Privacy Policy

Effective Date: [Insert Date]
Last Updated:[Insert Date]

This privacy policy (“Policy”) describes how Bestia Tech collects and processes Personal Information about you and the privacy rights you have.

Where applicable, this Policy shall be considered a “privacy notice” or “privacy statement” under the requirements of the applicable Data Protection Laws, containing all the information Bestia Tech must provide you with before processing your Personal Information.

DEFINITIONS

Any references to the capitalized definitions in this Policy have the following meanings:

• Administrator is the authorized representative of the Customer who manages website development projects and services.

• Bestia Tech, we, or us is defined as [Insert Company Legal Name], an Estonian company registered in Estonia, with a registered office address at [Insert Complete Estonian Address].

• Content is defined as any content you voluntarily provide, submit, upload, publish, grant us access to, or otherwise make available to Bestia Tech or the Services, which may include Personal Information.

• Customer is defined as an individual or legal entity that intends to use or uses our Services.

• Controller is defined as an entity that determines the purposes and means of Personal Information processing.

• Data Protection Laws are defined as data protection legislation, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR), the Personal Data Protection Act (Estonia), the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act of 2018 (CCPA), the California Privacy Rights Act of 2020 (CPRA – Proposition 24), the Personal Information Protection and Electronic Documents Act (PIPEDA), and any other legislation applicable to the processing of Personal Information or the provision of Services by Bestia Tech.

• Personal Information is defined as any information that relates to an identified or identifiable natural person, such as, but not limited to, names, addresses, email addresses, phone numbers, or other identifiers.

• Processor is defined as an entity that processes Personal Information on behalf of the Controller.

• Prospect is defined as a natural person who visits or browses Bestia Tech’s Website or otherwise interacts with Bestia Tech.

• Service(s) or Bestia Tech Service(s) are defined as Bestia Tech’s website design and development services, consulting services, and related offerings.

• Sub-processors are defined as third-party service providers engaged by Bestia Tech that may process Personal Information on behalf of Bestia Tech in connection with the provision of Services.

• Website is defined as Bestia Tech’s site at https://bestia.tech/ and any other Bestia Tech sites available to you.

• You are defined as a natural person who may act as a Prospect, Customer, or authorized representative.

1. INTRODUCTION TO PRIVACY

Bestia Tech is an Estonian company registered in Estonia and operating under Estonian and European Union law. We always respect your privacy and your privacy rights. Therefore, we hereby declare that Bestia Tech is committed to protecting your privacy and handling your Personal Information openly and transparently in accordance with the applicable Data Protection Laws, implementing relevant security measures to ensure the highest level of privacy and Personal Information protection.

As an Estonian company, we are subject to Regulation (EU) 2016/679 (GDPR) and Estonian data protection regulations. We are supervised by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) as our primary supervisory authority.

When you use Bestia Tech Services and/or browse the Website or otherwise interact with Bestia Tech as described below, we may collect and process your Personal Information. Services are designed for business use and are intended for commercial purposes. When a Prospect is browsing the Website or otherwise interacting with Bestia Tech, we always treat the Prospect as a natural person acting on behalf of a business.

By starting to browse the Website or use the Services, you acknowledge that you have read and accepted this Privacy Policy and consented to the terms specifying the collection, use, sharing, or processing of your Personal Information by Bestia Tech as described in this Policy.

2. ROLE OF PROCESSOR AND CONTROLLER

2.1. Bestia Tech as Controller

When Bestia Tech collects and processes Personal Information on its own behalf and sets the purposes for Personal Information processing, Bestia Tech is deemed a Controller concerning the Personal Information. When acting as a Controller, Bestia Tech is responsible for the privacy and Personal Information protection measures imposed on it as a Controller by applicable Data Protection Laws.

2.2. Bestia Tech as Processor

When Bestia Tech collects and processes Personal Information on behalf of the Customers, Bestia Tech is deemed a Processor, and the Customer is a Controller.

When acting as a Processor, Bestia Tech is responsible for the privacy and Personal Information protection measures imposed under the applicable Data Protection Laws and/or the data processing agreement between the Customer and Bestia Tech.

