Väike Päike Koolituskeskus OÜ (DigiLa) Privacy Policy

Effective from 18.08.2020

We follow European data protection regulations (GDPR) when processing personal data. Accordingly, we have drafted the Privacy Policy of Väike Päike Koolituskeskus OÜ. The purpose of the Privacy Policy is to protect the privacy of our clients in accordance with the laws of the Republic of Estonia and the regulations of the European Union.

“Personal data” refers to any information about an identified or identifiable natural person: for example, name, address, email address, bank account number, and information about visits to our website, social media channels, and the use of our services.

By using our website, you agree to the terms of processing personal data as described below in our Privacy Policy.

I Whose data does Väike Päike Koolituskeskus OÜ process?

Väike Päike Koolituskeskus OÜ is the data controller of personal data and for any questions, please contact digila@digila.eu.

Väike Päike Koolituskeskus OÜ processes the data of its clients and contact persons who have expressed a desire to consume our services or have previously used our services.

II How are data collected and processed?

The types of personal data collected by Väike Päike Koolituskeskus OÜ are: full name and personal identification code of the individual, phone number, and email address. Data is collected directly from the data subject and only with their consent.

In processing personal data, we ensure that:

  1. Processing is lawful, fair, and transparent to the data subject.
  2. We collect personal data accurately and clearly defined for lawful purposes and do not process them later in a manner incompatible with those purposes.
  3. We collect as little data as possible, meaning personal data is relevant, essential, and limited to what is necessary for the purposes of processing.
  4. Personal data is accurate, and if necessary, we update and delete or correct immediately any personal data that is inaccurate from the perspective of the processing purpose.
  5. We retain personal data in a form that allows data subjects to be identified only for as long as necessary for the purpose for which the personal data is processed.
  6. We process personal data reliably and securely.

To ensure lawful processing of personal data, we fulfill the following conditions, of which at least one must be met:

  1. The data subject (employee, client, learner) must consent to the processing of their personal data for one or more specific purposes.
  2. We process personal data to fulfill a contract to which the data subject is a party.
  3. We process personal data of Väike Päike Koolituskeskus OÜ as the data controller to fulfill a legal obligation.
  4. We process personal data when it is necessary to protect the vital interests of the data subject.
  5. We do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data for the purpose of uniquely identifying a natural person, health data, or data concerning a natural person’s sex life or sexual orientation.

The above-mentioned data is processed only if the employee has consented to the processing of such information, and the processing of this information is necessary to fulfill legal obligations.

III Data Subject Rights

The data subject has the right to obtain confirmation from Väike Päike Koolituskeskus OÜ as to whether personal data concerning them is being processed and to access the personal data collected about them, including the following information: the purpose of processing, types of personal data, recipients to whom the personal data has been or will be disclosed, the intended period of personal data retention, information about the right to lodge a complaint with a supervisory authority. If personal data was not collected from the data subject, the right to obtain information about its source applies.

  1. The data subject has the right to request that Väike Päike Koolituskeskus OÜ immediately correct any inaccurate personal data concerning them.
  2. The data subject has the right to request the completion of incomplete personal data by providing additional information and taking into account the purposes of data processing.
  3. The data subject has the right to request that Väike Päike Koolituskeskus OÜ immediately delete personal data concerning them.

IV Retention and Deletion of Personal Data

Secure retention of personal data is the highest security priority of Väike Päike Koolituskeskus OÜ. We strive to take all possible measures to prevent unauthorized access, disclosure, and other unlawful processing. We protect the confidentiality and integrity of personal data and ensure access to data in accordance with applicable laws.

We have established reasonable and adequate organizational measures, as well as technical and physical restrictions, to protect the personal data we collect and process.

Väike Päike Koolituskeskus OÜ has implemented necessary technical, physical, and organizational security measures to protect customer personal data from loss and unauthorized processing.

Collected personal data is deleted immediately when:

  1. Personal data is no longer needed for the purpose for which it was collected.
  2. The data subject withdraws consent for processing.
  3. The data subject objects to the processing of personal data.
  4. Personal data has been processed unlawfully.
  5. The law requires it.

V Other Provisions

Väike Päike Koolituskeskus OÜ reserves the right to unilaterally amend the Privacy Policy. The latest version of the Privacy Policy is always available on this website.

This Privacy Policy is governed by the laws of the Republic of Estonia.