Privacy Policy
How Myndaris OÜ processes personal data under Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and Estonian law. Last updated: 27 July 2026. Version 1.0.
Myndaris OÜ (“we”, “us”), operating the euroriie website, respects your privacy. This policy explains, in plain language, what personal data we process, why, on what legal basis, how long we keep it, who we share it with, and the rights you have under the GDPR.
1. Who controls your data
The controller of your personal data, within the meaning of Art. 4(7) GDPR, is:
- Legal name: Myndaris OÜ
- Registry code: 17553520 (Estonian Commercial Register)
- Registered office: Pärnu mnt 106-21, Kesklinna linnaosa, 11312 Tallinn, Estonia
- Phone: +372 8108 0284
- General email: info@euroriie.com
- Privacy contact: privacy@euroriie.com
We are a small company and are not required to appoint a Data Protection Officer under Art. 37 GDPR, and we have not appointed one. Privacy enquiries are handled through the privacy contact above.
2. Scope of this policy
This policy applies to personal data processed through the euroriie.com website and the communications arising from it — the contact form, email and telephone enquiries, and the preliminary steps towards a possible engagement.
Personal data processed while performing a signed service agreement is governed by that agreement and its data-protection terms, in addition to this policy.
3. Personal data we process
We process only the data needed for the purposes described here, in line with the data-minimisation principle (Art. 5(1)(c) GDPR).
| Category | Data | Source |
|---|---|---|
| Identification & contact | Name, email, phone (if you provide it) | You, via the contact form or a direct message |
| Enquiry content | The subject you select and the free text of your message | You |
| Server access logs | IP address, date and time of request, browser user-agent | Collected automatically by the hosting server |
| Cookie preference | Your stored cookie/notice choice and its version and timestamp | Stored in your browser when you make a choice |
Please do not send sensitive data through the form. We do not ask for special-category data (health, beliefs, and similar) or identity documents through the website. Where such data is genuinely needed for an engagement, we request it through an appropriate channel with a proper legal basis.
4. Purposes and legal bases
Each processing activity has a specific purpose and a legal basis under Art. 6(1) GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Respond to your enquiry | Identification, contact and message content | Legitimate interest in answering enquiries addressed to us — Art. 6(1)(f) |
| Take pre-contractual steps at your request | Identification, contact and message content | Steps prior to entering a contract — Art. 6(1)(b) |
| Keep the site secure and working | Server access logs, cookie preference | Legitimate interest in network and information security — Art. 6(1)(f) (Recital 49) |
| Comply with legal, accounting and tax obligations | Identification and records of communications | Compliance with a legal obligation — Art. 6(1)(c) |
| Establish, exercise or defend legal claims | Data relevant to the matter | Legitimate interest — Art. 6(1)(f) |
| Send optional updates, if you opt in | Name and email | Consent — Art. 6(1)(a) |
| Analytics / advertising cookies, if enabled and allowed | Device and usage identifiers | Consent — Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy |
Where we rely on legitimate interest (Art. 6(1)(f)), we have weighed it against your rights and freedoms and limited the processing to what is necessary. You may object at any time (see your rights below).
Where we rely on consent (Art. 6(1)(a)), you may withdraw it at any time, as easily as you gave it, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)).
Providing data through the contact form is voluntary; if you do not provide it, we simply cannot answer your enquiry (Art. 13(2)(e)).
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22).
5. Who receives your data
We do not sell or rent personal data. We share it only as far as necessary:
- Service providers (processors): our website hosting provider and our email provider, acting on our documented instructions under Art. 28 GDPR.
- Meta Platforms: only if advertising cookies are enabled and you consent — for conversion measurement and advertising on Facebook and Instagram. This is not active at present (see the Cookie Policy).
- Professional advisers: accountants or lawyers, where needed to meet a legal obligation or to exercise or defend legal claims.
- Public authorities: where required by law or a valid order.
6. International data transfers
Our core processing takes place within the European Economic Area (EEA). Some providers may process data outside the EEA.
