coreIT logo
  • Home
  • About
  • Services
    • IT support and maintenance
    • IT solution development
    • Server services
    • IT equipment repair
    • Security systems
    • Video surveillance systems
    • Website development
  • FAQ
  • Articles
  • Contact
🇪🇪 Eesti 🇷🇺 Русский 🇬🇧 English 🇫🇮 Suomi 🇺🇦 Українська 🇱🇻 Latviešu 🇱🇹 Lietuvių
ETEesti RUРусский ENEnglish FISuomi UAУкраїнська LVLatviešu LTLietuvių
Contact us
Home › Privacy and Data Processing Terms

Privacy and Data Processing Terms

This document explains how ELYNX Eesti OÜ, operating under the coreIT brand, processes personal data of website visitors, inquiry senders, client contacts and other related persons in accordance with the GDPR and applicable Estonian law.

1. Controller

The controller of personal data collected through the website coreit.ee is ELYNX Eesti OÜ, registry code 11676054, VAT number EE101301792, address Roopa tn 2, Tallinn, 10136, e-mail info@coreit.ee, phone +372 55 600 066.

2. How we come into contact with personal data

coreIT processes personal data in different situations and roles. In some cases we act as the controller, for example when a person sends us an inquiry through the contact form or by e-mail. In other cases we may act as a processor on behalf of a client if the client uses our IT services and their data is located in a technical environment maintained by us.

3. Data collected as controller

As a controller, we mainly collect data that a person provides to us directly. This may include name, e-mail address, phone number, company name, service interest, message content and any other information knowingly submitted by the user. We may also receive technical data related to website use, such as IP address, browser type, device type, cookie preferences and usage statistics.

If we interact with prospective clients, existing clients, representatives of partners or other natural persons, we process their data only to the extent necessary for communication, preparing an offer, preparing or performing a contract, delivering a service or protecting our legitimate interests.

4. Data processed on behalf of clients

If a client uses our IT support, server services, development or other technical services, personal data in the client’s systems or infrastructure may remain under the client’s control and the client is the controller of such data. In that case coreIT acts as a processor and processes the data only under the agreement with the client, the client’s instructions and to the extent necessary for providing the service.

This means we do not use such data for our own purposes and do not process it outside the scope of the agreement. The exact content of such data may be unknown to us because it may be located in files, databases, e-mails or other client systems.

5. Purposes and legal bases for processing

We process personal data mainly to respond to inquiries, prepare service delivery, conclude and perform contracts, manage client communication, handle billing, ensure the security of the website and technical solutions, and comply with legal obligations. The legal basis for processing may be pre-contractual steps, performance of a contract, legitimate interest, legal obligation or user consent.

6. Contact form and other voluntary communication

If a person fills in the contact form on the website, we store the submitted data and use it only for communication, identifying the need, providing a response and, where necessary, preparing an offer. Processing of data submitted via the contact form is usually based on pre-contractual steps or on an inquiry initiated by the user.

If a user voluntarily provides additional information, such as a description of an IT problem, the state of their systems or the requested service, such data is used only to handle that request unless the person has separately agreed to another use.

7. Cookies and other technologies

The website may use both strictly necessary and non-essential cookies. Strictly necessary cookies are required for the basic operation of the website, security and forms. Non-essential cookies, including analytics cookies, are used only if the user has given consent.

A cookie is a small text file stored on the user’s device to remember preferences, improve user experience and collect more anonymised statistical information. Users can manage cookie settings through their browser, but blocking some cookies may affect the proper functioning of the website.

8. Google Analytics

The website may use Google Analytics to evaluate traffic, understand how visitors use the website, and improve content and user experience. Google Analytics may process, for example, a shortened IP address, visited page data, device data and visit statistics.

Google Analytics must not be activated before the user has given the relevant consent for analytics cookies. If the user does not give consent or later withdraws it, analytics cookies must not be loaded and analytics tracking must be stopped.

9. Data sharing and engaged processors

coreIT does not disclose personal data to third parties without a legal basis. Where necessary, we may use partners and service providers for hosting, development, maintenance, e-mail, security or analytics. Such parties are subject to confidentiality and security obligations and may process data only to the extent necessary for providing the service.

Data may also be disclosed where required by law or where necessary to protect our rights, prevent fraud or resolve security incidents.

10. Transfers outside the EEA

If any service provider used by us processes data outside the European Economic Area, we ensure appropriate safeguards, such as the European Commission’s standard contractual clauses or another lawful transfer mechanism. Such transfers take place only to the extent necessary for providing the service or operating the website.

11. Access to data and security measures

Access to personal data is limited to those employees and service providers who need it for their job duties. We apply reasonable technical and organisational measures to protect data against unauthorised access, alteration, disclosure, destruction or other unlawful processing.

Depending on the risk, we may use access restrictions, logging, backups, system updates, security monitoring and other appropriate safeguards.

12. Accuracy of data

We strive to ensure that processed data is accurate, up to date and relevant. If a person believes that data processed about them is inaccurate or incomplete, they have the right to request correction or completion.

13. Retention periods

We retain personal data only for as long as necessary to fulfil the purpose of processing or comply with legal obligations. For example, inquiry and correspondence data may be retained for a reasonable period to ensure service continuity, answer follow-up questions and protect our rights in the event of a dispute.

Data related to contracts, billing or accounting is retained for as long as required by law. Full deletion of data from backups may not happen immediately, but within the normal technical deletion cycle.

14. Rights of the data subject

The data subject has the right to receive information about the processing of their personal data, request access to it, request correction of inaccurate data, request deletion in certain cases, request restriction of processing or object to processing. If processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

Where applicable, the data subject also has the right to data portability in a machine-readable format to the extent provided by law.

15. Deletion of data

If the purpose of processing has ended and there is no legal basis for continued retention, we delete or anonymise the data. In some cases, immediate complete deletion is not technically possible, for example in backups or logs. In such situations we restrict the use of the data until its normal deletion cycle.

16. Security incidents

If a personal data breach occurs that may create a risk to the rights and freedoms of data subjects, we act in accordance with applicable law, assess the impact, take measures to mitigate the consequences and, where required, notify the competent supervisory authority and affected persons.

17. Changes to these terms

coreIT may update these terms from time to time if laws, services, the technical structure of the website or the organisation of data processing change. The updated version will be published on this page and takes effect upon publication unless stated otherwise.

18. Complaints and contact

If you have questions about the processing of personal data or wish to exercise your rights, please contact us at info@coreit.ee. If you believe your rights have been violated, you also have the right to contact the Data Protection Inspectorate or a court.

coreIT footer logo

Professional IT services and support for businesses in Estonia and beyond.

Services
  • IT support and maintenance
  • IT solution development
  • Server services
  • IT equipment repair
  • Security systems
  • Video surveillance systems
  • Website development
Company
  • About
  • Articles
  • FAQ
  • Contact
Contact
  • ELYNX Eesti OÜ
  • Reg. nr.: 11676054
  • KMKR: EE101301792
  • Roopa tn 2, Tallinn, 10136
  • +372 55 600 066
  • info@coreit.ee

© 2024 coreIT IT Solutions. All rights reserved.

Privacy and Data Processing Terms