3. PERSONAL INFORMATION WE COLLECT

3.1. When Acting as Controller

Personal Information that a Prospect shares with Bestia Tech, or that Bestia Tech collects from the Prospect, may include your identification information, contact details, and other data that may help us to identify you as required for the purposes described in this Policy and to ensure that you can interact with the Website or the Services properly.

We may cooperate with third parties that help us conduct business activities, including but not limited to developing and enhancing the Services. Bestia Tech may collect Personal Information from such third parties or receive it from them. When Bestia Tech receives Personal Information from third parties, we require such third parties to provide guarantees that the Personal Information they share was lawfully collected and transferred to Bestia Tech.

Bestia Tech may collect the following Personal Information:

Information Collected Directly From You

Categories of Personal InformationConditions for the Collection
Identifying information (e.g., first name, last name)  Contact information (e.g., position in the company, company name, email address, phone number, postal address)When you use or interact with the Website, submit a Services quote request, communicate with us through the Website’s online contact form, chat, or other channels authorized by Bestia Tech and available to you. When you purchase our Services or enter into a service contract with Bestia Tech. When you visit offline events where Bestia Tech is a participant and we ask you to share your Personal Information with us for further business interaction.
Content (any information you voluntarily share with Bestia Tech, which may include Personal Information)When you submit Services feedback, requests, or complaints, download marketing materials, participate in surveys or promotions, engage with interactive features, or email us. When you share any information, including Personal Information, with Bestia Tech through the Website.
Contact information and Project details (e.g., website requirements, technical specifications, budget information)When you are identified as a project contact, open a support ticket, speak directly to one of our representatives, or engage with our support and project management teams.

Information Collected From Other Sources

Categories of Personal InformationConditions For the Collection
Identifying information(e.g., first name, last name) Contact information(e.g., position in the company, company name, business email address)When you have made your Personal Information publicly available online, and do not mind third parties accessing it (e.g., on social media sites, professional networks). When Bestia Tech’s partners (e.g., referral sources, marketing partners) provide Bestia Tech with information about potential customers (prospects) or their representatives. When a Customer provides Bestia Tech with your Personal Information (e.g., to conclude a commercial contract or resolve project-related issues).
Financial and payment information (e.g., billing address, payment method details)When a Customer designates you as responsible for transaction operations while paying for services. Our payment service providers may share some data with us.

3.2. Automatically Collected Personal Information

Bestia Tech collects Personal Information automatically through web beacons, pixels, clear gifs, and other cookie files and similar technologies used on the Website. The automatically collected Information is not always identifiable. However, it may be considered Personal Information when combined with the data or Personal Information that Bestia Tech possesses.

Bestia Tech may automatically collect the following Information:

Data Collected Automatically

Categories of Personal InformationConditions for the Collection
Web browser type  Website browsing activities information (e.g., what you have searched for and viewed on the Website)  Device and connection information (your connection type and the settings applied when you visit our Website, your device operating system, browser type, URLs of the referring/exit pages, device identifiers, IP address and/or region preference to approximate your geolocation to provide you with a better service experience)When you interact with the Website, we may collect some information about you, including Personal Information. In some cases, the scope of collected data depends on the type of device you use to access the Website and settings made on the device or the web browser you use.

Cookies. Bestia Tech uses cookie files and other tracking technologies to track your activities on the Website. We use such tools to recognize you across different sessions and enhance your experience concerning browsing the Website. Please see our Cookie Policy [insert hyperlink] for more Information.

3.3. Sensitive Personal Information

We never intend to collect or process sensitive Personal Information about you that may reveal your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification of a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation, or any other data that can be considered sensitive under the applicable Data Protection Laws.

We will immediately delete sensitive Personal Information if we become aware that such Personal Information was accidentally collected by Bestia Tech or received from you or any other third party.

