Privacy Policy
Last updated 1 June 2026
This policy explains what Startegys Digital OÜ does with personal data when you use startegys.com or engage us as a client. We are the controller for the processing described here.
This page was written for a demonstration site and has not been reviewed by a data protection lawyer. Have counsel check it against your actual processing before publishing.
Who we are
Startegys Digital OÜ, registration number 16482203, Pärnu mnt 141, 11314 Tallinn, Estonia. Privacy enquiries: privacy@startegys.com.
We have not appointed a Data Protection Officer. We are a six-person company that does not carry out large-scale monitoring or process special category data, so the GDPR does not require one.
What we collect and why
When you use the contact form
We collect your name, email address, and optionally your company and budget range, plus whatever you write in the message. We also record the IP address and browser user agent of the submission.
- Purpose: to answer you, and to prevent abuse of the form.
- Legal basis: legitimate interest (Article 6(1)(f)) in responding to a business enquiry you initiated and in keeping the form usable.
- Retention: 24 months from your last contact, then deleted. The IP address is kept for 30 days for rate limiting.
When you email us
Mail sent to an @startegys.com address is received by our provider, stored in our systems and readable by our team. It contains whatever you chose to put in it.
- Purpose: to correspond with you.
- Legal basis: legitimate interest in business correspondence, or performance of a contract if you are a client.
- Retention: 36 months, or the life of the engagement plus 24 months for client correspondence.
Please do not send us special category data — health, biometrics, political or religious views — or anyone’s payment card details. We have no need for any of it.
When you visit the site
Our hosting provider records standard server logs including IP address, requested URL and timestamp, for security and reliability. These are retained for 30 days.
We do not run advertising pixels, we do not build visitor profiles, and we do not sell or share data with data brokers. See the Cookie Policy for what we do and do not set.
When you are our client
We hold business contact details for the people we work with, and we process data inside your systems on your instructions. For that processing you are the controller and we are your processor, governed by a data processing agreement rather than this policy.
Who else touches it
We use a small number of processors. Each is bound by a data processing agreement and none of them may use your data for their own purposes.
- Resend — sending and receiving email. Processes sender and recipient addresses and message content.
- Vercel — website hosting. Processes server logs.
- Supabase — database hosting for contact submissions and mail. Data resides in the EU.
- Google Workspace — internal documents and calendars.
Where a processor transfers data outside the EEA, that transfer relies on the European Commission’s Standard Contractual Clauses or an adequacy decision. We will name the specific mechanism for any processor on request.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or send it to someone else in a portable format. You can object to processing based on legitimate interest, and we will stop unless we have compelling grounds not to.
Write to privacy@startegys.com. We answer within 30 days and we do not charge for it. If you are not satisfied, you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live.
Security
Data is encrypted in transit and at rest. Access to the mail database is restricted to a named allowlist and authenticated by single-use sign-in links rather than shared passwords. The application connects to the database as a role that can read and write three tables and nothing else — there is no all-powerful key in the runtime.
No system is perfectly secure. If a breach affects your rights we will tell the regulator within 72 hours and tell you without undue delay.
Automated decisions
We do not make decisions about you by automated means and we do not profile you.
Children
This is a business-to-business site and is not directed at children. We do not knowingly collect data about anyone under 16.
Changes
When we change this policy we update the date at the top. If a change materially affects your rights we will contact you directly rather than rely on you noticing.