Privacy Policy
01 Who we are
This privacy policy applies to MentiSec OÜ, entered in the Estonian Business Register, located in Tallinn (Narva mnt 10, 10124). Contact: [email protected]. MentiSec is the controller of personal data processed through this website and in client communication. In client projects we normally act as a processor, governed by a separate data processing agreement (DPA).
02 What data we collect
Via the contact form and e-mail: name and e-mail address; phone number (if provided); company (if provided); the content of your message.
When visiting the website: we use no marketing or tracking cookies and no Google Analytics or comparable third-party analytics. Technical server logs (IP address, browser, timestamp) are kept only for security and troubleshooting and are deleted by rotation.
In contractual relationships: data arising from invoices, contracts and correspondence is processed to fulfil statutory accounting and tax obligations.
03 Web analytics
We use self-hosted, cookieless analytics to understand whether and how our website reaches its visitors. At the moment of a page visit we process: the page visited, approximate location at city level, browser and device type, the referring page, technical performance metrics, and page-usage events (such as active reading time, scroll depth, link clicks, and whether the contact form was started or sent — form contents are never processed in analytics). The IP address is used only in memory while handling the request — it is not stored in analytics. To distinguish a visitor within a rolling 30-day window we derive an irreversible hash whose key is deleted at the end of the window; after that, visits cannot be linked to each other. Individual visit records are kept for up to 24 months; after that only anonymised aggregates remain. We honor the Global Privacy Control (GPC) signal. For security purposes we log requests by automated clients (bots) together with the IP address; these logs are kept for up to 12 months. The legal basis is legitimate interest (GDPR art 6(1)(f)); you may object to this processing (see “Your rights”), and the underlying assessment is available on request via our contact address.
04 Purposes and legal bases
Responding to enquiries — contract or pre-contractual measures (GDPR art 6(1)(b)). Performing the contract — service delivery, project documentation, invoicing. Compliance with legal obligations — accounting, tax (art 6(1)(c)). Legitimate interest — website security, fraud prevention, communication with existing clients (art 6(1)(f)). We do not use your data for direct marketing, profiling, or automated decision-making.
05 Retention
Enquiries that do not lead to a contract — up to 12 months, then deleted. Contractual data — for the duration of the contract and 7 years after the last transaction (Accounting Act §12). Server logs — up to 90 days.
06 Sharing
We never sell or rent your data. We share it only: with technical service providers that provide us e-mail, hosting, content-delivery and network-security (Cloudflare, Inc.) and e-mail-delivery services and act as processors bound by GDPR obligations — an up-to-date list of our main providers is available on request from [email protected]; with our accountant and tax adviser, to fulfil legal obligations; and with competent authorities where required by law. Where a provider processes data outside the European Economic Area, we ensure protection through European Commission standard contractual clauses or another valid transfer mechanism under GDPR chapter V.
07 Your rights
Under the GDPR you have the right to: request an overview of the data we process about you; have inaccurate data corrected; have data erased where we have no other legal basis; restrict or object to processing; receive your data in a machine-readable form (data portability); and lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee). Write to [email protected]; we normally respond within one month.
08 Security
We apply technical and organisational measures proportionate to the sensitivity of the data: encrypted storage and transfer, access restrictions, regular backups, multi-factor authentication. Client-specific security frameworks are agreed in a separate DPA.
09 Changes
We may update this policy when our operations, tooling or the legal framework change. Material changes are announced on the website and, where they affect an existing client, also directly by e-mail.
← Back to home