Last updated: 1 January 2025 | This policy complies with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and applicable Estonian data protection law.
1. Data Controller
MyDataBrick
J. Koorti tn 2-43, 13623 Tallinn, Estonia
Email: andres.magi@mydatabrick.shop
2. Personal Data We Collect
2.1 Data You Provide
- First and last name
- Work email address
- Organisation name (optional)
- Message content and service interest submitted via our contact form
2.2 Data Collected Automatically
- IP address and approximate geographic location
- Browser type and version, operating system
- Pages visited, time on page and referring URL
- Cookie consent preference (stored in browser localStorage)
3. Purposes and Legal Basis
- Responding to enquiries and pre-contractual steps — Art. 6(1)(b) GDPR
- Service delivery under contract — Art. 6(1)(b) GDPR
- Website security and legitimate operations — Art. 6(1)(f) GDPR (legitimate interests)
- Legal and regulatory compliance — Art. 6(1)(c) GDPR
- Non-essential cookies (where consent given) — Art. 6(1)(a) GDPR
4. Retention Periods
- Enquiry and contact data: up to 3 years from last contact
- Contract-related data: up to 7 years (Estonian accounting and commercial law)
- Website usage logs: up to 12 months
- Cookie consent preference: until browser storage is cleared by the user
5. Your Rights Under GDPR
Under GDPR Articles 15–22, you have the right to:
- Access — obtain a copy of personal data we hold about you;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — request deletion of your personal data;
- Restriction — limit how we process your data in certain circumstances;
- Portability — receive your data in a structured, machine-readable format;
- Object — object to processing based on our legitimate interests;
- Withdraw consent — at any time, without affecting prior lawful processing.
To exercise any right, email andres.magi@mydatabrick.shop with subject "Privacy Request". We will respond within 30 calendar days.
6. Data Sharing
We do not sell your personal data. We may share it with:
- Trusted service providers (e.g. web hosting, email delivery) acting as data processors under written agreements that comply with GDPR;
- Competent authorities when required by applicable law.
7. International Transfers
Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are applied under GDPR Chapter V — including Standard Contractual Clauses or adequacy decisions where applicable.
8. Data Security
We apply appropriate technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration or destruction. As a data management company, information security is a professional priority.
9. Cookies
For detailed information about our use of cookies and browser storage, see our Cookie Policy.
10. Supervisory Authority
You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): aki.ee — or with your local EU supervisory authority.
11. Changes to This Policy
We may update this policy from time to time. The most current version is published on this page with the revision date shown above.
12. Contact the Data Controller
MyDataBrick
J. Koorti tn 2-43, 13623 Tallinn, Estonia
andres.magi@mydatabrick.shop