Home/Privacy Policy
Legal · GDPR
Privacy Policy
How rixxityfi OÜ collects, uses and protects personal data — on this website and in the course of client work. Written to be read, not to be skipped.
Version 1.0 · Effective from 4 September 2026
rixxityfi OÜ respects your privacy and processes personal data in accordance with Regulation (EU) 2016/679 (the GDPR) and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus). This policy explains what happens to personal data that reaches us through this website, by e-mail, by telephone, or in the course of a project.
1. Who we are
The controller of your personal data is:
- rixxityfi OÜ, a private limited company registered in Estonia
- Registry code 17526485
- Registered address: Tiigi tn 4-45, Saku alevik, Saku vald, Harju maakond, 75501, Estonia
- E-mail: egertrosljukk@outlook.com
- Telephone: +372 5605 5198
We are not required to appoint a Data Protection Officer. Privacy questions are handled directly by the management board and can be sent to the e-mail address above.
2. What data we collect
2.1 Data you send us deliberately
When you contact us through the enquiry form, by e-mail, or by telephone, we receive whatever you choose to include. Typically this is:
- your name and, where relevant, your company name;
- your e-mail address and telephone number;
- the content of your message, including any details about your project, systems or business processes;
- any attachments or links you send us.
Note on the enquiry form. The form on our contact page does not transmit anything to a server of ours. It opens your own e-mail application with the message pre-filled, and the message is sent by you, from your own mailbox. We therefore receive it exactly as we would receive any other e-mail.
2.2 Data collected automatically
This website does not use analytics, advertising, profiling or third-party tracking of any kind. We do not operate cookies for measurement or marketing. The only browser storage used is a single local preference key that remembers you have dismissed the cookie notice — see the Cookies Policy.
Our hosting provider may, as any web server does, record technical connection data such as IP address, request time, requested file and user-agent string in its server logs for security and diagnostic purposes. We do not use these logs to identify individual visitors.
Web fonts on this site are loaded from Google Fonts. When a page loads, your browser makes a request to Google's servers, which necessarily discloses your IP address to them. If you would prefer to avoid this, browser extensions that block third-party font loading will prevent it without breaking the site.
2.3 Data received during a project
When we build or maintain software for you, we may be given access to systems that contain personal data belonging to your customers, staff or users. This is covered separately in section 10.
3. Why we process it
- To answer your enquiry. Reading your message, replying, asking clarifying questions and preparing an offer.
- To conclude and perform a contract. Agreeing scope, delivering work, providing support and handing over results.
- To issue and keep accounting records. Invoicing and retaining source documents as Estonian law requires.
- To defend legal claims. Keeping a record of what was agreed and delivered, in case of a later dispute.
- To keep our systems secure. Server logs and abuse prevention.
We do not sell personal data, we do not share it with advertising networks, and we do not use it for automated decision-making or profiling.
4. Legal bases
- Article 6(1)(b) — steps prior to a contract, and performance of a contract. Replying to your enquiry, quoting, and doing the work you engaged us for.
- Article 6(1)(c) — legal obligation. Retention of accounting documents under the Estonian Accounting Act.
- Article 6(1)(f) — legitimate interests. Keeping records of correspondence, securing our infrastructure, and establishing or defending legal claims. We have assessed that these interests do not override your rights and freedoms.
- Article 6(1)(a) — consent. Only where we ask for it explicitly, for example if you ask to be added to a mailing list. Consent can be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
5. How long we keep it
- Enquiries that do not become projects: up to 12 months from the last message, then deleted.
- Client correspondence and project records: for the duration of the engagement and 3 years afterwards, matching the general limitation period for contractual claims under Estonian law.
- Accounting documents (invoices, contracts): 7 years from the end of the relevant financial year, as required by the Estonian Accounting Act.
- Server logs held by our hosting provider: typically a few weeks, according to the provider's own retention settings.
When a retention period ends, data is deleted or irreversibly anonymised.
6. Who else sees it
We keep the list of recipients deliberately short. Personal data may be disclosed to:
- Our e-mail provider, which necessarily processes the messages you send us;
- Hosting and infrastructure providers used to run this website and, where applicable, your project;
- Our accountant, for invoices and accounting records;
- Public authorities, where we are legally obliged to disclose information.
Every processor acting on our behalf is bound by a written data processing agreement under Article 28 GDPR. We do not transfer personal data to third parties for their own marketing purposes, ever.
7. Transfers outside the EEA
We prefer service providers located in the European Economic Area. Where a provider processes data outside the EEA — for example, an e-mail service or a font provider operated by a company established in the United States — the transfer is based on an adequacy decision of the European Commission, or on Standard Contractual Clauses together with supplementary measures where required. You may request information about the safeguards applied to a specific transfer.
8. How we protect it
- Encrypted connections (HTTPS/TLS) for this website and for all systems we operate;
- Access to client systems limited to what a task actually requires, and revoked when the engagement ends;
- Multi-factor authentication on accounts that hold client data;
- Encrypted device storage and a password manager, rather than credentials in spreadsheets or chat messages;
- Backups stored separately from production systems, with restores tested rather than assumed.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Estonian Data Protection Inspectorate within 72 hours and inform you directly where the law requires it.
9. Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — have your data deleted, where no legal obligation requires us to keep it;
- Restriction — have processing limited while a dispute about accuracy or lawfulness is resolved;
- Portability — receive data you provided to us in a structured, machine-readable format;
- Object — object to processing based on our legitimate interests;
- Withdraw consent — at any time, where processing is based on consent.
To exercise any of these, write to egertrosljukk@outlook.com. We reply within one month. The request is free of charge; we may ask you to confirm your identity before disclosing personal data, and manifestly excessive or repetitive requests may attract a reasonable fee or be refused, as permitted by Article 12(5).
10. Client project data
When we develop or maintain software for a client and are given access to systems containing personal data of that client's own customers, staff or users, then in respect of that data:
- the client is the controller and rixxityfi OÜ acts as a processor;
- we process such data only on the client's documented instructions;
- a data processing agreement under Article 28 GDPR is concluded before access is granted;
- we do not use client data for our own purposes, do not copy it beyond what a task requires, and delete or return working copies when the engagement ends;
- we engage sub-processors only with the client's agreement.
If you are an end user of a system we built for someone else, that company — not rixxityfi OÜ — is the controller of your data, and your rights should be addressed to them.
11. Children
Our services are directed at businesses and organisations. We do not knowingly collect personal data of children. If you believe a child has sent us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy when our practices, services or the law change. The version number and effective date at the top of this page always show the current edition. Material changes affecting existing clients are communicated by e-mail.
13. Contact and complaints
Questions, requests and complaints about how we handle personal data can be sent to egertrosljukk@outlook.com or by post to the registered address above. We would prefer to resolve any concern directly with you.
You also have the right to lodge a complaint with the Estonian supervisory authority:
- Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
- Tatari 39, 10134 Tallinn, Estonia
- E-mail: info@aki.ee · Web: www.aki.ee
If you are resident in another EU member state, you may also complain to the supervisory authority of that country.
rixxityfi OÜ · Registry code 17526485 · Version 1.0 · Effective 4 September 2026
Related
Cookies Policy
Exactly what this website stores in your browser — which is almost nothing.
Read
Related
Terms of Service
How engagements work: scope, payment, intellectual property, warranty and liability.
Read
Questions?
Contact us
Data requests and privacy questions are answered within one month, usually much sooner.
Write