Privacy Policy
Last updated: September 28, 2026
Purpose
The purpose of this Privacy Policy is to establish a comprehensive framework for protecting the privacy of personal information (“Personal Data”) collected, processed, and stored by eno in the course of using our website and software applications (the “Platform”) or directly from you by other means.
This Policy ensures that eno respects individual privacy rights, and maintains the trust of customers, employees, and other data subjects through compliance with applicable privacy laws and regulations, including GDPR requirements for confidentiality and privacy.
Scope
This Policy applies to all employees, contractors, consultants, and third-party vendors of eno who handle personal information.
This Policy applies only to the processing of Personal Data by us and does not address the privacy practices of other parties from which we are not responsible.
We do not knowingly process or request Personal Data from persons under the age of 18. If you are such a person, please do not use the Platform or send us your data. We delete all the Personal Data about which we learn to have been provided by a person under the age of 18 without the consent of a parent or legal guardian.
What data do we process?
Personal Data
We may process Personal Data that you have provided to us voluntarily while using the Platform or Website. Personal Data encompasses all personal information collected, processed, stored, or transmitted by eno, including but not limited to: customer data, employee data, vendor data, and any other personally identifiable information, regardless of format or storage medium.
Technical Data
We may automatically collect technical data when you visit or interact with the Platform for statistical and analytical purposes. The technical data may include:
Device data, such as your computer or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers, language settings, mobile device carrier, radio/network information (e.g., Wi-Fi, LTE, 5G), and general location information such as city, state or general geographic area.
Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times and duration of access, and whether you have opened our emails or clicked links within them.
Application Usage data, such as duration of sessions, number of searches run, size of searches, number, page count and size of documents, types of AI prompts activated in connection with searches, durations of AI prompts, memory and CPU usage, and other similar metrics.
Google Drive integration
Connecting Google Drive is optional. If you choose to connect it, eno uses Google OAuth to request read-only access to your Google Drive and permission to appear in Google Drive’s “Open with” menu. We also request your Google Account identifier and e-mail address so we can associate the connection with your eno account and show you which Google Account is connected.
Data eno accesses and how it is used
The Google Drive integration may access:
- file and folder metadata, including names, identifiers, file types, sizes, modification times, parent folders, and Shared Drive information;
- search results and folder listings; and
- the contents of a supported file that you select or ask eno to open, including an exported PDF copy of a selected Google Docs, Sheets, or Slides file.
eno uses this data only to provide user-facing features that let you search and browse your Google Drive, select and open documents in eno, and use eno’s document-reading and AI features with documents you choose. The integration is read-only: eno does not create, modify, move, share, or delete files in your Google Drive.
Storage and retention
While your Google Drive account remains connected, eno stores your Google OAuth access and refresh tokens, the permissions granted, your Google Account identifier, and your Google Account e-mail address. We use this connection information to maintain the integration and request Google Drive data on your behalf.
Google Drive search results, folder listings, and file contents pass through eno-operated services as needed to fulfill your request, but eno does not persist them in cloud storage. A document you choose to open is downloaded to and processed on your device. Locally imported documents, indexes, or other copies remain on your device until you remove them through eno or delete eno’s local application data.
Sharing and transfers
eno does not sell Google user data or use it for advertising, retargeting, determining creditworthiness, or training or improving generalized artificial intelligence or machine-learning models.
Google Drive data is not shared with third parties except as necessary to provide a feature you request, for security purposes, to comply with applicable law, or as otherwise permitted by the Google API Services User Data Policy. When you use an AI feature with a document selected from Google Drive, relevant portions of that document may be sent to eno’s contracted language-model provider solely to generate the response you requested. These providers are subject to zero-data-retention terms and may not use the data to train their models. eno personnel do not read Google Drive data except with your affirmative consent for specific data, when necessary for security or abuse investigation, or when required by law.
eno’s use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your controls and deletion
You can disconnect Google Drive at any time from eno’s integration settings. Disconnecting revokes eno’s Google authorization and deletes the stored OAuth tokens and Google Account connection information from eno’s systems. Deleting your eno account also deletes this connection information and requests revocation of the Google authorization. Disconnecting does not automatically remove documents that you previously chose to download to your device; you can delete those local copies from eno or your device.
Processing Purposes
We process your Personal Data for the purpose of:
Performance of the contract concluded with you based on your decision to use the Platform. This purpose includes the following processing activities:
- informing about updates and new functions to our services
- notification of updates to our Terms and Conditions and this Policy;
- answering your queries about our services;
- resolving any problems and disputes related to the contract between us.
Improving our services - For this purpose, we collect information about how you use the Platform, such as your clicks, the features you use, the time you spend on each screen, and other analytical data.
Marketing
We may offer services to you via e-mail if you have agreed to receive newsletters on our Website, thereby giving us your consent to the processing of your e-mail address for marketing purposes.
In this case, we process your e-mail address on a legal basis, which is your consent in accordance with relevant privacy frameworks.
Advertising and analytics
We use Google Tag Manager on our Website to deploy Google Ads and Google Analytics. Google Ads measures the performance of our paid advertising campaigns, including which ads led to a visit or signup. Google Analytics helps us understand how visitors use our Website, such as which pages are viewed and how visitors navigate the site.
These tools may collect Technical Data described above — such as your IP address, device and browser information, and online activity on our Website — and share it with Google for these purposes. This applies only to our Website; it does not apply to your Personal Data within the eno application.