If, and only if, you consent to advertising cookies, the related data may be transferred to Meta Platforms, Inc. in the United States. For such transfers we rely on the EU–U.S. Data Privacy Framework adequacy decision and/or the European Commission's 2021 Standard Contractual Clauses, as incorporated into Meta's data-processing terms. The legal position of the Data Privacy Framework is subject to ongoing review at EU level; we keep the safeguard we rely on under review and will update this section as needed. You can ask us for a copy of the relevant safeguards using the privacy contact below.
At present the site loads no advertising or analytics tools, so no such international transfer takes place. This section describes what would apply if those tools are switched on with your consent.
7. Server logs and IP addresses
Like most websites, our hosting server records technical access data (including IP address, timestamp and user-agent) to keep the service secure and reliable. These logs are kept confidential, used only for security and troubleshooting, and not used to build behavioural profiles.
8. How long we keep data
| Data | Retention |
|---|---|
| Contact messages that do not lead to an engagement | Up to 24 months after the last contact, then deleted |
| Data linked to a signed agreement | For the term of the agreement and the statutory retention and limitation periods that apply after it ends |
| Accounting documents | 7 years, as required by the Estonian Accounting Act |
| Server access logs | A short period consistent with security needs, then deleted or anonymised |
| Cookie preference record | Up to 12 months, or until you clear it |
| Data processed on the basis of consent | Until you withdraw consent |
When the purpose ends, we delete or anonymise the data, unless the law requires us to keep it (Art. 17(3) GDPR).
9. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), proportionate to our size and the small volume of data this site processes:
- the whole site is served over HTTPS/TLS;
- access to data is limited to those who need it for the stated purpose;
- individual credentials and, where supported, two-factor authentication;
- confidentiality and security obligations imposed on our processors;
- regular maintenance and updates of the systems we use.
No measure is absolute. If a personal-data breach is likely to result in a risk to your rights, we will notify the Estonian Data Protection Inspectorate, and you where required, in line with Arts. 33–34 GDPR.
10. Your rights
Under the GDPR you have the right to:
- Access your personal data and obtain a copy (Art. 15).
- Rectification of inaccurate or incomplete data (Art. 16).
- Erasure (“right to be forgotten”) in the cases set out in Art. 17.
- Restriction of processing in the cases set out in Art. 18.
- Data portability — to receive certain data in a structured, machine-readable format and have it transmitted to another controller (Art. 20).
- Object to processing based on legitimate interest, on grounds relating to your situation, and to object at any time to direct marketing (Art. 21).
- Withdraw consent at any time, where processing is based on consent (Art. 7(3)).
- Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22) — which we do not carry out.
11. How to exercise your rights
Send your request to privacy@euroriie.com. Exercising your rights is free of charge. We may ask for information to confirm your identity, to make sure data is not disclosed to the wrong person.
We respond without undue delay and within one month of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests; if so, we will tell you within the first month and explain why (Art. 12(3)).
12. Right to complain
If you believe we process your data unlawfully, you may lodge a complaint with the Estonian supervisory authority (Art. 77 GDPR):
- Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
- Tatari 39, 10134 Tallinn, Estonia
- Email: info@aki.ee · Phone: +372 627 4135
- Website: www.aki.ee
13. Cookies and similar technologies
At present the site sets no cookies of its own and runs no analytics or advertising trackers. The only item stored on your device is a strictly-necessary record of your cookie/notice choice. Full details, and what would apply if analytics or advertising tools are added, are in our Cookie Policy. You can review your choice at any time:
14. Children's data
Our services are aimed at businesses and adults. We do not knowingly collect data from children. Under Estonian law the age at which a child can consent to information-society services is 13; if you are a parent or guardian and believe a child has provided us data without the necessary consent, please contact privacy@euroriie.com and we will delete it.
15. Changes to this policy
We may update this policy to reflect legal, regulatory or operational changes. The last-updated date and version appear at the top. Where a change materially affects how we use your data, we will make the update visible on this page and, where required, ask for fresh consent.
16. Contact
- Myndaris OÜ — registry code 17553520, Estonian Commercial Register
- Pärnu mnt 106-21, Kesklinna linnaosa, 11312 Tallinn, Estonia
- Privacy: privacy@euroriie.com
- General: info@euroriie.com
- Phone: +372 8108 0284