Quretec processes personal data only for specified purposes and to the extent necessary to operate our website, respond to enquiries, manage contractual relationships and recruit employees.
Who this notice applies to
This notice applies to visitors to Quretec’s website, people who contact us, contact persons of clients and partners, and people applying to work at Quretec.
Where Quretec develops or hosts a client’s information system and processes data on the client’s behalf, the client determines the purposes of processing as the data controller. The privacy terms of that service or information system apply to such processing.
Data controller
Quretec OÜ
Registry code 11043739
Ülikooli 6a, 51003 Tartu, Estonia
Phone: +372 730 9508
Email: Email address
Use the same contact details for privacy questions and requests.
What data we process and why
Contact and business enquiries
We process the name, contact details, organisation, message and subsequent correspondence that you provide to us. We use this information to respond, prepare proposals, take steps before entering into a contract and manage client or partner relationships.
The legal basis is taking steps at your request before entering into a contract or performing a contract (GDPR Article 6(1)(b)), and our legitimate interest in communicating with clients and partners and documenting business communications (Article 6(1)(f)). We generally retain correspondence for up to three years after the last communication. Contracts and accounting source documents are retained for the periods required by law, generally seven years.
Recruitment
We process the contact details, CV, cover letter, portfolio and recruitment notes provided by an applicant. The purpose is to assess suitability for a role and manage the recruitment process.
The legal basis is taking pre-contractual steps at the applicant’s request (Article 6(1)(b)) and our legitimate interest in conducting recruitment (Article 6(1)(f)). We retain application data for up to one year after the recruitment decision. We ask for separate consent before retaining it for longer.
Website technical data
Our server may record an IP address, request time, page viewed, browser or device information, and errors. We use this information to maintain website reliability and security, diagnose faults and prevent misuse based on our legitimate interest (Article 6(1)(f)).
We generally retain technical logs for up to 30 days. Data connected with a security incident may be retained for longer, until the incident is resolved and related claims have expired.
Special-category data
We do not ask for health data or other special-category personal data in our ordinary contact or recruitment forms. Please do not send such information unless it is necessary in a specific situation and has been agreed with us in advance.
Sources and requirement to provide data
We receive data primarily from you. Technical data is generated when you use the website. Providing data is voluntary, but without the necessary contact details we may be unable to respond or process an application.
Recipients and transfers
Personal data is accessible only to Quretec staff and partners who need it for their work. We may use trusted IT, hosting, email and other service providers that process data under our instructions. Where necessary, we may disclose data to legal or financial advisers and public authorities when required by law.
We do not sell personal data. We prefer processing within the European Economic Area. If a service entails a transfer outside the EEA, we apply safeguards required by the GDPR, such as a European Commission adequacy decision or Standard Contractual Clauses.
We do not use data collected through the website for automated decision-making or profiling that produces legal or similarly significant effects.
Cookies and analytics
Quretec’s public website does not use analytics or marketing cookies. A contact or application form may use only technically necessary session and security cookies without which the form cannot operate correctly or securely. These cookies are not used for advertising or user tracking.
Our pages may link to other websites. Their providers are responsible for their own cookies and data processing.
Data security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure and access. Access is based on need, and our employees and service providers are subject to confidentiality obligations.
Your rights
You have the right to:
- receive information about processing and access your personal data;
- have inaccurate data corrected;
- request erasure or restriction where the legal conditions are met;
- object to processing based on legitimate interests;
- receive data you provided in a machine-readable format where data portability applies;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with the Estonian Data Protection Inspectorate.
We generally respond within one month. We may ask you to verify your identity before releasing or changing data. These rights are not absolute, and in some cases the law permits or requires processing to continue.
Supervisory authority: Estonian Data Protection Inspectorate, Tatari 39, 10134 Tallinn, Estonia.
Changes to this notice
We may update this notice if our services, data processing or legal requirements change. We publish the current version on this page and show the date of the latest update.
Privacy
Contact us
Send questions or requests concerning your rights to Quretec’s general email address.