Privacy Policy

Last Updated: July 24, 2026

The privacy of our clients’ personal data is essential to eBusiness Solutions OÜ (hereinafter — “legaladdressinestonia.com“, “we”, “us”, or “our”).

This Policy describes the rules according to which legaladdressinestonia.com processes the personal data of any individual using the legaladdressinestonia.com website and any services offered by legaladdressinestonia.com.

1. General Definitions

legaladdressinestonia.com — the service provider that needs to process the Client’s personal data to deliver services. Depending on the service, the service provider is:

  • eBusiness Solutions OÜ (registry code 16618432, VAT number EE102672239, trust and company service provider license number FIU000421, address: Tornimäe tn 7-169, 10145 Tallinn, Estonia) — provides legal address, contact person, company registration, accounting, consulting, and other services.

Client — a natural person using the legaladdressinestonia.com website or any services provided by legaladdressinestonia.com.

GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

Policy — this privacy policy.

Personal Data — any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. The list of personal data processed by legaladdressinestonia.com is set out in Section 3.

Processing — any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Controller — the entity which, alone or jointly with others, determines the purposes and means of the processing of personal data. The Controller of the Client’s personal data is eBusiness Solutions OÜ.

Processor — the entity processing personal data on behalf of the Controller. In the course of providing services, legaladdressinestonia.com may act as a Processor by processing personal data on behalf of the Client or the Client’s legal entity. This Policy does not govern legaladdressinestonia.com’s activities as a Processor.

Service — any services provided through the legaladdressinestonia.com website.

2. Scope of the Policy

This Policy applies to personal data processing operations where legaladdressinestonia.com acts as a Controller.

Any processing of personal data carried out on behalf of the Client or a legal entity controlled by the Client is governed by a separate Data Processing Agreement (DPA) concluded between legaladdressinestonia.com and such legal entity.

3. Personal Data Processed

legaladdressinestonia.com processes the following personal data of the Client:

3.1. Personal Details — first and last name, gender, personal identification code, date of birth, citizenship, postal address, email address, mobile phone number.

3.2. Identification Data — data obtained from a copy of an identity document: document number, issue date, expiration date, issuing authority, photograph.

3.3. Verification Data — data collected to conduct customer due diligence procedures in accordance with anti-money laundering legislation, including information on whether the Client is a politically exposed person (PEP) or subject to international financial sanctions.

3.4. Background Data — data collected and processed to screen the Client for adverse media and negative mentions in open sources.

3.5. Payment Data — data regarding payments made to legaladdressinestonia.com and state fees: bank account number (IBAN), account holder name, bank name, transaction details. If the Client pays for services by credit card or PayPal, card details are not stored by legaladdressinestonia.com and are not accessible to us.

3.6. Business Activity Data — in the course of service delivery, we collect and process information regarding the Client’s business field and company description.

3.7. Device Data — information about the device from which the Client uses legaladdressinestonia.com: device model, device name or identifier, IP address.

3.8. Customer Support Data — correspondence between legaladdressinestonia.com and the Client (inquiries via the website, web chat, email, or social media).

3.9. Usage Data — data regarding the Client’s interaction with the legaladdressinestonia.com website.

4. Sources of Personal Data

Most of the Client’s personal data processed by legaladdressinestonia.com is collected directly from the Client.

We may also collect the Client’s personal data from third-party sources, including:

  • international financial sanctions databases and sanction lists;
  • politically exposed persons (PEP) databases;
  • the Estonian e-Business Register and similar public registers;
  • open sources and media when conducting adverse media screening.

Some of these databases are publicly accessible, while others are not.

5. Purposes of Collection and Processing

Personal data collected by legaladdressinestonia.com is processed for purposes established by law or described in this Policy, including but not limited to:

5.1. Contractual Purpose — processing the Client’s personal data is necessary to enter into a service agreement and to provide services to the Client.

5.2. Legal Compliance Purpose — processing the Client’s personal data is necessary to fulfill obligations under applicable law: complying with anti-money laundering and counter-terrorist financing (AML/CFT) requirements, preventing fraud, enforcing international financial sanctions, and responding to lawful requests from public authorities with which legaladdressinestonia.com is required to cooperate.

5.3. Analytical Purpose — processing the Client’s personal data is necessary to manage, analyze, and improve our services and website.

5.4. Marketing Purpose — processing the Client’s personal data is necessary to send relevant promotional materials regarding our services and related third-party offers, provided that the Client has given explicit consent.

5.5. Personalization Purpose — processing the Client’s personal data is necessary to customize the services and content provided to the Client.

