// legal
Privacy Policy & GDPR Statement
Last updated: 21 August 2026
1. Who is responsible for your data
The controller is 1PT Grupp Osaühing, an Estonian private limited company, registry code 11481296, EU VAT EE101404152, registered office A. Puškini tn 43, 20609 Narva, Ida-Viru maakond, Estonia.
Data protection contact: privacy@oneptgrupposauhing.com. General contact: support@oneptgrupposauhing.com, +372 5551 4827.
The company is not required to appoint a Data Protection Officer under GDPR Art. 37: its core activity is neither large-scale systematic monitoring nor large-scale processing of special categories of data. The address above reaches the person accountable for these questions.
2. What this policy covers
Personal data processed through the website oneptgrupposauhing.com and through direct correspondence with us. When we work inside a client's systems under a service agreement, we act as a processor for that client and the agreement's data-processing annex governs instead of this policy.
3. What we collect, why, and on what basis
3.1 Project enquiry form
- Data: company name, company website, your name, work email, optional phone, the scope answers you selected, your written description, and the plan our estimator computed from those answers.
- Purpose: to assess the enquiry, prepare a written scope and reply to you.
- Lawful basis: GDPR Art. 6(1)(b) — steps taken at your request before entering into a contract. We do not ask for your consent to this and do not rely on it.
- Retention: 24 months from the last contact, if the enquiry does not lead to an engagement. If it does, the retention period in the service agreement applies.
3.2 Contact form and direct email
- Data: name, email, optional phone, subject and message.
- Purpose: to answer your message and keep a record of business correspondence.
- Lawful basis: GDPR Art. 6(1)(f) — our legitimate interest in responding to business correspondence addressed to us. You may object at any time under Art. 21.
- Retention: 24 months, then deletion.
3.3 Optional technical mailing
- Data: the name and email you gave on the enquiry form, plus the fact that you ticked the optional box.
- Purpose: occasional technical notes about our work.
- Lawful basis: GDPR Art. 6(1)(a) — consent. It is genuinely optional: leaving it unticked changes nothing about whether your enquiry is answered. You can withdraw at any time, from any message or by writing to privacy@oneptgrupposauhing.com, and withdrawal does not affect anything sent beforehand.
- Retention: until you withdraw.
3.4 Abuse protection and server logs
- Data: a salted hash of the IP address that submitted a form, the browser user agent, the referring page, the HTTP status and a timestamp. The raw IP address is not stored in the application database — the hash is enough to count submissions from one source and not enough to reconstruct who sent them.
- Purpose: rate limiting, spam prevention and diagnosing faults.
- Lawful basis: GDPR Art. 6(1)(f) — legitimate interest in keeping the service available and free of automated abuse.
- Retention: rate-limit counters expire within 24 hours. Application logs are kept 90 days. Web-server access logs, which do contain IP addresses, are kept 30 days by the hosting provider and then rotated out.
3.5 Advertising measurement
- Data: only if you allow it — a Microsoft Advertising (UET) identifier and the page you arrived on.
- Purpose: to measure which of our own advertising campaigns lead to enquiries.
- Lawful basis: GDPR Art. 6(1)(a) consent, plus consent for the storage itself under the ePrivacy Directive as implemented in Estonia. Nothing is set before you choose, and refusing changes nothing about how this site works.
- Retention: as set out in the Cookie Policy, and under Microsoft's own retention rules as an independent controller for the data it receives.
4. What we never do with it
- We do not sell personal data, and never have.
- We do not share form submissions with advertising networks, data brokers or list providers.
- We do not build profiles or make automated decisions with legal or similarly significant effects.
- We do not send unsolicited marketing to addresses harvested from anywhere.
- We do not use the details in an enquiry for anything other than answering that enquiry.
5. Who else can see it
The website and its API run on a single application server. Personal data submitted through this site is handled by:
- Namecheap, Inc. (AS22612), as a processor, for the server this site runs on. The machine is located in United States — Los Angeles, California. Mail sent by the enquiry forms is delivered from that same server to our own mailbox provider.
- Microsoft Ireland Operations Ltd / Microsoft Corporation, as an independent controller, only if you allow advertising measurement.
Nobody else. There is no CRM, no analytics platform, no chat widget and no third-party font, script or pixel on this site — which you can confirm in your browser's network tab.
6. Transfers outside the EEA
This website is hosted in the United States. The server is operated by Namecheap, Inc. (AS22612) in United States — Los Angeles, California. Everything you submit through a form on this site is therefore stored on a machine outside the EEA, which is a transfer to a third country under Chapter V of the GDPR.
That transfer is made on the basis of the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) in the hosting provider's data processing agreement, together with the technical measures described in section 9: HTTPS in transit, access restricted to the application account, and IP addresses hashed rather than stored. We say this plainly rather than describing the site as “EU-hosted”, because it is not, and a residency claim that does not survive a DNS lookup is worse than no claim at all.
The company itself is established in Estonia, its records are kept there, and correspondence about your data is handled from there. If the hosting arrangement changes, this section changes with it.
If you allow advertising measurement, data received by Microsoft may be processed in the United States under the EU–US Data Privacy Framework and the Standard Contractual Clauses in Microsoft's terms. Declining that choice avoids the transfer entirely.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy (Art. 15);
- have inaccurate data corrected (Art. 16);
- have data erased where the conditions in Art. 17 are met;
- restrict processing (Art. 18);
- receive the data you gave us in a portable format (Art. 20);
- object to processing based on legitimate interests (Art. 21) — including everything in section 3.2 and 3.4;
- withdraw consent at any time, where consent is the basis (Art. 7(3)).
Write to privacy@oneptgrupposauhing.com. We answer within one month, as Art. 12(3) requires. We do not charge for this, and we do not ask for identity documents unless we genuinely cannot tell who is asking.
8. Complaints
If you think we have handled your data wrongly, tell us first — it is usually the fastest route to a fix. You also have the right to complain to the Estonian supervisory authority:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
www.aki.ee/en
If you are in another EU or EEA country, you may complain to your own national supervisory authority instead.
9. Security
Traffic to this site is served over HTTPS. Form submissions are validated and rate-limited on the server, IP addresses are hashed with a salt before storage, and access to the database is restricted to the application account. We do not ask for, and you should never send us, passwords, API keys or production credentials through a form on this website.
10. Changes
If this policy changes materially we update the date at the top and, where the change affects a purpose you are already involved in, we say so directly rather than relying on you re-reading the page. Every published version corresponds to a specific build of this site; the build identifier is printed in the footer.