Legal
Privacy Policy
- Legal entity
- COUBUS OÜ
- Registry code
- 14419079
- Registered address
- Vesivärava tn 50-301, Kesklinna linnaosa, 10152 Tallinn, Harju maakond, Estonia
- VAT number
- EE102258750
- Contact
- hello@coubus.com
This Privacy Policy explains how COUBUS OÜ (“COUBUS”, “we”, “us”) processes personal data when you visit coubus.com (the “Website”), contact us, or enter into a business relationship with us. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.
This policy covers the Website and our sales and business communications. Our own products are governed by their own privacy policies: Notitask; Spotrum’s policy is available within the product.
- 1. Data controller
- 2. Data we collect
- 3. Purposes and legal bases
- 4. Retention
- 5. Recipients and processors
- 6. International transfers
- 7. Security
- 8. Your rights
- 9. Cookies and analytics
- 10. Automated decision-making
- 11. Children
- 12. Third-party websites
- 13. Changes to this policy
- 14. Contact and complaints
1. Data controller
The controller of your personal data is COUBUS OÜ, a private limited company registered in Estonia (registry code 14419079), Vesivärava tn 50-301, Kesklinna linnaosa, 10152 Tallinn, Harju maakond, Estonia. Privacy inquiries: privacy@coubus.com.
We have not appointed a Data Protection Officer, as we are not required to do so; the contact above handles all data protection matters.
2. Data we collect
2.1 Data you provide
- Project inquiry form — name, company, email address, project type, project stage, estimated budget, project description and any other information you choose to include.
- Direct correspondence — email, messages, meeting notes and documents you send us in the course of discussing or delivering a project.
- Contract and billing data — for clients: contact persons, roles, contractual and invoicing details, payment records.
2.2 Data collected automatically
- Server logs — IP address, date and time of the request, requested URL, HTTP status, referrer, browser and operating system, kept by our hosting provider and us for security and reliability.
- Form protection signals — a submission timestamp and a hidden anti-spam field, used only to distinguish people from automated submissions. We may also apply a temporary per-IP rate limit.
- Analytics — if enabled, aggregated, cookie-less usage statistics (page views, referrers, country, device type, browser). Individual visitors are not identified. See section 9.
2.3 Data we do not collect
We do not collect special categories of personal data (such as health, political or religious data), and we do not sell personal data. Please do not include such data in your inquiries.
3. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Responding to your inquiry and discussing a potential project | Inquiry form, correspondence | Art. 6(1)(b) — steps prior to entering into a contract; Art. 6(1)(f) — legitimate interest in responding to business inquiries |
| Preparing proposals, negotiating and performing contracts | Correspondence, contract and billing data | Art. 6(1)(b) — performance of a contract |
| Invoicing, accounting and tax reporting | Contract and billing data | Art. 6(1)(c) — legal obligation (Estonian Accounting Act, tax law) |
| Keeping the Website secure, preventing abuse and spam | Server logs, form protection signals | Art. 6(1)(f) — legitimate interest in security and integrity of our systems |
| Understanding how the Website is used (Google Analytics) | Analytics data | Art. 6(1)(a) — your consent, given through the cookie banner and withdrawable at any time |
| Aggregated, cookie-less traffic and security statistics | Request metadata | Art. 6(1)(f) — legitimate interest in security and performance |
| Establishing, exercising or defending legal claims | Any of the above, as relevant | Art. 6(1)(f) — legitimate interest |
| Sending you information about our services after a project (where permitted) | Business contact details | Art. 6(1)(f) — legitimate interest in existing-customer communication, with the right to object at any time; or Art. 6(1)(a) — consent where required |
Where we rely on legitimate interest, we have assessed that our interest is not overridden by your interests or fundamental rights. You may request details of this assessment.
Providing personal data is voluntary; however, without the information marked as required in the inquiry form we cannot respond to your request.
4. Retention
- Inquiries that do not lead to a contract — up to 24 months from the last communication, then deleted.
- Client and contract data — for the duration of the relationship and up to 7 years afterwards, as required by Estonian accounting and tax legislation.
- Server logs — up to 90 days, unless needed longer to investigate a security incident.
- Analytics data — retained only in aggregated form.
When data is no longer needed, it is deleted or irreversibly anonymised.
5. Recipients and processors
We share personal data only where necessary, with:
- Service providers (processors) acting on our instructions under data processing agreements: web hosting and infrastructure, email and communication services, form delivery, document storage, accounting and invoicing software, and — where you consented to analytics — Google Ireland Limited (Google Analytics).
- Professional advisers — accountants, lawyers and auditors, bound by confidentiality.
- Authorities — where required by law, court order or to protect our legal rights.
- A successor — in the event of a merger, acquisition or sale of assets, under the same protections.
We do not sell, rent or trade personal data, and we do not share it with third parties for their own marketing.
6. International transfers
We are based in the European Union and prefer providers that process data within the EU/EEA. Where a provider processes data outside the EEA, we ensure an adequate level of protection through an EU adequacy decision, the European Commission’s Standard Contractual Clauses together with a transfer impact assessment, or another safeguard permitted under Chapter V of the GDPR. You may request a copy of the relevant safeguards.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), access control on a need-to-know basis, separation of production systems, logging, regular updates and backups. No method of transmission or storage is completely secure; if we become aware of a personal data breach that is likely to result in a risk to you, we will notify you and the supervisory authority as required by law.
8. Your rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy (Art. 15);
- Rectify inaccurate or incomplete data (Art. 16);
- Erase your data in the circumstances set out in Art. 17;
- Restrict processing (Art. 18);
- Data portability — receive data you provided in a structured, machine-readable format (Art. 20);
- Object to processing based on legitimate interest, including direct marketing, at any time (Art. 21);
- Withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal (Art. 7(3)).
To exercise these rights, email privacy@coubus.com. We may ask you to verify your identity. We respond within one month; this period may be extended by two further months for complex requests, in which case we will inform you. Requests are free of charge unless manifestly unfounded or excessive.
9. Cookies and analytics
Analytics cookies are set only after you accept them; the Website works fully without them. Details, including how to withdraw consent, are in our Cookie Policy.
10. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you. Anti-spam filtering of form submissions is automated but has no such effect; a rejected submission can always be resent by email.
11. Children
The Website and our services are directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Third-party websites
The Website links to third-party websites and app stores (for example, our products’ websites and Google Play). Those sites have their own privacy policies; we are not responsible for their content or practices.
13. Changes to this policy
We may update this policy to reflect changes in our practices or in the law. The effective date at the top indicates the latest version. Material changes will be highlighted on the Website; continued use of the Website after the effective date constitutes acknowledgement of the updated policy.
14. Contact and complaints
COUBUS OÜ (registry code 14419079), Vesivärava tn 50-301, Kesklinna linnaosa, 10152 Tallinn, Harju maakond, Estonia · privacy@coubus.com
If you believe we have not handled your data in accordance with the law, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with the supervisory authority in your EU member state of residence or work. We would appreciate the chance to address your concern first.