01Who we are
This website is operated by [NUUX legal entity name, e.g. NUUX OÜ], a company registered in the Estonian Commercial Register under registry code [registry code], with its registered address at [registered address], Tallinn, Estonia ("NUUX", "we", "us").
NUUX is the controller of the personal data described in this policy within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"). You can contact us about any privacy matter at [privacy@nuux domain].
02Scope
This policy covers personal data processed through the NUUX company website, including when you browse it, request a demo or otherwise contact us.
03Data we collect
Data you give us
- Demo requests and enquiries: your name, work email address, organization, role, the products you are interested in and anything you write in your message.
- Correspondence: the content of emails and calls with us, including scheduling details for a demo.
Data collected automatically
- Technical data: your IP address, browser type and version, device type, operating system, referring page, pages viewed and the date and time of your visit. Our hosting provider records this in server logs to deliver the site and keep it secure.
We do not ask for, and ask you not to send us, special categories of personal data under Article 9 GDPR, such as health information.
04Purposes and legal bases
We process personal data only where the GDPR gives us a legal basis to do so.
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Responding to a demo request or enquiry, and arranging and holding the demo | Contact and enquiry data, correspondence | Steps taken at your request before entering into a contract, Art. 6(1)(b); or our legitimate interest in answering business enquiries, Art. 6(1)(f) |
| Following up after a demo about the product you asked about | Contact and enquiry data | Legitimate interest in developing business relationships, Art. 6(1)(f). You can object at any time. |
| Sending marketing emails or newsletters | Name, email address | Your consent, Art. 6(1)(a), or where permitted for existing customers, our legitimate interest, Art. 6(1)(f). You can withdraw or opt out at any time. |
| Operating the website securely, preventing abuse and fixing errors | Technical data | Legitimate interest in a secure, working website, Art. 6(1)(f) |
| Keeping business and accounting records, and responding to lawful requests | Correspondence, contract data | Compliance with legal obligations, Art. 6(1)(c), including the Estonian Accounting Act |
| Establishing, exercising or defending legal claims | Any relevant data | Legitimate interest, Art. 6(1)(f) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can ask us for details of that assessment. We do not use your data for automated decision-making, including profiling, that produces legal or similarly significant effects for you.
05Cookies and similar technologies
This website does not set advertising or analytics cookies, and it does not track you across other websites. It uses only what is strictly necessary to display the site.
To display our typefaces, your browser loads fonts from Google Fonts, a service provided by Google Ireland Limited. This request shares your IP address with Google. If we add analytics or any other non-essential cookies in future, we will ask for your consent first, as required by the ePrivacy Directive and the Estonian Electronic Communications Act, and we will update this section.
06Who receives your data
We do not sell personal data. We share it only with the following categories of recipients, and only as far as needed:
- Service providers acting as our processors, such as website hosting, email, video conferencing, scheduling and customer relationship management providers. They process data only on our instructions under contracts that meet Article 28 GDPR. A current list is available on request.
- Professional advisers, such as accountants, auditors and lawyers, who are bound by confidentiality.
- Public authorities, courts and law enforcement, where we are legally required to disclose data.
- A buyer or successor, if NUUX is involved in a merger, acquisition or sale of assets, subject to equivalent protection of your data.
07Transfers outside the EEA
We aim to store and process personal data within the European Economic Area. Where a service provider processes data outside the EEA, we ensure an appropriate safeguard under Chapter V GDPR is in place. This may be an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for certified US companies, or the Commission's Standard Contractual Clauses together with any supplementary measures needed. You can ask us for a copy of the relevant safeguard.
08How long we keep data
- Demo requests and enquiries that do not lead to a contract: up to 24 months after our last contact, then deleted or anonymized.
- Customer and contract records: for the duration of the relationship and up to the end of the limitation period for claims under the Estonian Law of Obligations Act and General Part of the Civil Code Act.
- Accounting source documents: 7 years, as required by the Estonian Accounting Act.
- Server logs: no longer than 90 days, unless needed to investigate a security incident.
- Marketing data: until you withdraw consent or opt out.
09Your rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy of it (Art. 15)
- Rectify inaccurate or incomplete data (Art. 16)
- Erase your data in certain circumstances (Art. 17)
- Restrict how we process your data (Art. 18)
- Data portability, receiving data you gave us in a structured, machine-readable format (Art. 20)
- Object to processing based on legitimate interests, and to direct marketing at any time (Art. 21)
- Withdraw consent at any time, without affecting processing that took place before withdrawal (Art. 7(3))
To exercise any of these rights, email [privacy@nuux domain]. We will reply within one month, which may be extended by two further months for complex requests, in which case we will tell you. We may need to verify your identity before acting on a request. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
10Security
We use appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls limited to staff who need the data, and careful selection of service providers. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you and the supervisory authority as required by Articles 33 and 34 GDPR.
11Children
This website is intended for organizations, schools and adults. We do not knowingly collect personal data from children through it. In Estonia, a child may consent to information society services from the age of 13. If you believe a child has sent us personal data, contact us and we will delete it. The way IO Examiner handles student data is explained in its own privacy notice.
12Changes to this policy
We may update this policy to reflect changes in our practices or the law. The date at the top shows when it was last revised. If we make material changes, we will highlight them on this website.
13Contact and complaints
Questions or requests about this policy: [privacy@nuux domain], or by post to [NUUX legal entity name], [registered address], Tallinn, Estonia.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live, work or where an alleged infringement took place. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, www.aki.ee. We would appreciate the chance to address your concern first.