Privacy Policy

Last updated: 24 August 2026

1. Introduction

Productory Services OÜ (hereinafter “Productory”, “we”, or “us”) respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, share, and protect data in connection with Productory services, the Ritemark desktop application, and the Lightmark web service.

2. What data we collect

We may collect the following data:

  • Name and contact details (email, phone)
  • Company name and job title
  • Website usage data and cookie choices
  • Training participation data
  • Anonymous Ritemark product-usage events when analytics is enabled
  • Written feedback that a user explicitly submits

3. How we use your data

We use data for the following purposes:

  • Providing training and services
  • Communicating with you and responding to inquiries
  • Improving services and Ritemark and monitoring reliability
  • Marketing communications with your consent

4. Data sharing

We do not sell personal data. We share data with service providers only where necessary to provide a service, carry out an AI request initiated by the user, or comply with law. Ritemark AI requests travel from the selected local runtime directly to the external AI provider or service selected by the user, not through a Productory AI proxy.

5. Your rights

Subject to applicable law, you have the right to:

  • Access your data
  • Correct your data
  • Delete your data
  • Restrict data processing
  • Object to data processing

6. Cookies

Our website uses cookies and similar technologies according to your choices. You can change your preferences in the website cookie settings.

7. Ritemark product

Local files

Ritemark is a free, open-source desktop application for macOS and Windows. Ritemark stores and edits user files locally. Productory does not receive or host a copy of the user’s workspace as part of ordinary editing. Users choose and control any separate file synchronization or backup service.

Desktop analytics

When analytics is enabled, Ritemark uses PostHog’s EU service to collect anonymous product-usage events. Analytics is enabled by default and can be disabled in Ritemark settings. Ritemark stores a random anonymous identifier in local application state. Events may include app version and platform, app-session starts, feature use, selected agent use, and reaction choices. They do not include AI prompts or file contents. If a user explicitly submits written feedback, the text entered by the user is transmitted with that feedback event.

PostHog Privacy Policy

AI-provider processing

AI features are optional. When a user invokes AI, the selected local runtime sends the request and relevant context directly to the selected external provider or service. Supported routes include Anthropic through Claude Code, OpenAI through Codex, and Google, OpenAI, Anthropic, or OpenRouter through OpenCode. The runtime uses the user’s provider account or API key.

Depending on the task, transmitted context may include the user’s prompt, active-file paths or content, selected text and surrounding context, explicit attachments, shared browser context, recent cross-runtime conversation context, and tool results. Where the user’s permission settings allow it, an agent may also read or modify other workspace files or use tools.

Each provider processes data under the terms, privacy policy, retention choices, and account settings applicable to the user. Productory does not receive the user’s API key through an AI proxy.

User control

Ritemark can be used without invoking AI. Before an AI turn, users can review visible context chips, remove supported context items, choose the runtime and model, and select a permission mode. Removing an item from one turn does not prevent an authorized agent from later reading a workspace file with an allowed tool.

8. Lightmark

Lightmark is a web application that helps an organisation measure, plan, and develop the maturity of its AI use at individual, team, and business-process levels. A person answers a questionnaire about their work practices and receives a personal result; anonymous aggregates with sufficient participation help the organisation plan development needs.

Processing roles and purposes

The organisation that invites a person to Lightmark determines the purpose and legal basis for assessing its employees or members and is the controller for that processing. Productory Services OÜ provides Lightmark as a processor acting on the organisation’s instructions. Productory is a separate controller to the limited extent that we process data for our own account and information security, service reliability, fraud prevention, legal obligations, or minimal product analytics.

The inviting organisation determines the legal basis for the assessment and explains it in the invitation or its employee privacy notice. Because of the employment relationship, Lightmark does not treat completion of the questionnaire as the employee’s GDPR consent by default. Newsletter consent is separate from the assessment and voluntary.

