Eesti Firma (legal name: Eesti Firma OÜ, registry code 14164797, registered address Vesivärava 50-301, 10152 Tallinn, Estonia) is the operator of the website eestifirma.ee and the controller of the personal data processed through it. We are a licensed trust and company service provider (TCSP licence FIU000144) supervised by the Estonian Financial Intelligence Unit, and we strictly comply with data protection legislation, including the Personal Data Protection Act of the Republic of Estonia and the General Data Protection Regulation (EU) 2016/679 (GDPR).
This Privacy Policy explains, in plain terms, what personal data we collect, why we collect it, the legal basis for each use, how long we keep it, whom we share it with, and the rights you can exercise. By using the eestifirma.ee website, you confirm that you have read and understood the data processing practices described herein.
In short
We collect only the data needed to provide our Services, meet our legal obligations, and improve the Website. We never sell or rent your personal data. We store it within the European Economic Area and process it strictly under the GDPR. You can access, correct, or delete your data — and reach our Data Protection Officer — at any time. By law, we keep client due-diligence data for 5 years and accounting records for 7 years.
For a complete understanding of how we operate, we also recommend reviewing our related policies and rules:
Who We Are (Data Controller)
The data controller responsible for your personal data is Eesti Firma OÜ, registry code 14164797, registered at Vesivärava 50-301, 10152 Tallinn, Estonia. You can reach us at info@eestifirma.ee or +372 641 7777. We have appointed a Data Protection Officer (DPO), whose contact details are provided in the “Contact Information” section below. The DPO is your single point of contact for any question about how your data is handled.
Information We Collect
We collect and process various types of information, strictly adhering to the principles of data minimization and lawful data collection. The primary categories of data we collect include:
- Personal Data: Information you provide to us directly, such as your name, email address, telephone number, and other details you submit during account registration, contacting us, or using our services. In certain cases (e.g., to comply with AML requirements), this may also include identification data, such as a copy of an identity document and beneficial-owner information.
- Technical Data: Information automatically collected when visiting our website, including IP address, browser type, device information, operating system version, and other technical parameters. These data enable us to ensure the correct operation of the site, compatibility with various devices, and optimization of user experience.
- Usage Data: Information about your interactions with the site. We record which pages you visit, the time spent on each page, how you navigate between sections, referral sources to our site, and how you interact with the content. This data is essential for analyzing user activity and improving our services.
- Communication Data: Information contained in your correspondence with us. If you contact our team via email, feedback forms, or other means, we retain records of such communications, including provided contact details and message content. This allows us to process your inquiries effectively and enhance service quality.
We deliberately do not collect data from individuals under 18 years of age. Our website and services are not intended for minors. If we become aware that personal data of a child has been collected without parental/guardian consent, we will promptly delete such information.
How We Use Your Information
We process personal data only on the lawful grounds set out in the GDPR: to fulfil contractual obligations, to comply with legal requirements, to pursue our legitimate interests, or on the basis of your consent. We use information ethically and only for the purposes for which it was collected. The primary purposes for processing your data include:
- Provision of Services: We use your data to provide our services and fulfill contractual obligations towards you. This includes company registration, legal support, accounting services, and other services we offer. Data processing for these purposes is essential for concluding or performing a contract with you, as well as for managing ongoing customer relationships.
- Communication with Users: Your contact information is used to respond to your inquiries, provide service consultations, and deliver important notifications and updates. With your consent, we may also send newsletters or promotional offers tailored to your preferences. You may always opt out of marketing messages using the unsubscribe link provided in the email or by contacting us directly.
- Analytics and Service Improvement: We analyze visitor behavior on our website to enhance its functionality and content. Usage data (in anonymized or aggregated form) helps us understand audience needs, optimize navigation, improve user interface convenience, and develop new features. Such processing is based on our legitimate interest in service improvement, while we take measures to minimize interference with your privacy (for example, using aggregated data).
- Legal Compliance: We may process and retain specific data to comply with our legal obligations. This notably pertains to accounting and tax regulations, as well as anti-money laundering and counter-terrorism financing requirements. For instance, by law, we must identify clients and retain certain data for reporting purposes. Data processing for legal compliance is mandatory and based on legal requirements.
- Security Measures: Collected data are used to ensure the security of our website, your accounts, and our services. We monitor to detect and prevent fraud, unauthorized access, cyberattacks, and other threats. Such processing is based on our legitimate interest in safeguarding our infrastructure and users. We continually improve our monitoring and protection systems to keep your data secure.
Please note that we do not engage in automated decision-making that produces legal or similarly significant effects on you. No critical decision (such as whether to provide a service, or at what price) is made solely by algorithms without human involvement.
