Privacy Policy

GDPR Compliant A.D Technological Solutions Effective: 1 January 2024 Last updated: 1 January 2024

Summary: We collect only what we need, never sell your data, keep it only as long as necessary, and honour all GDPR rights. Any privacy request: info@sanj-tech.com.

1. Data Controller

The controller responsible for your personal data is:

A.D Technological Solutions
Sepapaja tn 6, Lasnamäe linnaosa
Tallinn 15551, Estonia
Email: info@sanj-tech.com
Website: sanj-tech.com

2. Scope of This Policy

This Privacy Policy applies to personal data collected through:

Where we process data on behalf of a client (as a data processor), this policy does not apply — the client's own policy governs that processing.

3. Data We Collect

3.1 Data You Provide Directly

CategoryExamplesHow Collected
Identity dataFirst name, last name, job titleContact form, email, service agreements
Contact dataEmail address, phone number, company nameContact form, email correspondence
Communication dataMessages, support tickets, meeting notesEmail, helpdesk, calls
Commercial dataPurchase history, invoices, contract detailsService agreements

3.2 Data Collected Automatically

CategoryExamplesHow Collected
Technical dataIP address, browser type, OS, device typeServer logs, analytics cookies
Usage dataPages visited, time on site, referral sourceAnalytics cookies (with consent)
Cookie dataConsent preference, session IDCookies (see Section 10)

3.3 Data We Do Not Collect

We do not collect special category data (health, biometric, political opinions, etc.) through this website, nor do we collect payment card data directly — payments are handled by PCI-DSS-compliant third-party processors.

4. Purposes and Legal Bases (GDPR Art. 6)

PurposeLegal BasisDetails
Responding to enquiriesArt. 6(1)(b) Contract / Art. 6(1)(f) Legitimate interestReplying to your contact form or email.
Delivering Managed IT ServicesArt. 6(1)(b) Contract performanceNecessary to fulfil our service agreement.
Marketing communicationsArt. 6(1)(a) ConsentOnly where you have opted in. Withdrawable at any time.
Website analyticsArt. 6(1)(a) Consent (cookie banner)Google Analytics with IP anonymisation.
Invoicing and accountingArt. 6(1)(c) Legal obligationEstonian accounting and tax law.
Security and fraud preventionArt. 6(1)(f) Legitimate interestServer logs and security monitoring.
Compliance and legal claimsArt. 6(1)(c) / Art. 6(1)(f)Retaining data to defend legal claims.

Legitimate interest balancing: Where we rely on legitimate interests, we have carried out a balancing test and concluded our interests do not override your rights, given the nature of data collected from a business IT services website.

5. Data Retention

Data CategoryRetention PeriodReason
Contact form enquiries (non-client)3 years from last contactLegitimate interest
Client contractual dataContract duration + 7 yearsEstonian Accounting Act
Marketing consent recordsUntil withdrawn + 3 yearsDemonstrate consent
Server logs / technical data90 days rollingSecurity monitoring
Analytics data26 months (anonymised)Website improvement
GDPR request records3 years from responseAccountability obligation

6. Data Sharing and Processors

We do not sell, rent, or trade your personal data. We share data only with processors bound by GDPR Art. 28 data processing agreements.

Processor CategoryPurposeLocation
Email delivery providerTransactional and marketing emailsEU/EEA
CRM / helpdesk platformClient relationships and supportEU/EEA
Analytics (Google Analytics)Anonymous website statisticsUSA (SCCs in place)
Cloud infrastructureWebsite and system hostingEU/EEA
Accounting softwareFinancial records and invoicingEU/EEA

We may also disclose data to authorities where required by law, or to protect the safety and rights of our company, clients, or the public.

7. International Data Transfers

Our operations are based in Estonia (EU/EEA). Where processors are outside the EEA (e.g., Google Analytics), we ensure safeguards under GDPR Chapter V via Standard Contractual Clauses (SCCs) — Commission Implementing Decision (EU) 2021/914 — and supplementary technical measures such as IP anonymisation. You may request a copy of applicable transfer safeguards at info@sanj-tech.com.

8. Your Rights Under GDPR

Contact us at info@sanj-tech.com to exercise any right. We respond within 30 days (extendable by 60 days for complex requests).

👁️

Right of Access

Obtain a copy of your data and processing information (Art. 15).

✏️

Right to Rectification

Correct inaccurate or incomplete data (Art. 16).

🗑️

Right to Erasure

Request deletion where there is no compelling reason to continue (Art. 17).

⏸️

Right to Restriction

Restrict processing in certain circumstances (Art. 18).

📦

Right to Portability

Receive data in a structured, machine-readable format (Art. 20).

🚫

Right to Object

Object to processing based on legitimate interest or for direct marketing (Art. 21).

↩️

Withdraw Consent

Withdraw consent at any time without affecting prior lawful processing (Art. 7(3)).

🤖

Automated Decisions

Not to be subject to solely automated decisions affecting you (Art. 22). We don't carry out such processing.

9. Opt-Out of Marketing Communications

To unsubscribe from marketing emails:

We will action your request within 5 business days. Transactional and service emails (invoices, service notifications) are not affected by marketing opt-out.

10. Cookies

We use cookies to operate the site and, with your consent, to analyse usage. A cookie consent banner is displayed on first visit. Strictly necessary cookies are always active; analytics cookies require explicit consent. See the Cookie Policy available via the cookie banner or footer for full details.

11. Children's Privacy

Our services target business professionals. We do not knowingly collect data from individuals under 16. If you believe a minor has provided data, contact info@sanj-tech.com and we will delete it promptly.

12. Security Measures

We implement appropriate technical and organisational measures including TLS encryption for data in transit, access controls and role-based permissions, regular security assessments and staff training, and pseudonymisation where appropriate. In the event of a data breach likely to risk your rights, we will notify the supervisory authority within 72 hours and affected individuals as required under GDPR Art. 33–34.

13. Complaints

If you believe we've not handled your data lawfully, please contact us first at info@sanj-tech.com. You also have the right to lodge a complaint with:

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, Tallinn 10134, Estonia
www.aki.ee · info@aki.ee

Or with the supervisory authority in your EU/EEA country of residence.

14. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be flagged with an updated "Last updated" date. Where required by law, we will seek your consent. We recommend reviewing this page periodically.

15. Contact Us

A.D Technological Solutions
Sepapaja tn 6, Lasnamäe linnaosa
Tallinn 15551, Estonia
Email: info@sanj-tech.com
Subject line for GDPR requests: "GDPR Request – [Your Name]"

Response time: We acknowledge all privacy requests within 3 business days and provide a full response within 30 days as required by GDPR Art. 12.