4. HOW WE PROCESS PERSONAL INFORMATION

4.1. Purposes

Following legal basis requirements determined in the applicable Data Protection Laws, Bestia Tech collects and processes Personal Information for the following purposes:

Website Functioning. We use Personal Information to operate and administer the Website and provide you with the content you access and request, enhance the Website’s functionality, and perform internal operations, including but not limited to troubleshooting, data analysis, software testing, and statistical calculations. We also make Website elements more accessible to you based on your preferences and enable more effective communication with Bestia Tech through the Website.

Contact Request Handling. We process your Personal Information to handle your contact request when you communicate with us through the Website’s online contact form, chat form, or other communication channels authorized by Bestia Tech and available to you.

Service Delivery. We use Personal Information about you to provide website design and development services, project management, client communication, technical support, quality assurance, and service fulfillment.

Safety and Security. We process Personal Information to provide the security of our systems, websites, and Services you may have access to, particularly through investigating, detecting, and preventing suspicious activity, fraud, and cybercrime that affects or may affect Bestia Tech.

Promotional Communication. We may use Personal Information, including information on the use of the Website, to send you relevant promotional communications that may be of specific interest to you, including promotional emails, or to display our ads on other platforms. These communications may include marketing information, information about new Services, functionalities, features, survey requests, newsletters, and marketing events that may interest you. You may control and restrict the use of your Personal Information for promotional activities through the opt-out options described in this Policy below.

Non-Commercial Communication. We use your Personal Information to communicate with you via email to confirm your service requests, send reminders about project milestones, respond to your questions and requests, provide customer support, send out technical notices, updates, security alerts, administrative messages, etc.

Contract Conclusion. If you wish to engage our Services, Bestia Tech uses Personal Information about you to communicate with you on issues related to the conclusion of the service contract or any other commercial document governing the use of the Services.

Support Activities. Our support team is available for your requests. You may contact us on any support issue related to the Website or Services, and we use our best efforts to resolve any issues you may encounter. We use some Personal Information about you to handle and respond to your support request, resolve the issue, and improve the Services.

Payment Management. Where you identify yourself as a person responsible for the transaction operations and provide Bestia Tech with financial Information, we use Personal Information about you to verify you and the Information you provide. We may also process your Personal Information for invoicing or financial reporting.

Service Development and Optimization. We process your Personal Information to develop, optimize, and improve the performance of the Services.

4.2. Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you. Any automated processing we conduct (such as website analytics) is limited to improving user experience and does not result in decisions that have legal or significant impact on individuals.

If we implement automated decision-making in the future, we will update this policy and provide appropriate safeguards, including the right to obtain human intervention and to contest the decision.

4.3. Legal Basis

We collect and process your Personal Information relying on the legal bases described below. Legal bases applied depend on the interaction between Bestia Tech and you, the Personal Information processing purposes, and the categories of the processed Personal Information.

Contract Performance. We may process Personal Information when it is required to perform a service contract for the use of the Services or take particular steps before entering into such a service contract.

Legitimate Interest. We process your Personal Information when Bestia Tech pursues its legitimate interests, unless your interests or fundamental rights and freedoms override such legitimate interests. We have conducted balancing tests to ensure our legitimate interests do not override your rights. Bestia Tech’s legitimate interests may cover research and development of the Website, advertisement, marketing, and promotional activities, fraud prevention, network and information security, or protecting our legal rights and interests. You have the right to object to processing based on legitimate interests.

Legal Obligations. Data Protection Laws may impose on Bestia Tech legal obligations. Therefore, when cooperating with public and government authorities, courts, or regulators in accordance with our legal obligations to the extent this requires the processing or disclosure of Personal Information to protect Bestia Tech’s rights, we may process Personal Information about you to cover such obligations.

Consent. If the applicable Data Protection Laws require us to obtain consent to process your Personal Information, we ask you to give us consent. Your right to provide us consent is voluntary, and you have a choice whether to give us your consent or not. If we process your Personal Information based on your consent, you have the right to change your mind and withdraw the consent at any time by contacting us at [Insert Privacy Email] or using the unsubscribe links in our communications.

4.4. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to you without undue delay, as required by GDPR Article 34.