Legal Bases and Retention at a Glance
The table below summarizes, for each category of data, why we process it, the GDPR legal basis we rely on, and how long we keep it. This overview is provided for transparency; the rest of this policy explains each point in more detail.
| Data category | Purpose | Legal basis (GDPR) | Retention period |
|---|---|---|---|
| Identification / KYC data (name, ID document, beneficial-owner info) | Client onboarding and AML/CFT due diligence | Legal obligation — Art. 6(1)(c); Money Laundering and Terrorist Financing Prevention Act | 5 years after the end of the business relationship |
| Contract & service data (orders, service-related correspondence) | Providing and administering the Services | Performance of a contract — Art. 6(1)(b) | Duration of the relationship + statutory limitation period |
| Accounting & invoicing data | Bookkeeping, tax and accounting compliance | Legal obligation — Art. 6(1)(c); Accounting Act | 7 years after the end of the financial year |
| Marketing data (email, preferences) | Newsletters and tailored offers | Consent — Art. 6(1)(a) | Until you withdraw consent / unsubscribe |
| Technical & usage data (IP, device, analytics) | Site operation, security and analytics | Legitimate interests — Art. 6(1)(f) | As set out in our Cookie Notice; aggregated thereafter |
| Communication data (inquiries, support) | Responding to and managing requests | Legitimate interests / contract — Art. 6(1)(f)/(b) | Duration of the relationship + limitation period |
Cookies and Tracking Technologies
To enhance your user experience and analyze website traffic, we use cookies and similar tracking technologies. This enables us to tailor our website content to your interests and better understand how users interact with our website.
The use of cookies is conducted in accordance with applicable laws (e.g., the EU Directive on Privacy and Electronic Communications) and our separate Cookie Notice. The main categories of cookies we use are:
- Strictly Necessary Cookies: These cookies are essential for the proper functioning of the website. They enable basic functionalities (such as saving your privacy preferences or maintaining your logged-in session) and cannot be disabled, as the website would not function properly without them.
- Analytical Cookies: These cookies collect anonymized statistics about how visitors use our website, such as which pages are visited, how long users spend on each page, or whether they encounter errors. We use this information to improve website performance and usability. For instance, such technologies help us identify the most popular sections and optimize the content accordingly.
- Marketing Cookies: These cookies are used to deliver more relevant advertisements and promotions for our services. They allow us to track the effectiveness of advertising campaigns and may remember what you’ve viewed on our website in order to offer you similar services. We use marketing cookies responsibly and, where required, obtain your consent before placing them on your device.
You have the right to manage your cookie settings at any time. Most browsers allow you to disable unnecessary cookies or delete existing cookie files. Please be aware, however, that disabling strictly necessary cookies may impact the website’s functionality. You can find more detailed information in our Cookie Notice and your browser settings.
Data Sharing with Third Parties
We do not sell or rent your personal data to third parties. However, to run our business and deliver our Services, we may need to share data with trusted partners bound by confidentiality obligations. Such third parties may include:
- Outsourced Service Providers: We cooperate with reliable companies and specialists who assist us in providing services. These include, for example, hosting providers and data centers (for hosting our website and databases), payment processing services (for handling transactions), analytics platforms (for traffic monitoring), and customer support services. In these cases, we only provide partners with the minimum necessary amount of data and require strict adherence to confidentiality and data protection measures under data processing agreements.
- Compliance with Legal Requirements: We may disclose your information to governmental authorities, regulators, or other authorized entities when legally required — for example, to the Financial Intelligence Unit, the Tax and Customs Board, or a court. Disclosure may be necessary to comply with a court order, during the investigation of illegal activities, or to protect our legitimate rights and interests. In each case, we carefully assess the legality of the request and disclose only the information required by law.
Beyond the cases above, your data may be transferred as part of a corporate restructuring. If we merge with another entity, sell the business, or otherwise reorganize, users’ personal data may pass to the successor. In such cases, we will ensure the recipient is bound by the same confidentiality obligations set out in this policy.
Data Security
We apply appropriate technical and organizational measures to protect your personal data against unauthorized disclosure, unlawful access, destruction, or alteration. These include encryption, firewalls, intrusion detection systems, and strict control over physical and logical access to our servers. Internally, our information security policies limit employee access to personal data on a need-to-know basis, supported by regular staff training. Together, these measures safeguard the confidentiality, integrity, and availability of your data, as required by the GDPR. While no method of transmission or storage over the Internet is ever 100% secure, we continually update and test our security systems to minimize risk.
Data Retention
We keep personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer period is required or permitted by law. Specific statutory periods apply: client due-diligence (KYC) data collected for anti-money-laundering purposes is kept for 5 years after the end of the business relationship, as required by the Estonian Money Laundering and Terrorist Financing Prevention Act; accounting source documents are kept for 7 years after the end of the financial year, as required by the Estonian Accounting Act. Other data is generally kept for the duration of the relationship plus the applicable limitation period. Once the relevant period expires, the data is securely deleted or anonymized so that you can no longer be identified. We review our data holdings and retention periods regularly, keeping data no longer than necessary.
