Rytly Digital · Privacy Policy · Legal Notice

20 Jan 2025

Legal

Last Updated: January 20, 2025

1. Responsible Party / Data Controller

Rytly Digital OÜ
Registration Number: 14743621
Sepapaja tn 6
15551 Tallinn
Estonia

Contact:
Phone:
Email:

Responsible Person: Simon Neureuter
The controller determines the purposes and means of the processing of personal data (e.g., names, email addresses, contact details).

2. General Information on Data Processing

2.1 Scope of Personal Data Processing

We process personal data of our users only to the extent necessary to provide a functional website and our services. The processing of personal data occurs only with the user's consent or when processing is permitted by legal regulations.

2.2 Legal Basis for Processing Personal Data

When we obtain consent for the processing of personal data, Article 6(1)(a) GDPR serves as the legal basis.

For processing necessary for the performance of a contract, Article 6(1)(b) GDPR serves as the legal basis.

For processing necessary to comply with a legal obligation, Article 6(1)(c) GDPR serves as the legal basis.

For processing necessary to protect legitimate interests, Article 6(1)(f) GDPR serves as the legal basis.

2.3 Data Retention and Deletion

We store personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Unless specified otherwise in this privacy policy, we delete personal data when it is no longer needed.

General retention periods:

  • Contact form inquiries: Until request is fulfilled + 3 years (legal retention for business correspondence)
  • Server logs: 30 days
  • Contract data: Duration of contract + 10 years (Estonian accounting law)

3. Website Functionality

3.1 No Cookies

We do not use cookies on this website. We do not track visitors or use analytics cookies.

3.2 SSL/TLS Encryption

This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by "https://" in your browser's address bar and the lock icon.

3.3 Server Log Files

When you visit our website, our hosting provider automatically collects and stores the following information in server log files:

  • Browser type and version
  • Operating system used
  • Referrer URL (previously visited page)
  • Hostname of accessing computer
  • Date and time of server request
  • IP address (anonymized after 7 days)

Legal basis: Article 6(1)(f) GDPR (legitimate interest in ensuring system security and detecting abuse)

Retention period: 30 days, then automatically deleted

No merging with other data sources occurs. This data is not used to identify individual persons. We do not share this data with third parties.

4. Contact Form

4.1 Data Processing

When you use our contact form, we collect:

  • Name
  • Email address
  • Company name (optional)
  • Message content
  • Date and time of submission

Legal basis: Article 6(1)(a) GDPR (consent) or Article 6(1)(b) GDPR (pre-contractual measures)

Purpose: Processing your inquiry and responding to your request

Retention period: Until inquiry is resolved + 3 years for business correspondence, or until you request deletion

4.2 Your Rights

You may withdraw your consent at any time by sending an email to info@rytly.com. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.

5. Third-Party Services

5.1 Web Hosting

Our website is hosted by:

INFOMANIAK NETWORK SA

Head office address: Avenue de la Praille 26 1227 Carouge (GE), Switzerland
Data processing agreement: infomaniak.com/en/legal/general-data-protection-regulation

Data processed: All data mentioned in "Server Log Files"

Legal basis: Article 6(1)(f) GDPR (legitimate interest in reliable website hosting)

Data processing agreement: In place according to Article 28 GDPR

5.2 Email Service

We use INFOMANIAK NETWORK SA for business email communication.

Head office address: Avenue de la Praille 26 1227 Carouge (GE), Switzerland
Data processing agreement: infomaniak.com/en/legal/general-data-protection-regulation

Data processed: Email correspondence, sender/recipient information

Legal basis: Article 6(1)(b) GDPR (contract performance) and Article 6(1)(f) GDPR (legitimate interest)

6. International Data Transfers

Our hosting and email provider (Infomaniak Network SA) is based in Switzerland. Switzerland is recognized by the European Commission as providing an adequate level of data protection (Adequacy Decision 2000/518/EC, updated September 2023). For any other services that may involve data transfers outside the EEA, such transfers are based on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, or
  • Adequacy decisions by the European Commission

We ensure that adequate safeguards are in place for all international data transfers.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

7.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether personal data concerning you is being processed and, if so, to access that data.

7.2 Right to Rectification (Article 16 GDPR)

You have the right to obtain the rectification of inaccurate personal data.

7.3 Right to Erasure (Article 17 GDPR)

You have the right to obtain the erasure of personal data ("right to be forgotten") under certain circumstances.

7.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to obtain restriction of processing under certain circumstances.

7.5 Right to Data Portability (Article 20 GDPR)

You have the right to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

7.6 Right to Object (Article 21 GDPR)

You have the right to object to processing based on legitimate interests.

7.7 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

7.8 Automated Decision-Making

We do not use automated decision-making or profiling as defined in Article 22 GDPR.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39
10134 Tallinn
Estonia
Website: https://www.aki.ee/en
Email: info@aki.ee
Phone: +372 627 4135

9. Data Security

We use appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

  • SSL/TLS encryption for data transmission
  • Secure server infrastructure
  • Regular security updates
  • Access controls and authentication
  • Regular backups

10. Children's Privacy

Our services are not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us so we can delete such information.

11. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in our practices or legal requirements. The current version is always available on this page. Significant changes will be communicated on our website.

Last updated: January 20, 2025

12. Contact for Privacy Matters

For questions regarding the processing of your personal data or to exercise your rights, please contact:

Rytly Digital OÜ
Phone:
Email:

We will respond to your request within one month of receipt. This period may be extended by two further months where necessary, considering the complexity and number of requests.