Myndaris OÜ (“we”, “us”), operating the euroriie website, respects your privacy. This policy explains, in plain language, what personal data we process, why, on what legal basis, how long we keep it, who we share it with, and the rights you have under the GDPR.

1. Who controls your data

The controller of your personal data, within the meaning of Art. 4(7) GDPR, is:

  • Legal name: Myndaris OÜ
  • Registry code: 17553520 (Estonian Commercial Register)
  • Registered office: Pärnu mnt 106-21, Kesklinna linnaosa, 11312 Tallinn, Estonia
  • Phone: +372 8108 0284
  • General email: info@euroriie.com
  • Privacy contact: privacy@euroriie.com

We are a small company and are not required to appoint a Data Protection Officer under Art. 37 GDPR, and we have not appointed one. Privacy enquiries are handled through the privacy contact above.

2. Scope of this policy

This policy applies to personal data processed through the euroriie.com website and the communications arising from it — the contact form, email and telephone enquiries, and the preliminary steps towards a possible engagement.

Personal data processed while performing a signed service agreement is governed by that agreement and its data-protection terms, in addition to this policy.

3. Personal data we process

We process only the data needed for the purposes described here, in line with the data-minimisation principle (Art. 5(1)(c) GDPR).

Category Data Source
Identification & contact Name, email, phone (if you provide it) You, via the contact form or a direct message
Enquiry content The subject you select and the free text of your message You
Server access logs IP address, date and time of request, browser user-agent Collected automatically by the hosting server
Cookie preference Your stored cookie/notice choice and its version and timestamp Stored in your browser when you make a choice

Please do not send sensitive data through the form. We do not ask for special-category data (health, beliefs, and similar) or identity documents through the website. Where such data is genuinely needed for an engagement, we request it through an appropriate channel with a proper legal basis.

4. Purposes and legal bases

Each processing activity has a specific purpose and a legal basis under Art. 6(1) GDPR.

Purpose Data used Legal basis
Respond to your enquiry Identification, contact and message content Legitimate interest in answering enquiries addressed to us — Art. 6(1)(f)
Take pre-contractual steps at your request Identification, contact and message content Steps prior to entering a contract — Art. 6(1)(b)
Keep the site secure and working Server access logs, cookie preference Legitimate interest in network and information security — Art. 6(1)(f) (Recital 49)
Comply with legal, accounting and tax obligations Identification and records of communications Compliance with a legal obligation — Art. 6(1)(c)
Establish, exercise or defend legal claims Data relevant to the matter Legitimate interest — Art. 6(1)(f)
Send optional updates, if you opt in Name and email Consent — Art. 6(1)(a)
Analytics / advertising cookies, if enabled and allowed Device and usage identifiers Consent — Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy

Where we rely on legitimate interest (Art. 6(1)(f)), we have weighed it against your rights and freedoms and limited the processing to what is necessary. You may object at any time (see your rights below).

Where we rely on consent (Art. 6(1)(a)), you may withdraw it at any time, as easily as you gave it, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)).

Providing data through the contact form is voluntary; if you do not provide it, we simply cannot answer your enquiry (Art. 13(2)(e)).

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22).

5. Who receives your data

We do not sell or rent personal data. We share it only as far as necessary:

  • Service providers (processors): our website hosting provider and our email provider, acting on our documented instructions under Art. 28 GDPR.
  • Meta Platforms: only if advertising cookies are enabled and you consent — for conversion measurement and advertising on Facebook and Instagram. This is not active at present (see the Cookie Policy).
  • Professional advisers: accountants or lawyers, where needed to meet a legal obligation or to exercise or defend legal claims.
  • Public authorities: where required by law or a valid order.

6. International data transfers

Our core processing takes place within the European Economic Area (EEA). Some providers may process data outside the EEA.