5.6. Communication Purpose — communicating with the Client for administrative purposes: customer support, addressing technical or legal matters related to services, and sending service-related notices and updates.

We will not use the Client’s personal data for any other purposes incompatible with those listed above unless authorized or required by law.

The Client is under no statutory obligation to provide us with the personal data described in this Policy. However, collecting certain personal data may be required by law or strictly necessary to deliver the services — specifically data needed for Client verification. Failure to provide such data may result in adverse consequences, such as our inability to comply with statutory duties, leading to a refusal to provide services. The Client may request clarification regarding the requirement to provide specific personal data and the potential consequences of withholding it.

6. Legal Bases for Processing

legaladdressinestonia.com relies on the following legal bases when processing the Client’s personal data:

6.1. Processing is necessary for the performance of a contract or to take steps at the request of the Client prior to entering into a contract (Art. 6(1)(b) GDPR) — processing for contractual purposes.

6.2. Processing is necessary for compliance with a legal obligation to which legaladdressinestonia.com is subject (Art. 6(1)(c) GDPR) — processing for compliance purposes, including obligations under the Estonian Money Laundering and Terrorist Financing Prevention Act (RahaPTS) and the International Sanctions Act.

6.3. Processing is necessary for the legitimate interests pursued by us (Art. 6(1)(f) GDPR) — processing for analytical and personalization purposes. The Client may request details regarding our balancing of interests test.

6.4. The Client has given consent to the processing of their personal data (Art. 6(1)(a) GDPR) — processing for marketing purposes and non-essential cookie technologies.

7. Automated Decision-Making

legaladdressinestonia.com delivers services to clients operating in specific business sectors. Not all business activities are supported by us.

legaladdressinestonia.com uses automated decision-making during the pre-contractual stage to determine whether a Client is eligible to use our services.

Automated decision-making refers to a decision made solely based on automated processing of the Client’s personal data — using algorithms or software code without human intervention.

Automated decision-making is necessary for entering into a contract with us and is used to accept or reject the Client’s application for service provision.

In accordance with Article 22(3) GDPR, the Client has the right to:

  • request human intervention by an employee of legaladdressinestonia.com;
  • express their point of view and submit additional explanations or supporting documents;
  • contest the automated decision.

To exercise these rights, the Client should contact us using the contact details in Section 16.

8. Disclosure of Personal Data to Third Parties

legaladdressinestonia.com may share the Client’s personal data with third parties, including:

8.1. public authorities and supervisory bodies (e.g., the Estonian e-Business Register, the Tax and Customs Board, the Financial Intelligence Unit), to which we are statutory obligated to disclose data;

8.2. hosting service providers operating the servers where legaladdressinestonia.com systems are hosted;

8.3. identity verification providers helping us verify the Client’s identity and obtain due diligence data;

8.4. communication service providers facilitating emails, phone calls, SMS messages, and other communications between legaladdressinestonia.com and the Client;

8.5. customer support software providers and Customer Relationship Management (CRM) platforms;

8.6. marketing service providers;

8.7. banking partners of legaladdressinestonia.com providing bank accounts or financial services to the Client or their legal entity;

8.8. affiliates of legaladdressinestonia.com, meaning any entity that directly or indirectly controls us, is controlled by us, or is under common control with our ultimate parent entity;

8.9. other contractors participating in the delivery of legaladdressinestonia.com services (accountants, auditors, lawyers, IT maintenance specialists).

legaladdressinestonia.com takes steps to ensure that all data recipients maintain strict confidentiality and security, processing data exclusively for service delivery in compliance with applicable law.

9. International Data Transfers

Certain data recipients may be located outside the European Economic Area (EEA), where data protection standards may differ and where no adequacy decision has been issued by the European Commission. In such countries, the security of personal data may not be guaranteed to the same level as within the EU.

When transferring personal data outside the EEA, legaladdressinestonia.com ensures appropriate safeguards are implemented, specifically:

  • transfers to countries recognized by the European Commission as providing an adequate level of data protection (including certified US entities under the EU–US Data Privacy Framework);
  • execution of Standard Contractual Clauses (SCCs) approved by the European Commission;
  • other lawful transfer mechanisms under Chapter V of the GDPR.

The Client may request a copy of the safeguards implemented by contacting us via Section 16.

10. Security Measures

legaladdressinestonia.com implements appropriate legal, organizational, and technical measures to protect personal data in compliance with data privacy regulations against unauthorized or accidental processing, disclosure, or destruction.

