Skip to main content

Legal

Privacy Policy

Document controller

4Tuna OÜ · Registry code 14773496 · EU VAT EE102445932
Liivalaia tn 13, 10118 Tallinn, Kesklinna linnaosa, Harju maakond, Estonia
info@4tunaou.com

Last updated 10 September 2026 · Governing law: Estonia, European Union

This policy explains what personal data 4Tuna OÜ collects through this website, why, on what legal basis, how long it is kept and what you can do about it. It is written to be read, not to be skimmed past.

1. Who is responsible for your data

The data controller is 4Tuna OÜ, an Estonian private limited company with registry code 14773496 and EU VAT number EE102445932, registered office at Liivalaia tn 13, 10118 Tallinn, Kesklinna linnaosa, Harju maakond, Estonia. You can reach us about anything in this policy at info@4tunaou.com.

We have not appointed a data protection officer, because we are not required to under Article 37 GDPR. Data protection questions are handled by the company’s management at the address above.

2. What we collect, and why

2.1 Request for proposal form

When you submit a request for proposal we collect the organisation name, contact person, work e-mail address, and optionally a telephone number, together with the project scope, technical requirements, preferred engagement model and your message.

  • Purpose. Reading and answering your request, and preparing a written response or a follow-up conversation.
  • Legal basis. Article 6(1)(b) GDPR, steps taken at your request before entering into a contract. Where you write on behalf of an organisation rather than on your own account, Article 6(1)(f), our legitimate interest in responding to a business enquiry. You can object to processing on that basis at any time under Article 21.
  • Retention. 24 months from your last contact with us, then deleted. If the enquiry becomes a contract, the contract’s own retention rules apply instead, including the seven-year accounting retention required by Estonian law.
  • Consequence of not providing it. The organisation, contact person, e-mail, scope and message are needed to answer at all. Everything else is optional and the form works without it.

2.2 General enquiry form

Name, work e-mail, optional organisation, subject and message. Purpose, legal basis and retention are the same as for the request for proposal form.

2.3 Technical data recorded by the server

Our web server records the request path, timestamp, response status, user agent and referrer for every request, as any web server does. Your IP address is not stored in readable form: it is passed through a salted SHA-256 hash and only the hash is written, so it can be used to rate-limit abusive submissions but cannot be turned back into an address.

  • Legal basis. Article 6(1)(f), our legitimate interest in keeping the service available and preventing abuse.
  • Retention. Server logs are rotated and deleted after 14 days. Rate-limit records are deleted after 24 hours.

2.4 Cookies and measurement

Nothing optional is stored in your browser until you choose it. Analytics and advertising measurement are switched off by default for every visitor and are only enabled if you turn them on in the cookie banner. The full inventory is in the Cookie Policy.

3. What we do not do

  • We do not sell, rent or trade personal data. Ever, to anyone.
  • We do not use enquiry data for advertising, profiling or automated decision-making, and no decision affecting you is made by automated means.
  • We do not add you to a newsletter because you sent an enquiry.
  • We do not load web fonts, embedded videos, social widgets, chat widgets or trackers from third parties. Typefaces come from your own device.

4. Who else sees your data

Enquiry contents are read by 4Tuna OÜ personnel only. Two categories of processor are involved in delivering the service itself:

  • Hosting. This website runs on a dedicated virtual server rented from Namecheap, Inc. The server is located in the United States. This is a transfer of personal data outside the EEA within the meaning of Chapter V GDPR, and it is covered by the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) together with encryption in transit. We state the hosting country plainly rather than implying EU hosting we do not have. If your organisation requires EU-only hosting for a project, we design and deploy client systems in EU regions; that is a property of the engagement, not of this marketing site.
  • E-mail. Replies to your enquiry are sent from our own domain through our mail provider.

We may also disclose data where we are legally required to, for example in response to a lawful order from a competent authority.

5. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Article 15);
  • have inaccurate data corrected (Article 16);
  • have data erased (Article 17);
  • restrict processing (Article 18);
  • receive your data in a portable format (Article 20);
  • object to processing based on legitimate interests (Article 21);
  • withdraw consent at any time where processing is based on consent, without affecting processing carried out before you withdrew it (Article 7(3)).

Write to info@4tunaou.com and we will respond within one month. There is no charge. We may ask you to confirm your identity where we cannot otherwise tell that the request is yours.

If you are not satisfied with our response, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, aki.ee, or to the supervisory authority in your own EU country of residence.

6. Security

The site is served only over HTTPS with a modern TLS configuration. Form submissions are rate-limited and validated on the server. Database credentials are held outside the web root. Access to enquiry data is limited to personnel who need it to answer you. No transmission over the internet can be guaranteed absolutely secure, and we do not claim otherwise.

7. Children

This site is aimed at business customers. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us data, write to us and we will delete it.

8. Changes to this policy

If this policy changes materially we will update the date at the top of the page. The version you are reading was last updated on 10 September 2026.