you to reconnect each time.
    We use this refresh token solely to complete actions you have initiated — such as downloading slides when you press "Generate", or saving outputs to your chosen folder. We do not use this token to access, scan, or monitor your Drive independently of your actions.
    You may revoke edON.ai's access and invalidate the refresh token at any time through your Google Account settings (myaccount.google.com) or Microsoft Account settings (account.microsoft.com), or from within your edON.ai account settings.

      5. Direct Marketing

      If you are an existing client of edON.ai, we may use your email address for direct marketing purposes, but only with regard to products and/or services that are similar or related to our Services, and only if you do not object to such use.
      In other cases, we will use your personal data for direct marketing only if you have given us your prior consent.
      We provide a clear, free of charge, and easily realisable possibility to withdraw your consent or object to receiving marketing communications at any time. Each marketing email will contain an unsubscribe link, and you may also contact us at hello@edon.ai to opt out.

        6. How We Share Your Personal Data

        We may disclose your personal data to the following categories of recipients:
        • Public authorities and institutions — only upon request and only when required by applicable laws, or to defend the Company's legitimate interests
        • Authentication providers (e.g., Google) — solely to verify your identity during login
        • Cloud storage providers (e.g., Google, Microsoft) — to enable the Drive/OneDrive integration features you have authorized
        • IT and infrastructure service providers — including hosting, cloud storage, and data center providers, who process your data only on our instructions
        • Legal, financial, auditing, and accounting service providers — provided only with data necessary for their services
        • Third parties in connection with a business transaction — if the Company intends to enter into a sale or merger transaction or conduct legal/financial due diligence
        • Other persons — with your explicit consent
        In each case, we share only as much data as is necessary. All third-party service providers are bound by data processing agreements and are prohibited from using your data for their own purposes.

          7. International Data Transfers

          In case your personal data is transferred outside the European Economic Area (EEA), we will take the necessary steps to ensure that your data is treated securely and in accordance with this Policy. This may be done through:
          • Transfer to a country approved by the European Commission as having an adequate level of protection
          • Use of Standard Contractual Clauses (SCC) adopted by the European Commission (see here)
          • Special permission obtained from a supervisory authority
          • Other appropriate safeguards as indicated in the GDPR

            8. How Long We Keep Your Personal Data

            We keep your personal data for as long as it is needed for the purposes for which it was collected, and no longer than required by applicable laws and regulations.
            Data Type
            Retention Period
            Account and contract data
            Duration of the contract + maximum 10 years after the relationship ends
            Uploaded content (videos, slides)
            Until you delete it, or 90 days after account closure
            OAuth / refresh tokens
            Until you revoke access or delete your account
            Usage and session logs
            12 months
            Communication and support records
            3 years
            Pre-contractual data (if no contract concluded)
            Maximum 12 months
            We may retain your personal data for a longer period when:
            • It is necessary to defend against existing or threatened legal claims
            • There is a suspicion of illegal activity
            • It is required by applicable laws
            Upon expiration of the retention period, we will delete and/or reliably depersonalize your data within a reasonable time.

              9. Your Rights

              Under the GDPR and Lithuanian data protection law, you have the following rights:
              • The right to be informed — to receive clear and transparent information about how we process your personal data
              • The right to access — to request a copy of your personal data held by us
              • The right to rectification — to request correction of inaccurate or incomplete data
              • The right to erasure ("right to be forgotten") — to request deletion of your data when there is no longer a valid reason for us to process it
              • The right to restrict processing — to request that we limit how we use your data in certain situations
              • The right to data portability — to receive your data in a machine-readable format or have it transferred to another controller, where the legal basis is consent or contract
              • The right to object — to object to processing based on legitimate interests, including direct marketing
              • The right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
              • The right to lodge a complaint — with the competent supervisory authority
              To exercise any of these rights, contact us at hello@edon.ai. We will respond within 30 calendar days of receiving your request. This period may be extended by 60 calendar days in complex cases, and we will inform you of any such extension within the initial 30-day period.
              We may refuse your request if exceptions under the GDPR apply or if the request is manifestly unfounded or disproportionate, and will provide written reasons for any refusal.
              Supervisory Authority:
              State Data Protection Inspectorate of the Republic of Lithuania
              Address: L. Sapiegos st. 17, LT-10312 Vilnius
              Phone: +370 5 271 2804 / +370 5 279 1445
              Email: ada@ada.lt
              Website: https://vdai.lrv.lt/en/

                10. How We Protect Your Personal Data

                Although no technology system is completely secure, we have implemented appropriate technical and organizational measures to minimize the risk of unauthorized access to or improper use of your personal data, including:
                • HTTPS/TLS encryption for all data in transit
                • Encrypted storage of uploaded files and OAuth tokens
                • Role-based access controls limiting internal access to personal data
                • Regular security reviews and audits
                All third-party service providers engaged in processing personal data on our behalf are contractually obligated to respect confidentiality and to process data only in accordance with our instructions.

                  11. Cookies

                  If you access our Services through our website or application, we use cookies and similar technologies to maintain your login session, remember your preferences, and analyze usage.

                    13. Changes to This Policy

                    We regularly review this Policy and reserve the right to modify it at any time in accordance with applicable laws. Material changes will be communicated by email or through a notice within the platform at least 14 days before they take effect. Please review this Policy periodically to stay informed of any updates.

                      14. Contact Us

                      edON.ai
                      Email: hello@edon.ai
                      Website: https://www.edon.ai
                      Address: K. Donelaičio g. 60, A įėjimas, II a., LT-44248 Kaunas, Lithuania