When transferring personal data to third parties, we apply the following safeguards:

10.1. legaladdressinestonia.com enters into a Data Processing Agreement (DPA) with the third party;

10.2. legaladdressinestonia.com ensures the third party undertakes to implement adequate technical and organizational security measures;

10.3. legaladdressinestonia.com verifies that (a) the recipient is located in an adequate jurisdiction or (b) processing is subject to appropriate safeguards under the GDPR.

10.4. In the event of a personal data breach posing a risk to the Client’s rights and freedoms, we will notify the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) within 72 hours and inform affected Clients without undue delay if the risk is high.

11. Accuracy and Data Retention Periods

11.1. legaladdressinestonia.com retains personal data for as long as required or permitted by law, but no longer than reasonably necessary to fulfill the collection purposes.

11.2. legaladdressinestonia.com takes reasonable steps to ensure that processed personal data is accurate, complete, and up to date.

11.3. Primary Retention Periods:

Data CategoryRetention PeriodLegal Basis
Client Identification and Due Diligence Data (KYC/AML)5 years following the termination of the business relationshipEstonian Money Laundering and Terrorist Financing Prevention Act (RahaPTS)
Accounting Records, Primary Documents, Payment Data7 years from the end of the financial yearEstonian Accounting Act (Raamatupidamise seadus)
Contracts and Related Business CorrespondenceUp to 3 years following contract termination (standard limitation period)Estonian General Part of the Civil Code Act
Consent-based Marketing DataUntil consent is withdrawnArt. 6(1)(a) GDPR
Website Usage Data and CookiesIn accordance with the Cookie Policy retention terms

12. Rights of the Client

Under the GDPR, the Client has the following rights regarding their personal data:

12.1. Right to Information — legaladdressinestonia.com provides all statutory information in this Policy, which is accessible on our site at all times.

12.2. Right of Access — the Client has the right to request a copy of their personal data processed by legaladdressinestonia.com.

12.3. Right to Rectification — the Client has the right to request the correction of inaccurate or incomplete personal data.

12.4. Right to Erasure (“Right to be Forgotten”) — the Client has the right to request the deletion of personal data when processing is no longer required by law or contract.

12.5. Right to Restriction of Processing — the Client has the right to request the suspension of data processing under specific circumstances.

12.6. Right to Data Portability — the Client has the right to receive their personal data in a structured, machine-readable format and transfer it to another controller.

12.7. Right to Object — the Client has the right to object to processing based on legitimate interests or direct marketing at any time.

12.8. Right to Withdraw Consent — the Client may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

12.9. Right to Lodge a Complaint — the Client has the right to submit a complaint directly to us or to the supervisory authority:

Estonian Data Protection Inspectorate

The Client may also lodge a complaint with the data protection authority in their EU/EEA member state of residence or place of work.

To exercise any of these rights, the Client must submit a written request to legaladdressinestonia.com (details in Section 16). We will respond to the request within one (1) month in accordance with Article 12(3) GDPR.

13. Cookies and Tracking Technologies

We use automatically collected information obtained via cookies and similar technologies.

Cookies are small text files transferred to the Client’s device browser to recognize the browser and remember preferences (e.g., language selection).

13.1. Cookie Types Used:

13.1.1. First-party cookies placed directly by legaladdressinestonia.com for site functionality and analytical insights;

13.1.2. Third-party cookies placed by external service providers (e.g., Google Analytics 4) to analyze traffic and site performance.

13.2. Cookie Purposes: authentication, security, user preference retention, personalized content/advertising, and site traffic analysis.

13.3. Cookie Consent. Non-essential cookies (analytical, marketing) are enabled only after obtaining explicit consent via the cookie banner. The Client can adjust preferences at any time via the site settings or browser controls.

13.4. Google Analytics & Advertising Technologies

legaladdressinestonia.com uses Google Analytics to measure site usage and traffic. Users can opt out of Google Analytics tracking via the Google Analytics Opt-out Browser Add-on or manage preferences via Google Ad Settings.

14. Commercial Communications

Clients receiving promotional emails can unsubscribe at any time using the link in the message or by contacting info@legaladdressinestonia.com. Processing opt-out requests may take up to five (5) business days. Transactional or administrative service notices will continue to be sent.

15. Amendments to this Policy

legaladdressinestonia.com reserves the right to amend this Policy unilaterally. Clients will be notified of material changes via email.

16. Contact Information

For questions or requests regarding this Privacy Policy or data protection, please contact us:

17. Acknowledgment

By accepting this Policy, the Client confirms that they have read, understood, and agreed to its terms.