Privacy Policy

Last updated: 7/27/2026

At Gaobaltech OÜ, we take the protection of your personal data seriously. This policy explains what information we process, for what purposes, the legal bases we rely on, and what rights you have under the General Data Protection Regulation (GDPR) and Estonian data protection law.

1. Data Controller

Gaobaltech OÜ

  • Registry code: 17289890
  • VAT number: EE102885068
  • Registered address: Sepapaja tn 6, 15551 Tallinn, Estonia
  • Email: info@gaobaltech.com

In general, Gaobaltech OÜ acts as the data controller for the data described in this policy. In projects we develop for our clients, we may process personal data on their behalf, acting as a data processor. That processing is governed by the Data Processing Agreement (DPA) signed with each client and not by this policy.

2. Data We Process and Purposes

We collect only the data necessary for each purpose and do not collect information unnecessarily:

Purpose What it involves Data processed
Provision of services Preparing quotations, delivering projects in phases, invoicing, and communicating during the engagement. Name, email address, telephone number, and billing details.
Handling enquiries Responding to requests submitted through a form or by email. Name, email address, telephone number, and message content.
Referral programme Managing referrals, verifying the referral, and processing bonus payments. Referrer’s billing details and the referred person’s contact details.
Marketing communications Sending news or information about our services, only with your consent. Name and email address.

We obtain most data directly from you. For the referral programme, we may receive your contact details from the person who recommends you, who confirms that they have your permission to provide them.

In general, Gaobaltech OÜ acts as the data controller for the data described in this policy. In projects we develop for our clients, we may process personal data on their behalf, acting as a data processor. That processing is governed by the Data Processing Agreement (DPA) signed with each client and not by this policy.

We process your data on one or more of the following legal bases under the GDPR:

  • Performance of a contract (Article 6(1)(b)): where processing is necessary to provide our services or manage the relationship.
  • Compliance with a legal obligation (Article 6(1)(c)): for example, accounting or tax obligations.
  • Legitimate interests (Article 6(1)(f)): where we have a legitimate interest that does not override your rights and freedoms.
  • Consent (Article 6(1)(a)): for example, for marketing communications, which you may withdraw at any time.

4. Data Retention

We retain your data for as long as necessary for the purpose for which it was collected and, in a contractual relationship, for the duration of that relationship. Afterwards, the data remains restricted for the period during which legal, accounting, or tax liabilities may arise. In Estonia, accounting records are retained for up to seven years. Once the applicable retention period has expired, the data is securely deleted.

5. Recipients and International Transfers

We do not disclose or sell your data to third parties for commercial purposes. Data is accessed only by service providers that support us with hosting, email, invoicing, analytics, or development tools. These providers act as processors in accordance with our instructions and with the contractual safeguards required by the GDPR. We may also disclose data to competent authorities where legally required.

If a provider is located outside the European Economic Area (EEA), we ensure that the transfer uses GDPR safeguards: an adequacy decision, such as the EU–US Data Privacy Framework, or, where no adequacy decision applies, Standard Contractual Clauses together with any additional protective measures required.

6. Use of Artificial Intelligence and Automated Decision-Making

To provide and improve our services, we may use artificial intelligence tools, including large language models (LLMs), which process text and other information. Where this processing involves external providers, it is carried out with the safeguards described in this policy and with personal data limited to what is strictly necessary.

We do not make decisions producing legal effects or similarly significant effects about you based solely on automated processing without human involvement. If we ever intended to do so, we would inform you beforehand and respect your right to request human intervention or object to the decision.

7. Your Rights

You may exercise the rights of access, rectification, erasure, objection, restriction of processing, and data portability free of charge at any time. You may also withdraw your consent by contacting us at info@gaobaltech.com. If you believe that we have not processed your data correctly, you may lodge a complaint with the Estonian supervisory authority: Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia (info@aki.ee).

8. Information Security

We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, or alteration, taking into account the nature of the information processed. When sharing data with providers, we enter into data processing agreements with them and ensure that they provide equivalent safeguards.

9. Changes to This Policy

We may update this policy to reflect regulatory changes or new services. We will always publish the current version on this page together with its date and will notify you when changes are material.

10. Contact

If you have any questions about this policy or how we process your data, please contact us at info@gaobaltech.com.

Contact form

The form is ready when you are.

Load the Microsoft form and tell us what you need.

Prefer email? Write to us directly.

Email us

Privacy preferences

We use essential technologies and, with your permission, functional services such as the contact form.