5. PERSONAL INFORMATION SHARING

5.1. Who We Share Personal Information With

Service Providers/Vendors. We may sometimes need help in running our business, maintaining the Website, or providing Services. Therefore, we engage third-party service providers/vendors to provide the following services:

• Website hosting and development services 

• Payment processing and analysis services 

• Email service providers and marketing platforms 

• Analytics services (Google Analytics, etc.) 

• Customer relationship management (CRM) systems 

• Cloud storage providers 

• Technical support and troubleshooting services

This involvement may require Bestia Tech to provide service providers access to Personal Information in our possession. Where a service provider accesses some Personal Information to perform relevant services on our behalf, they do so under strict instructions from Bestia Tech and our strict control.

Partners. We may share your Personal Information with our business partners, who are not service providers and may help us provide Services to Customers or refer potential customers to us.

Personnel. We grant Bestia Tech’s officers, directors, managers, employees, consultants, and contractors access to Personal Information, provided Bestia Tech authorizes them to process the Personal Information and commit themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Enforcement Requests and Applicable Laws. We may be forced to share your Personal Information with public, state, or competent supervisory authorities if it is reasonably necessary to comply with any applicable legislation, regulation, legal process, or governmental request.

Professional Advisers. In individual instances, we may share your Personal Information with professional advisers – including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services.

5.2. International Data Transfers

As an Estonian company, we are located within the European Union. We primarily store and process Personal Information on protected cloud servers in Estonia, other EU countries, and the United States. When processing Personal Information, we may be required to transfer it to recipients from various countries to complete the purposes specified in this Policy.

Where we process the Personal Information of individuals who are in the European Union, the EEA, Switzerland, or the United Kingdom, we may be required to transfer Personal Information to countries outside the EU/EEA that do not ensure adequate Personal Information protection under the applicable Data Protection Laws. In such cases, we use the legal transfer mechanisms stipulated by the applicable Data Protection Laws, including the Standard Contractual Clauses approved by the European Commission.

EU to Third Country Transfers: When transferring data from the EU to countries without an adequacy decision, we implement appropriate safeguards such as: 

• Standard Contractual Clauses (SCCs) approved by the European Commission 

• Adequacy decisions for countries deemed to provide adequate protection 

• Certification schemes and codes of conduct

• Binding corporate rules where applicable

6. SECURITY AND PROTECTION OF PERSONAL INFORMATION

We use industry-standard technical measures to secure your Personal Information at the highest level. Taking into account state-of-the-art architecture, the costs of implementation, and the nature, scope, context, and purposes of data processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, we have implemented appropriate security, technical, and administrative measures to prevent unauthorized disclosure, use, or access to Personal Information.

Technical Measures: 

• SSL/TLS encryption for data transmission 

• Encrypted data storage 

• Access controls and authentication
• Regular security updates and patches 

• Network security monitoring

Organizational Measures: 

• Staff privacy training 

• Data processing agreements with vendors 

• Privacy by design principles 

• Incident response procedures 

• Regular security assessments

7. PERSONAL INFORMATION RETENTION

7.1. How Long We Retain Personal Information

Bestia Tech processes and uses Personal Information for as long as it is required to complete the purposes defined by Bestia Tech or as required to fulfill our legal obligations under the applicable legislation. We retain some of your Personal Information for as long as we consider you as Bestia Tech’s potential Customer, pursuing our legitimate interests.

Specific Retention Periods: 

• Active client data: Duration of relationship + 7 years 

• Prospective client data: 3 years from last contact 

• Website analytics: 26 months 

• Marketing data: Until consent withdrawn 

• Financial records: 7 years (legal requirement) 

• Project files and communications: 7 years after project completion

8. HOW TO ACCESS AND CONTROL YOUR PERSONAL INFORMATION

8.1. Privacy Rights You Have

We respect your rights relating to your Personal Information subject to the applicable Data Protection Laws. Therefore, to the extent applicable under Data Protection Laws, we provide you with the possibility to exercise the following rights:

8.1.1. Common Rights

• Right to be informed: You have the right to be informed about how your Personal Information is collected and processed by Bestia Tech. 

