Last updated: July 24, 2026
eBusiness Solutions OÜ processes personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Estonian Personal Data Protection Act.
This page explains how the seven principles of Article 5 of the GDPR are applied in the daily operations of a licensed corporate service provider, what rights you possess as a data subject, and how to exercise them. It also explicitly clarifies a question clients ask most frequently: why certain data cannot be erased upon request—even if explicitly demanded—and on what statutory grounds.
Specific processing activities (which exact data categories are collected, from whom, for what purpose, and to whom they are transferred) are detailed in our [Privacy Policy]. This document explains the core principles and serves to complement, rather than replace, that policy.
| Parameter | Value |
|---|---|
| Legal Name | eBusiness Solutions OÜ |
| Registry Code | 16618432 |
| VAT Number (KMKR) | EE102672239 |
| TCSP Licence | FIU000421 |
| Registered Address | Tornimäe tn 7-169, 10145 Tallinn, Estonia |
| Data Protection Supervisory Authority | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) |
Key distinction in our operations:
In certain processes, we act as a Data Controller (when we determine the purposes of processing: entering into a contract with you, conducting KYC checks, marketing). In other processes, we act as a Data Processor (when we maintain bookkeeping for your company and process personal data of your employees and counterparties on your instructions). In the second scenario, you determine the processing purposes, and our relationship is governed by a separate Data Processing Agreement (DPA). This document outlines our role exclusively as a Data Controller.
We process data only when at least one legal basis under Article 6 GDPR applies. In our operations, four primary legal bases are utilized:
| Legal Basis | Applicable Circumstance |
|---|---|
| Performance of a Contract (Art. 6(1)(b)) | Service delivery: registered office address, contact person, company registration, accounting. |
| Legal Obligation (Art. 6(1)(c)) | Client identification and verification under RahaPTS, sanctions screening, regulatory reporting. |
| Legitimate Interests (Art. 6(1)(f)) | System security, website analytics, fraud prevention. |
| Consent (Art. 6(1)(a)) | Newsletters, marketing communications, non-essential cookies. |
This breakdown is not a mere technicality: your rights directly depend on the legal basis invoked. Data processed under a Legal Obligation cannot be erased upon your demand, whereas data processed based on Consent can be withdrawn at any time.
Transparency for us means specific, clear disclosures rather than vague statements. We state precisely which data categories we collect, on what basis, and for what retention periods, providing advance notice if additional documents are needed to deliver a service.
Data collected for one purpose is not reused for another incompatible purpose.
Practical industry example: Documents provided to pass KYC compliance checks (passport copies, proof of source of funds, ownership diagrams) are used strictly for compliance and disclosure to supervisory authorities upon their lawful request. They are never entered into marketing databases, used to formulate commercial offers, or shared with third parties for advertising purposes.
If a new processing purpose arises, we will either obtain explicit consent or establish another lawful basis—notifying you prior to initiating processing.
We request only the volume of data strictly necessary for a specific service, proportionate to the client’s assigned risk profile.
In practice, requested documentation varies: for a dormant company’s zero annual report, requirements are minimal; for a client operating with crypto-assets or complex corporate layers, documentation requirements are significantly broader as mandated by the risk-based approach under RahaPTS. We do not collect documents “just in case” and justify every request with a specific legal or operational necessity.
If it is unclear why a specific document is requested, you have the right to request—and receive—a formal explanation.
Inaccurate data in our field carries direct consequences: an error in a board member’s personal data submitted to the Commercial Register leads to application rejection, while an outdated address risks missing statutory notices.
Therefore, we periodically request confirmation of data accuracy (also mandated by ongoing AML monitoring rules), promptly apply updates upon your notification, and verify details against public registers where appropriate.
Your cooperation is essential: please inform us immediately of changes to contact details, board composition, ownership structures, or business operations. This ensures both service quality and regulatory compliance.
A specific retention period is assigned to each data category, after which data is securely erased or anonymized:
| Category | Retention Period | Statutory / Legal Basis |
|---|---|---|
| KYC/AML Records & Client Screening Data | 5 years after termination of business relationship | Money Laundering and Terrorist Financing Prevention Act (RahaPTS) |
| Accounting Files & Primary Vouchers | 7 years from the end of the financial year | Estonian Accounting Act (Raamatupidamise seadus) |
| Contracts & Business Correspondence | 3 years after contract termination | General statutory limitation period under civil law |
| Consent-based Data (Marketing) | Until consent is revoked | Art. 6(1)(a) GDPR |
| Inquiries Not Leading to Contract | Generally up to 12 months | Legitimate interest |
Retention periods may only be extended in explicitly defined statutory cases—such as by order of a supervisory authority or during active litigation.
Technical Measures: Encryption of transmission channels and storage of sensitive documents, access rights management, automated backups, infrastructure security, and patch monitoring.
