Privacy Policy
This Privacy Policy describes how Bauhub as the controller (Bauhub OÜ, registry code 12979880, registered office Raekoja plats 10, 51004 Tartu, Estonia) processes personal data when the Services provided by Bauhub (hereinafter we or the Service Provider) are used.
All capitalised terms used in this document are regarded in accordance with their definition in the Terms of Use.
1. Personal data to be processed
We may process the following personal data when providing the Service:
• contact details such as name, email address, telephone number;
• work-related data, such as the details of the related company and workplace;
• details of payment transactions, such as bank details, credit card details and invoice details;
• log data and information received from cookies.
2. Purposes and legal bases for processing
2.1 Provision of the Service and enabling the use of the Service.
An email address and password must be submitted in order to use the Service and open the Account. We may request additional contact details from you, such as your name, phone number and details of the related company.
If you pay for the Service, the data to be processed may include credit card data, bank details and the invoice address.
We may use your contact details to provide customer support and assist you in using the Service. Also, your request may contain personal data if you contact us.
In the aforementioned situations, the legal basis for personal data processing is the entry into and performance of a contract.
2.2 Compliance with legal obligation
We may process your data if this is necessary for the performance of the obligations arising from law. Such processing may cover, for example, responding to queries from authorities and performance of accounting duties.
The performance of a legal obligation is the legal basis.
2.3 Marketing
We may use your email address and other personal data collected via the Service to send notices about the services we provide.
Your consent or our legitimate interest is the legal basis.
2.4 Improvement of the Service and convenience of use
We may process log data and information obtained from cookies to improve the service and ease of use.
Our legitimate interest is the legal basis.
2.5 Protection of rights
We may process your personal data to protect our rights (to identify, submit and defend legal claims).
Our legitimate interest is the legal basis.
3. Manners of collecting personal data
We collect your personal data in the following manners:
• you submit your personal data to us yourself;
• your personal data are transmitted to us by the Client’s representative or another User;
• your personal data are provided to us by a third party (e.g. if a third party payment service provider confirms whether your payment was successful or not);
• we have collected your personal data automatically (log data and information obtained from cookies).
4. Data retention
We will retain the collected personal data for as long as necessary for the achievement of the objectives described above.
• Personal data related to the account, such as your email address, name and phone number, are retained for as long as your account is active. Personal data are erased when the account is closed, unless such data are necessary for the purpose of legal obligations, resolution of disputes or prevention of fraud.
• Invoice data are retained for at least seven years as of their submission in accordance with the Estonian Accounting Act.
• Information on contractual transactions is retained for ten years.
5. Recipients of personal data
We only use carefully selected service providers (processors) for processing your personal data. Processors have access to personal data to the extent necessary for the provision of their services in accordance with the contract entered into with them.
We only issue your personal data to the authorities or third parties that have a legal basis for requesting them under the law (e.g. investigative bodies, bodies conducting extra-judicial proceedings or courts).
6. Transmission of personal data outside the EU.
We transmit your personal data outside the EU and retain them there only if we have a legal basis for this, including to data recipients, who are in a country where the protection of personal data is adequately ensured or who is subject to a measure that meets the EU requirements for the transmission of personal data outside the EU.
7. Safety
We apply technical and organisational security measures to protect your personal data, taking into account (i) the level of technology, (ii) the implementation costs, (iii) the nature, scope, context and objectives of processing, and (iv) the risks borne by you. Such security measures include, inter alia, encrypted storage and access control.
8. Your rights
You have all the rights of the data subject specified in the General Data Protection Regulation in respect of your personal data. You have the right to:
• request access to your personal data;
• receive a copy of your personal data;
• demand correction of inaccurate or incomplete personal data. You can correct and update your personal data on your account;
• demand erasure of personal data;
• demand restriction of personal data processing;
• demand transfer of personal data;
• object to the processing of personal data, which is based on legitimate interests and which is done for the purposes of direct marketing;
• withdraw the consent granted for personal data processing if your personal data are processed on the basis of consent.
You have the right to lodge a complaint with the Data Protection Inspectorate (www.aki.ee) if you find that your rights have been violated by personal data processing.
9. Amendment of Privacy Policy
We may update this Privacy Policy at any time. The amended Privacy Policy is published on the website www.bauhub.ee.
10. Contact information
If you have any questions about the processing of your personal data or if you wish to exercise your rights as a data subject, please contact us at info@bauhub.ee.
The privacy policy is effective as of 24th of March 2022.