Lightmark data we process

  • Invitation and account data: name, email address, organisation, role, team, membership, and sign-in state.
  • Technical authentication data: Firebase UID, authentication-token metadata, IP address, user agent, and sign-in method used.
  • Assessment data: draft and submitted answers, questionnaire version, response time, calculated scores, maturity stage, recommendations, and measurement history.
  • Planning data: organisational goals, context, selected actions, and ideas or other free text entered by a user.
  • Minimal product-usage events and security logs described below.

Who sees your answers

Only you can see your individual answers, personal profile, result, history, and personal recommendations. An organisation administrator may see your name, email, role, team, and whether your response is in progress or complete, but not your answers or personal result. A Productory consultant or client manager cannot open your personal result in the ordinary workflow.

Results are shown to the organisation only as an anonymous aggregate when Lightmark’s privacy thresholds are met. If the group or participation is too small, the result is suppressed. The aggregate does not reveal who answered what, and overlapping views must not be used to infer a person’s result. A Lightmark result describes work practices and must not be used for pay, promotion, performance management, redundancy, or another individual employment decision.

Anonymous benchmark

Lightmark may show an organisation a comparison with an anonymous aggregate of other organisations. An observed benchmark is calculated from organisation-level aggregates, not individual answers, and publication controls prevent attribution of an organisation’s or person’s result. Lightmark does not disclose the names of organisations or the number of respondents in a benchmark cohort. If a comparison is synthetic or blended, its provenance is labelled clearly.

Product usage measurement with PostHog

To understand whether the application works and which core flows need improvement, Lightmark sends limited server-side usage events to PostHog’s European service, such as opening or submitting a questionnaire, sending an invitation, and adding an action to a plan. The legal basis is Productory’s legitimate interest in improving the reliability and usability of the service.

A PostHog event does not carry a name, email address, answers, score, internal organisation ID, or the user’s IP address. The event uses a pseudonymous identifier derived from the sign-in session; person profiles and geolocation are disabled. PostHog is not used for advertising or employee monitoring.

Data location and service providers

The Lightmark application, database, assessment answers, scores, plans, organisation data, and backups are hosted in Google Cloud’s European Union region europe-west4 (Netherlands). Those assessment and organisation data are not sent to Firebase Authentication.

We use Google Firebase Authentication for sign-in. Firebase Authentication is operated from US data centres and receives only the identity and technical information needed for authentication, such as email address, Firebase UID and token metadata, IP address, user agent, and sign-in method. This limited data flow does not include your questionnaire answers, score, plan, or organisation aggregate.

Resend delivers invitation and sign-in emails and processes the recipient email address and technical message metadata for that purpose; Resend service and log data may be processed in the United States. Lightmark’s PostHog project uses European data hosting. We use the providers’ data-processing terms and applicable international-transfer safeguards for Google, Resend, and PostHog.

Retention

Account, assessment, and planning data are retained while the organisation uses Lightmark and afterwards only for as long as required by the customer agreement, the organisation’s documented instruction, resolution of a rights request, or defence of a legal claim. At the end of the agreement, data are returned, deleted, or irreversibly anonymised according to the organisation’s instruction and data-processing agreement. Database backups expire through the ordinary backup cycle. Exact periods for temporary authentication, email, analytics, and audit records are set by data category, and this notice will be updated as Lightmark’s retention schedule is finalised.

Your rights and automated decisions

You may have the right to obtain a copy of your data, correct inaccurate data, request erasure or restriction, and object to processing. Start with the contact at the inviting organisation or email Productory at info@productory.eu; we will help the organisation respond, generally within one month. You also have the right to complain to the Estonian Data Protection Inspectorate at info@aki.ee or through aki.ee.

Lightmark calculates a deterministic profile and recommendations from the answers, but it does not make automated decisions about you that produce legal or similarly significant effects. An employer must not use the result to make an individual employment decision.

Cookies in Lightmark

Lightmark uses a strictly necessary session cookie that keeps you signed in. No cookie is used for product-usage measurement, and no separate PostHog identifier is written to or read from your device.

9. Contact

If you have questions about this privacy policy or want to exercise your rights, contact us:

Productory Services OÜ
Email: info@productory.eu
Phone: +372 520 1443