International Data Transfers
Currently, all personal data are stored and processed within the European Economic Area (EEA), primarily on servers located in Estonia or other EU countries. We do not transfer your data to countries outside the EEA unless explicitly required for providing services (e.g., if you are located outside the EU and request us to contact a local partner).
Should we ever need to transfer your data outside the EEA, we will put in place all safeguards required by law. In practice, this means transferring data only to countries the European Commission has recognized as offering adequate protection, or under Standard Contractual Clauses (SCC) or another authorized mechanism. Your data stays protected even if it is processed outside the European Union.
Links to Third-Party Websites
Our website may contain links to external websites or services that are not controlled by our company. This Privacy Policy does not extend to such third-party resources. We are not responsible for the content or privacy practices of external websites. We recommend reviewing the privacy policies of each external resource before providing any personal data on such sites.
Children’s Privacy
We recognize the importance of protecting children’s personal data. Our website and services are not intended for individuals under the age of 18, and we do not knowingly collect data from children without appropriate consent from their parents or legal guardians. If we become aware that we have inadvertently received personal data from a minor under 18 years old, we will promptly take steps to delete such information from our servers. Parents who discover that their child may have provided us with personal data are encouraged to contact us so we can swiftly remove the relevant information.
Your Rights
In accordance with the GDPR and other applicable regulations, you, as a data subject, have extensive rights concerning your personal data. We respect these rights and strive to facilitate their exercise. You have the right to:
- Access your data: request confirmation that your personal data is being processed, as well as obtain a copy of the data we hold about you. This enables you to know exactly what information is processed and verify the lawfulness of its processing.
- Rectify your data: request correction of inaccurate or outdated personal data concerning you. We will promptly make the necessary adjustments to ensure the accuracy and currency of your information.
- Erase your data: in certain circumstances, request the deletion of your personal data (“right to be forgotten”). For example, you can request deletion if the data is no longer necessary for the purposes for which it was collected, or if you withdraw your consent and we have no other lawful grounds for processing. Please note that this right is not absolute—there are exceptions (for example, we cannot delete data that we are legally required to retain).
- Restrict processing: in specific situations, request temporary restriction of the processing of your data (for example, while disputing the accuracy of the data or objecting to processing). During the restriction period, we will merely store your data, pausing active operations involving it.
- Object to processing: you have the right to object to processing your data if such processing is based on our legitimate interests or carried out for direct marketing purposes. In certain cases prescribed by law, we must stop such processing upon your request. In particular, you can always unsubscribe from mailings and object to profiling for marketing purposes.
- Data portability: obtain personal data you have provided to us in a structured, commonly used format (e.g., CSV) and/or request its transfer directly to another provider, if technically feasible. This right applies when processing is based on your consent or a contract with you and is carried out by automated means.
- Withdraw consent: if any data processing relies on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before your withdrawal, but we will cease such processing going forward. For instance, you can unsubscribe from marketing newsletters you previously agreed to receive at any time.
Note
The right to erasure is not absolute. Where we are legally required to keep certain data — for example, client due-diligence records for 5 years under anti-money-laundering law, or accounting documents for 7 years under the Accounting Act — we will retain it for the statutory period before deleting it, even if you request earlier deletion.
You also have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated or your data processed unlawfully. The supervisory authority in Estonia is the Data Protection Inspectorate (Andmekaitse Inspektsioon). You may contact this authority, or a supervisory authority in your place of residence. We hope to resolve any concern directly, but you are entitled to escalate it to the regulator at any time.
To exercise any of these rights, contact us using any method listed in the “Contact Information” section. We handle requests free of charge and respond without undue delay, and in any event within one month of receiving your request, as required by the GDPR. If we need an extension, or have to decline a request on lawful grounds, we will tell you within that period and explain the reasons.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or new technologies. When we publish an updated version, it appears on this page with the date of the latest revision shown at the top.
The updated version takes effect as soon as it is published. We recommend checking this section periodically to stay informed about the current version.
Contact Information
If you have questions, comments, or requests related to the processing of your personal data on our website, please contact us:
- Company: Eesti Firma OÜ
- Registration Code: 14164797
- Address: Vesivärava 50-301, 10152 Tallinn, Estonia
- Data Protection Officer (DPO): Ilja Nikiforov
- Email: info@eestifirma.ee
- Phone: +372 641 7777
We value the trust of our clients and visitors and aim to respond promptly and thoroughly. You will receive a reply no later than one month from the date of your request, as required by applicable law.
We welcome your questions and are always glad to provide further information about your personal data and how we protect it. Your privacy and data security are our highest priority.
This Privacy Policy was developed and approved by the lawyer, Data Protection Officer (DPO), and co-founder of Eesti Firma OÜ – Ilja Nikiforov, who is responsible for monitoring the company’s compliance with data protection legislation (GDPR), as well as implementing best compliance practices in the company’s activities. The provisions of this policy apply to every client of the company without exception. If you have any questions or require further clarification, please contact Eesti Firma‘s support service directly.