• Right to access: You have the right to request access to your Personal Information, including information about how it is processed and who processes it.
• Right to rectification: You can request the correction of inaccurate or incomplete Personal Information. 

• Right to erasure (“right to be forgotten”): You have the right to request the deletion of your Personal Information under certain circumstances. 

• Right to object: You may object to the processing of your Personal Information for specific purposes, such as direct marketing. 

• Right to data portability: You have the right to receive your Personal Information in a structured, commonly used, and machine-readable format.

8.1.2. If the Processing of Personal Information Is Subject to GDPR

• Right to restriction of processing: You can request the restriction of processing your Personal Information in certain situations. 

• Right to withdraw consent: If Personal Information processing relies on consent, you can withdraw your consent at any time. 

• Right to lodge a complaint: You can lodge complaints with the competent supervisory authority.

8.1.3. Rights Specific to CCPA and CPRA

• Right to know: You can request information about the categories and sources of your Personal Information collected during the last 12 months. 

• Right to delete: You can request the deletion of your Personal Information held by us, subject to exceptions. 

• Right to opt out: You have the right to opt out of the sale and sharing of your Personal Information with third parties. 

• Right to non-discrimination: You have the right not to be discriminated against for exercising your privacy rights.

8.2. Submission Procedure

You must submit all rights requests electronically to the following email address: [Insert Privacy Email Address]. You should explicitly specify the subject matter of each request submitted, clarifying the right you wish to exercise.

Response Time: We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA), with possible extensions as permitted by law.

9. ADDITIONAL INFORMATION FOR EU RESIDENTS

9.1. Estonian Registration and GDPR Commitments

Bestia Tech is registered in Estonia as an Estonian company and operates under Estonian law. As an Estonian company, we are fully subject to Regulation (EU) 2016/679 (GDPR) and Estonian data protection regulations.

When Personal Information processing is subject to the GDPR, we process your Personal Data solely under the principles and based on legal grounds stipulated by the GDPR. Bestia Tech implements, maintains, and requires Sub-processors to implement and maintain security and organizational measures to ensure your Personal Data is protected in compliance with the GDPR.

Estonian Data Protection Authority: As an Estonian company, we are primarily supervised by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). You can contact them at:

9.2. Data Protection Officer

Following the requirements of GDPR Art. 37, if required, we will designate a Data Protection Officer (DPO). Contact details will be provided at: [Insert DPO Contact Information if applicable]

9.3. EU Representative

As an Estonian company established in the EU, we do not require an EU representative under GDPR Article 27. Estonian residents and other EU residents can contact us directly at our Estonian address.

10. ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS

10.1. CCPA/CPRA Applicability

The CCPA applies to businesses that: 

• Have annual gross revenues exceeding $25 million (adjusted for inflation – $26.625 million as of 2025), 

OR

 • Buy, sell, or share the personal information of 100,000 or more California residents or households annually, 

OR 

• Derive 50% or more of their annual revenues from selling or sharing California residents’ personal information

If our business meets any of these thresholds, California residents are entitled to the rights described below.

10.2. Our Commitment

We collect and process Personal Information under the California Consumer Privacy Act of 2018 (CCPA), the California Privacy Rights Act of 2020 (CPRA – Proposition 24), and other applicable Data Protection Laws. Bestia Tech implements and maintains security and organizational measures to ensure your Personal Information is protected and our compliance with the CCPA and the CPRA.

We process your Personal Information for the purposes specified in this Policy and never sell your Personal Information to any third parties. We may share or disclose the Personal Information only as described in this Policy.

