We respect your privacy and want you to understand clearly what happens with your data. Below, in plain language, we explain what data we receive when you visit our website or contact us through the form, why we need it, and how you can manage it.

1. Data Controller and Contact Details

1.1. The controller of personal data processed through the website [website URL] is Altrenis OÜ, registration code 17502711, VAT number EE102984480, registered address: Vesivärava tn 50-301, Kesklinna linnaosa, Tallinn, Harju maakond, 10152, Estonia (hereinafter the «Company» or «we»).

1.2. For any questions relating to the processing of personal data, and to exercise your rights, you may contact us by email at: altrenisou@gmail.com.

1.3. The Company has not appointed a Data Protection Officer, as the obligation to appoint one under Article 37 of Regulation (EU) 2016/679 (GDPR) does not arise in respect of the Company’s activities. The Company performs the functions of a contact point for data protection matters itself, at the address indicated above.

1.4. This Policy applies to the processing of personal data of natural persons carried out by the Company as controller through the website [website URL]. Processing carried out by other parties on other websites, including those accessible via links provided, is not governed by this Policy.

1.5. Personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) and, as regards the use of cookies and electronic communications, the Electronic Communications Act (Elektroonilise side seadus).

2. What Personal Data We Collect and From What Sources

2.1. We process personal data that you provide to us voluntarily when completing the contact form on the website. This includes:

  • name (mandatory field);
  • email address (mandatory field);
  • telephone number (mandatory field);
  • company name (optional field);
  • message text (optional field).

2.2. Account registration and login are not available on the website. We do not collect any other personal data through the website.

2.3. When the website is accessed, the hosting provider, acting as a processor on our behalf, may automatically keep technical logs containing, among other things, the IP address, to the extent and for the period necessary to ensure the functioning and security of the website. Such data is processed on the basis of our legitimate interest (Article 6(1)(f) GDPR) in maintaining the operability and security of the website.

2.4. We obtain all personal data directly from you. We do not obtain your data from third-party sources.

2.5. We do not request, and we ask you not to provide in the form, including in the message text, any special categories of personal data, in particular data concerning health. If such data is nevertheless provided by you on your own initiative, we do not use it for making any decisions and delete it at the earliest opportunity.

2.6. The website and the contact form are intended for legal entities and their representatives and are not addressed to children. We do not knowingly collect personal data of minors.

3. Purposes and Legal Bases of Processing

3.1. Handling your enquiry. We process the data from the form (name, email address, telephone number, and, where provided, company name and message text) for the purpose of handling your enquiry and responding to it. The legal basis is our legitimate interest (Article 6(1)(f) GDPR) in receiving enquiries and communicating with those who contact us and, where the enquiry is aimed at concluding a contract with you, taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR). Providing the data is voluntary; however, without your name and contact details we will not be able to handle your enquiry and respond.

3.2. Sending marketing communications. If you have given separate consent to this, we process your email address and telephone number in order to contact you with information about our activities, products, services and cooperation proposals by email and telephone calls. The legal basis is your consent (Article 6(1)(a) GDPR) and, as regards communications by electronic means, the requirements of the Electronic Communications Act (Elektroonilise side seadus). Consent is voluntary, does not affect the handling of your enquiry, and you may withdraw it at any time (see Section 7). Withdrawal does not affect the lawfulness of processing carried out before it.

3.3. Consent to marketing is given separately from submitting an enquiry, by a separate checkbox in the form. We do not make the handling of your enquiry conditional on giving such consent.

3.4. We do not take decisions in relation to you based solely on automated processing, including profiling.

4. Recipients of Personal Data

4.1. We do not sell personal data and do not transfer it to third parties for their own purposes. Access to the data, to the extent necessary for its processing, is available only to authorised employees of the Company.

4.2. To provide certain services, we engage processors acting on our behalf and in accordance with our instructions:

  • the hosting provider Zone Media OÜ (Estonia), which hosts the website and stores the related data on its servers. The servers are located within the European Economic Area. Processing is carried out on the basis of the provider’s terms of service, which contain provisions on the processing of personal data, and a data processing agreement within the meaning of Article 28 GDPR;
  • the email service provider Google, through which we receive and store enquiries submitted via the form and conduct correspondence.

4.3. We may disclose personal data to competent authorities where this is necessary to comply with legal requirements or to establish, exercise or defend our legal rights.

4.4. Your data is not transferred to any other third parties.

5. Transfers Outside the EEA

5.1. Hosting of the website and storage of enquiries take place on servers located within the European Economic Area. In this respect, no transfer of personal data to third countries occurs.

5.2. When using Google’s email services, data may be processed in part outside the European Economic Area. Such transfers are safeguarded by appropriate measures in accordance with Chapter V GDPR, namely a European Commission adequacy decision (the EU-US Data Privacy Framework) and/or standard contractual clauses.

6. Retention Periods

6.1. Personal data is stored for no longer than is necessary for the purposes for which it was collected.

6.2. Enquiries and related correspondence, where the enquiry has not led to a contractual relationship, are stored for 12 months from the last contact, after which they are deleted.

6.3. Where an enquiry has led to the conclusion or performance of a contract, the relevant data is stored for the period necessary to perform the contract and to comply with legal requirements, including retention periods established for accounting purposes.

6.4. Data processed for the purpose of sending marketing communications is stored until you withdraw your consent or, in the absence of activity on your part, until 24 months have elapsed, after which the consent is deemed to have expired and the data is deleted or anonymised.

6.5. The hosting provider’s technical logs are stored for the period established by the provider to ensure the functioning and security of the website.

7. Rights of the Data Subject

7.1. In respect of your personal data, you have the following rights under the GDPR, to the extent and in the cases provided for by the Regulation:

  • the right of access to the data and to obtain a copy of it;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure of the data;
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object to processing based on our legitimate interest;
  • the right to withdraw, at any time, consent to processing for marketing purposes, which does not affect the lawfulness of processing carried out before the withdrawal.

7.2. To exercise your rights, and to withdraw consent, you may contact us at the email address indicated in Section 1. Each marketing communication will also provide the option to opt out of further communications.

7.3. If you consider that the processing of your personal data infringes legal requirements, you have the right to lodge a complaint with the supervisory authority, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).

8. Cookies

8.1. The website uses only strictly necessary (technical) cookies that ensure its functioning, including the operation of the contact form and remembering the selected interface language. Such cookies do not require consent and are not used for analytics, tracking or marketing.

8.2. The website does not use analytics, advertising or other non-essential cookies, nor does it load third-party resources that set such cookies.

8.3. You may delete stored cookies or restrict their use at any time in your browser settings. Disabling necessary cookies may affect the functioning of certain features of the website.

9. Security Measures

9.1. We apply reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. Data transmitted between your browser and the website is protected by encryption (TLS/HTTPS protocol).

9.2. No method of transmitting data over the internet is completely secure, so we cannot guarantee absolute security of the data; however, we take measures to maintain an appropriate level of its protection.

10. Changes to the Policy and Entry into Force

10.1. We may update this Policy from time to time. The current version is always published on this page, together with the date of entry into force. In the event of material changes, we will take reasonable steps to inform you.

10.2. This version enters into force on [effective date].