Privacy policy
Last updated 24 July 2026
Who processes your data
The controller of personal data is Minoseg Design OÜ, registry code 12521520, email tugi@aihankejalgija.ee.
You can contact us on data protection matters using the same details. We reply within thirty (30) days at the latest.
What data we collect
| Data | Why | Source |
|---|---|---|
| Company name, registry code, VAT number, address, field of activity | Providing the service, issuing invoices | Business register open data and the client's own input |
| Contact person name, email, phone | Sending briefings, communication, account management | The client |
| Monitoring profile: categories, keywords, limits, described conditions | Finding and selecting suitable tenders | The client |
| Invoices, payment status and subscription history | Accounting and statutory records | Our system |
| Chat messages and any email left there | Answering the question | The client |
| Technical log of logins and service use, IP address | Security and abuse prevention | Automatically |
We do not collect special categories of personal data and we do not make automated decisions producing legal effects concerning a person.
Legal basis
- Performance of a contract is the basis for processing contact details, the monitoring profile and invoices. Without them the service cannot be provided.
- Legal obligation is the basis for retaining accounting records.
- Legitimate interest is the basis for security logs and service development. Our interest is keeping the service working and secure, and it does not override the client's rights.
- Consent is the basis only where the client has separately subscribed to marketing messages. Consent can be withdrawn at any time.
How long we keep data
- Account data and monitoring profile: for the duration of the service and twelve (12) months after the subscription ends, so the account can easily be restored if wanted.
- Accounting source documents, including invoices: seven (7) years, as required by the Estonian Accounting Act.
- Chat messages: twelve (12) months.
- Security and technical logs: six (6) months.
Once the period expires the data is deleted or irreversibly anonymised.
Who we share data with
We do not sell or rent client data to anyone. Data is shared only with the processors whose help is needed to provide the service:
- Web hosting and email delivery, with data located in the European Union.
- Accounting service, for invoices and payments.
- An AI service provider, for assessing the substance of tenders. The text of the tender notice and the conditions of the monitoring profile are sent there, not the client's contact details.
Data may also be disclosed to a law enforcement authority where there is a statutory obligation to do so.
Rights of the client
You have the right to:
- find out what data we process about you and receive a copy of it;
- have inaccurate data corrected, which in most cases you can do yourself in the client area;
- have data erased where there is no statutory basis for keeping it;
- request restriction of processing or object to processing;
- receive your data in a machine readable format and have it transferred;
- withdraw consent where processing is based on consent.
Requests can be sent to tugi@aihankejalgija.ee. If you believe we have infringed your rights, you may contact the Estonian Data Protection Inspectorate (info@aki.ee, aki.ee).
Cookies
Necessary cookies are the ones without which the site does not work: the login session and the security token on forms. These are always used and they expire when the login session ends, or after two (2) weeks at the latest.
We also use Google Analytics to see which pages actually help visitors. The statistics cookie is stored only after you have given consent on your first visit. Until you choose, or if you choose "Only necessary", no statistics are collected and no analytics cookie is stored.
You can change your choice at any time by clearing the stored data for this site in your browser, after which we ask again. We use no advertising cookies and share no data with advertising networks.
Security
The connection to the site is encrypted (HTTPS). Passwords are stored hashed, never in readable form. Access to client data is limited to those who need it to provide the service. Backups are made daily and kept in the European Union.
Should a data breach occur that is likely to risk clients' rights, we notify the Data Protection Inspectorate upon discovery and the affected clients without delay.
Changes
If we make material changes to this policy we give at least thirty (30) days notice by email. Minor clarifications take effect on publication, and the date of the last change is always shown at the top of the page.