10.3. Categories of Personal Information (CCPA Categories)

Under California law, we collect the following categories of personal information:

A. Identifiers: Real name, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers

B. Personal Information (Cal. Civ. Code § 1798.80(e)): Name, address, telephone number, education, employment, employment history

C. Commercial Information: Records of services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies

D. Internet or Other Electronic Network Activity Information: Browsing history, search history, and information on interaction with our website or advertisements

F. Professional or Employment-Related Information: Current or past job history (for business clients)

11. ADDITIONAL INFORMATION FOR OTHER US STATE RESIDENTS

11.1. Virginia, Colorado, Connecticut, Utah, and Other State Privacy Laws

Residents of Virginia (Virginia Consumer Data Protection Act – VCDPA), Colorado (Colorado Privacy Act – CPA), Connecticut (Connecticut Data Privacy Act – CTDPA), Utah (Utah Consumer Privacy Act – UCPA), and other states with comprehensive privacy laws have rights similar to those described in the California section above.

Your Rights Include: 

• Right to access your personal data 

• Right to correct inaccuracies in your personal data 

• Right to delete your personal data
• Right to obtain a copy of your personal data (data portability) 

• Right to opt out of the processing of personal data for targeted advertising 

• Right to opt out of the sale of personal data 

• Right to opt out of profiling in furtherance of automated decisions that produce legal or similarly significant effects

Sensitive Data: Under these state laws, we do not process sensitive data categories (such as precise geolocation, biometric data, health data, etc.) without explicit consent or as otherwise permitted by law.

Appeals Process: If we decline to take action on your request, you may appeal our decision by contacting us at [Insert Privacy Email]. We will respond to your appeal within 60 days.

11.2. Applicability Thresholds

These state privacy laws generally apply to businesses that: 

• Conduct business in the respective state or target residents of the state, 

AND 

• Meet certain revenue or data processing thresholds (which vary by state)

If our business activities meet these thresholds, the respective state law protections apply to residents of those states.

12. OUR POLICY TOWARD CHILDREN

The Website and Services must not be used by individuals under 16 (or 13 in jurisdictions where COPPA applies).

We do not knowingly collect Personal Information from or about individuals under the applicable age limit.

If we become aware that an individual under the applicable age limit has provided us with any Personal Information, we will delete such Personal Information immediately.

If you become aware that an individual under the applicable age limit has provided us with Personal Information, please contact us immediately.

13. CHANGES TO PRIVACY POLICY

We may update this Privacy Policy from time to time, depending on: 

• Changes in applicable Data Protection Laws 

• Changes in Bestia Tech’s business activities
• When we believe such changes are reasonable

We will provide notice to you if these changes are material, and, where required by applicable law, we will obtain your consent. Otherwise, the amended version will be effective as of the date it is published.

We encourage you to review our Privacy Policy regularly when browsing the Website or using the Services.

If you disagree with any changes to this Privacy Policy, you must stop using the Services and contact Bestia Tech to deactivate your accounts.

14. CONTACT US

For privacy-related questions, concerns, or to exercise your rights:

Email: [Insert Privacy Email]
Estonian Address: [Insert Complete Estonian Address]
Phone: [Insert Phone Number]
Estonian Registration Number: [Insert Estonian Company Registration Number]

Data Protection Authorities

EU Residents: As an Estonian company, we are primarily supervised by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

  • Website: https://www.aki.ee/en
  • Email: info@aki.ee
  • Address: Tatari 39, Tallinn 10134, Estonia

You can also contact other EU Data Protection Authorities. A complete list is available at: https://edpb.europa.eu/about-edpb/board/members_en

California Residents: You can file complaints with the California Privacy Protection Agency at: https://cppa.ca.gov/

Other US Residents: Contact your state’s attorney general or relevant privacy authority.

Company Registration Information

Estonian Company Registration: [Insert Estonian Company Registration Number]
EU VAT Number: [Insert EU VAT Number if applicable]
Registered Office: [Insert Complete Estonian Address]

Last Updated: [Insert Date]
Version: 1.0

This Privacy Policy has been developed for an Estonian company to comply with applicable privacy laws including Regulation (EU) 2016/679 (GDPR), Estonian Personal Data Protection Act, CCPA/CPRA, PIPEDA, and other relevant legislation. It should be reviewed by legal counsel familiar with Estonian and EU law to ensure compliance with specific business operations and applicable laws in all relevant jurisdictions.