Organizational Measures: Access to client data is restricted exclusively to personnel requiring it for service execution; all employees and contractors operate under strict Non-Disclosure Agreements (NDAs); personnel undergo routine data protection training.
Incident Response: In the event of a personal data breach, we follow internal incident protocols: mitigating the cause, assessing risks, notifying the Data Protection Inspectorate within 72 hours (Art. 33 GDPR), and informing affected data subjects if the risk to their rights is high (Art. 34 GDPR).
The principle under Article 5(2) GDPR requires not only complying with rules, but being able to demonstrate compliance. To ensure accountability, we maintain:
A formal Record of Processing Activities (Art. 30 GDPR);
Internal Data Protection and AML/CFT Procedure Manuals;
Data Processing Agreements (DPAs) with sub-processors having data access;
Data Protection Impact Assessments (DPIAs) for high-risk processing operations (Art. 35 GDPR);
Periodic internal audits of processing workflows and retention schedules.
This is the most frequent practical question raised by corporate service clients.
The right to erasure is not absolute. Article 17(3)(b) GDPR explicitly provides that the right to erasure does not apply where processing is necessary for compliance with a legal obligation to which the controller is subject.
Documents collected during Customer Due Diligence (CDD) procedures must be retained for 5 years following the termination of a business relationship under RahaPTS. This means:
Requests for erasure of such compliance records will be refused—citing the statutory legal obligation;
Instead of erasure, restriction of processing applies: data is stored securely but cannot be processed for any operational purpose other than legal compliance;
Upon expiry of the statutory 5-year retention period, data is automatically deleted without requiring a separate request.
Similarly, the tipping-off prohibition under AML laws overrides GDPR disclosure obligations: if a Suspicious Activity Report (SAR) regarding a transaction is submitted to the Financial Intelligence Unit, the law strictly prohibits us from informing the client. In such scenarios, the data subject’s right to information under GDPR is limited by direct statutory provisions.
Subject to the conditions and exceptions established under the GDPR, you possess the following rights:
| Right | Article | Description |
|---|---|---|
| Right to be Informed | 13–14 | To know what data is processed, for what purposes, and on what legal grounds. |
| Right of Access | 15 | To receive confirmation of processing and obtain a copy of your personal data. |
| Right to Rectification | 16 | To correct inaccurate or complete incomplete personal data. |
| Right to Erasure | 17 | To request data erasure in the absence of a legal basis for retention (see Section 3). |
| Right to Restriction | 18 | To temporarily pause data processing under specific legal conditions. |
| Right to Portability | 20 | To receive provided data in a structured, machine-readable format or transfer it to another controller. |
| Right to Object | 21 | To object to processing based on legitimate interests; object to direct marketing unconditionally at any time. |
| Automated Decisions | 22 | To request human review, express your point of view, and contest automated outcomes. |
| Withdrawal of Consent | 7(3) | To revoke consent at any time without affecting the lawfulness of prior processing. |
| Right to Lodge Complaint | 77 | To submit a complaint to a supervisory authority (see Section 6). |
To exercise any of your rights, submit a written request using the contact details in Section 7.
Identity Verification: Before disclosing data, we must verify that the request originates from you to prevent unauthorized data exposure. For active clients, an email sent from a registered address or a qualified electronic signature is sufficient.
Response Timeline: Within 1 month of receipt (Art. 12(3) GDPR). For complex or high-volume requests, this period may be extended by an additional two months with prior notification explaining the delay.
Cost: Requests are handled free of charge, unless requests are manifestly unfounded, excessive, or repetitive.
Refusals: If a request is declined, we state the precise statutory legal basis and outline appeal options, including your right to lodge a complaint with supervisory authorities.
If you believe your privacy rights have been infringed, we encourage you to contact us first—most matters can be resolved directly and promptly. You also retain the right to lodge a complaint with the supervisory authority:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Address: Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee
Website: www.aki.ee
If you reside or work in another EU/EEA member state, you may lodge a complaint with your local national data protection authority.
Company Name: eBusiness Solutions OÜ
Registry Code: 16618432
TCSP Licence: FIU000421
Email: info@legaladdressinestonia.com
Phone: +372 5691 0000
Address: Tornimäe tn 7-169, 10145 Tallinn, Estonia
Website: legaladdressinestonia.com (also legaladdress.ee)
This document is explanatory in nature and complements, but does not replace:
[Privacy Policy] — details specific data processing operations;
[AML/CFT Policy] — details Customer Due Diligence measures;
[Cookie Policy] — details tracking technologies and cookie usage.
In the event of any conflict between this document and the [Privacy Policy], the terms of the Privacy Policy shall prevail.
We update this page periodically to reflect changes in legislation, regulatory guidance, or internal compliance protocols. The active version is published on this page displaying the latest revision date.