Last updated: 1 January 2025 | This policy complies with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and applicable Estonian data protection law.
1. Data Controller
DataAgentia
Lõõtsa tn 5, 11415 Tallinn, Estonia
Email: kristjan.sepper@dataagentia.online
2. Personal Data We Collect
2.1 Data You Provide
- First and last name
- Work email address
- Organisation name (optional)
- Message content and service interest submitted via our contact form
2.2 Data Collected Automatically
- IP address and approximate location
- Browser type and version, operating system
- Pages visited, time spent and referring URL
- Cookie consent preference (stored in browser localStorage)
3. Purposes and Legal Basis
- Responding to enquiries and pre-contractual steps — Art. 6(1)(b) GDPR
- Service delivery under contract — Art. 6(1)(b) GDPR
- Website security and operation — Art. 6(1)(f) GDPR (legitimate interests)
- Legal and regulatory compliance — Art. 6(1)(c) GDPR
- Non-essential cookies (with consent) — Art. 6(1)(a) GDPR
4. Retention Periods
- Enquiry and contact data: up to 3 years from last contact
- Contract-related data: up to 7 years (Estonian accounting and commercial law)
- Website usage logs: up to 12 months
- Cookie consent preference: until browser storage is cleared
5. Your Rights Under GDPR
Under GDPR Articles 15–22, you have the right to:
- Access — obtain a copy of your personal data we hold;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion ("right to be forgotten");
- Restriction — limit processing in certain circumstances;
- Portability — receive your data in a machine-readable format;
- Object — object to processing based on legitimate interests;
- Withdraw consent — at any time, without affecting prior lawful processing.
To exercise any right, email kristjan.sepper@dataagentia.online with the subject "Privacy Request" or "Opt-Out". We will respond within 30 days.
6. Data Sharing
We do not sell your personal data. We may share it with:
- Trusted service providers (e.g. hosting, email) acting as data processors under written data processing agreements;
- Competent authorities when required by applicable law.
7. International Transfers
Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are applied in accordance with GDPR Chapter V, including Standard Contractual Clauses or adequacy decisions where relevant.
8. Data Security
We implement appropriate technical and organisational security measures to protect your personal data. As a data management company, robust information security is fundamental to how we operate.
9. Cookies
For detailed information about our use of cookies and browser storage, please see our Cookie Policy.
10. Supervisory Authority
You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): aki.ee — or with your local EU supervisory authority.
11. Changes
We may update this policy from time to time. The most current version is always published on this page, with the revision date shown above.
12. Contact the Data Controller
DataAgentia
Lõõtsa tn 5, 11415 Tallinn, Estonia
kristjan.sepper@dataagentia.online