If, and only if, you consent to advertising cookies, the related data may be transferred to Meta Platforms, Inc. in the United States. For such transfers we rely on the EU–U.S. Data Privacy Framework adequacy decision and/or the European Commission's 2021 Standard Contractual Clauses, as incorporated into Meta's data-processing terms. The legal position of the Data Privacy Framework is subject to ongoing review at EU level; we keep the safeguard we rely on under review and will update this section as needed. You can ask us for a copy of the relevant safeguards using the privacy contact below.

At present the site loads no advertising or analytics tools, so no such international transfer takes place. This section describes what would apply if those tools are switched on with your consent.

7. Server logs and IP addresses

Like most websites, our hosting server records technical access data (including IP address, timestamp and user-agent) to keep the service secure and reliable. These logs are kept confidential, used only for security and troubleshooting, and not used to build behavioural profiles.

8. How long we keep data

Data Retention
Contact messages that do not lead to an engagement Up to 24 months after the last contact, then deleted
Data linked to a signed agreement For the term of the agreement and the statutory retention and limitation periods that apply after it ends
Accounting documents 7 years, as required by the Estonian Accounting Act
Server access logs A short period consistent with security needs, then deleted or anonymised
Cookie preference record Up to 12 months, or until you clear it
Data processed on the basis of consent Until you withdraw consent

When the purpose ends, we delete or anonymise the data, unless the law requires us to keep it (Art. 17(3) GDPR).

9. Security

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), proportionate to our size and the small volume of data this site processes:

  • the whole site is served over HTTPS/TLS;
  • access to data is limited to those who need it for the stated purpose;
  • individual credentials and, where supported, two-factor authentication;
  • confidentiality and security obligations imposed on our processors;
  • regular maintenance and updates of the systems we use.

No measure is absolute. If a personal-data breach is likely to result in a risk to your rights, we will notify the Estonian Data Protection Inspectorate, and you where required, in line with Arts. 33–34 GDPR.

10. Your rights

Under the GDPR you have the right to:

  1. Access your personal data and obtain a copy (Art. 15).
  2. Rectification of inaccurate or incomplete data (Art. 16).
  3. Erasure (“right to be forgotten”) in the cases set out in Art. 17.
  4. Restriction of processing in the cases set out in Art. 18.
  5. Data portability — to receive certain data in a structured, machine-readable format and have it transmitted to another controller (Art. 20).
  6. Object to processing based on legitimate interest, on grounds relating to your situation, and to object at any time to direct marketing (Art. 21).
  7. Withdraw consent at any time, where processing is based on consent (Art. 7(3)).
  8. Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22) — which we do not carry out.

11. How to exercise your rights

Send your request to privacy@euroriie.com. Exercising your rights is free of charge. We may ask for information to confirm your identity, to make sure data is not disclosed to the wrong person.

We respond without undue delay and within one month of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests; if so, we will tell you within the first month and explain why (Art. 12(3)).

12. Right to complain

If you believe we process your data unlawfully, you may lodge a complaint with the Estonian supervisory authority (Art. 77 GDPR):

  • Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
  • Tatari 39, 10134 Tallinn, Estonia
  • Email: info@aki.ee · Phone: +372 627 4135
  • Website: www.aki.ee

13. Cookies and similar technologies

At present the site sets no cookies of its own and runs no analytics or advertising trackers. The only item stored on your device is a strictly-necessary record of your cookie/notice choice. Full details, and what would apply if analytics or advertising tools are added, are in our Cookie Policy. You can review your choice at any time:

14. Children's data

Our services are aimed at businesses and adults. We do not knowingly collect data from children. Under Estonian law the age at which a child can consent to information-society services is 13; if you are a parent or guardian and believe a child has provided us data without the necessary consent, please contact privacy@euroriie.com and we will delete it.

15. Changes to this policy

We may update this policy to reflect legal, regulatory or operational changes. The last-updated date and version appear at the top. Where a change materially affects how we use your data, we will make the update visible on this page and, where required, ask for fresh consent.

16. Contact