This tracking is optional and active by default. You can opt out of it at any time using Cookie Preferences (see our Cookie Policy for details), which takes effect immediately and applies going forward. Google’s use of this data is also governed by Google’s Privacy Policy.
Affiliate referrals
We operate an affiliate program using our own first-party systems. If you arrive at our Website through an affiliate referral link, an opaque click identifier records the referral and whether you accepted or declined referral attribution. If you accept the referral cookie and then create an account, we associate that visit with your account so we can credit the affiliate for your signup.
The referral identifier identifies an affiliate, a referral event, the landing page, and your consent choice. It does not contain your name, e-mail address, payment details, IP address, or another browser identifier. Declined and otherwise unattributed click records expire after 60 days and cannot be connected to an account. An accepted referral is associated with your account once you create one. We retain attributed referral records for as long as your account exists and for as long as we are required to keep records supporting affiliate payments, after which they are deleted. You can ask us to delete them using the rights described below.
For details of our optional measurement and attribution cookies, their duration, and how to avoid or remove them, see our Cookie Policy.
Third Parties
Your Personal Data is primarily processed by us. We do not share your Personal Data with any recipients unless one of the following circumstances occurs:
It is processed by a service provider acting on our behalf - We use a small number of service providers that process Personal Data on our instructions and under contract. Affiliate referral information is processed on Eno-operated systems, as described under “Affiliate referrals” above and in our Cookie Policy. Affiliates in our program may receive reporting on the signups attributable to their referrals; they do not receive access to your account or its contents. We also use Google Tag Manager, Google Ads, and Google Analytics to measure paid advertising performance and website usage, as described under “Advertising and analytics” above and in our Cookie Policy.
It is necessary in order for us to fulfill our obligations to you - In the event that our subcontractors with whom we work to operate our Platform need access to your Personal Data, we have taken appropriate contractual and organizational measures to ensure that your Personal Data is processed in accordance with all applicable laws and regulations. We only use third party providers that maintain the same or above levels of data protection and security.
It is necessary for legal reasons - We may share your Personal Data with recipients outside of the Company if we believe in good faith that specific access to your Personal Data and the corresponding use is proportional and necessary to (i) comply with all applicable laws; (ii) detecting, preventing and resolving fraud and security or technical problems; and/or (iii) protect the interests, property or safety of the Company, our users or the public, in accordance with the law. If possible, we will inform you of such processing.
International Processing
We are headquartered in Canada and may use service providers that operate in other countries to process your Personal Information. Your Personal Information may be stored or transferred or other locations where privacy laws may not be as protective as those in your state, province, or country; however, we will ensure our storage or transfers comply with applicable laws around your Personal Information.
Data Security
We take all proportional and appropriate security measures to protect us and our customers from unauthorized access or unauthorized alteration, disclosure, or destruction of Personal Data. Measures include, where appropriate, encryption, firewalls, secure devices, and access rights systems.
Privacy compliance activities will be regularly monitored and audited to ensure compliance with this Policy and applicable regulations. This includes annual reviews of processing activities, data subject rights fulfillment, and privacy impact assessments.
Should a data breach occur despite security measures that are likely to adversely affect your privacy, we will notify you as soon as reasonably possible.
Privacy incidents and data breaches are handled according to established procedures:
- Immediate containment and assessment of privacy incidents
- Notification to supervisory authorities within required timeframes
- Communication to affected individuals when required
- Documentation of incident response and remedial actions
- Post-incident review and process improvement
Data Subject Rights
eno will respect and facilitate data subject rights as required by applicable privacy laws:
Right of access to your Personal Data - you may at any time ask us to confirm whether or not your Personal Data is being processed, and if so, for what purposes, to what extent, to whom it is made available, for how long we will process it, whether you have the right to correct, delete, limit the processing or raise an objection from where we obtained Personal Data form and whether there is automatic decision-making based on the processing of your Personal Data, including possible profiling. You also have the right to obtain a copy of your Personal Data, the first provision being free of charge, and for the next provision, we may require a reasonable payment of administrative costs.
Right to rectification - you may at any time request we correct or add to your Personal Data if it is inaccurate or incomplete.
Right to erasure - you can also request the deletion of your Personal Data from our systems. We will comply with these requests unless we have a legitimate reason not to delete your Personal Data.
Right to restrict processing - you can ask us to restrict certain processing of your Personal Data. If we restrict certain processing of your Personal Data, this may lead to limits on the use of our Platform and Website.
Right to data portability - you have the right to receive your Personal Data from us in a structured, commonly used, and machine-readable format for the purpose of transferring Personal Data to another processor.
How to exercise your rights - you can exercise your rights listed above free of charge by e-mail to info@enopdf.com. Depending on your request, we may require verification of your identity.
Can you file a complaint?
If you believe that our processing of your Personal Data is not in accordance with applicable data protection laws, you may file a complaint with your local authorities.
Compliance
This policy is designed to help eno comply with any regulatory standards or requirements. This policy supports compliance with the following:
- SOC 2
- HIPAA
- GDPR
eno reserves the right to monitor and audit the use of its IT resources to ensure compliance with this Policy and applicable regulations. This includes but is not limited to network traffic analysis, system logs review, and periodic compliance assessments.
Enforcement
Any known violations of this policy should be reported to info@enopdf.com. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.
Policy Review
This policy will be reviewed and updated at least annually, or more frequently as needed, to reflect changes in technology, regulations, or business practices. This document shall be stored in a secure and accessible location and made available to all employees of eno. It is to be referenced in conjunction with other established policies and procedures.