Privacy Policy
Last updated:
Hillool OÜ (Registry code: 16212483), registered at Pärnu mnt. 139B (3rd floor), 11317 Tallinn, Estonia ("Hillool", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect information about you in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Estonian data protection law.
By using our website at hillool.com or engaging our services, you acknowledge that you have read and understood this policy.
1. Data Controller
Hillool OÜ
Registry code: 16212483
Pärnu mnt. 139B (3rd floor), 11317 Tallinn, Estonia
Email: support@hillool.com
2. What Data We Collect
We may collect the following categories of personal data:
- Contact information: name, email address, phone number (when provided).
- Project information: details about your project or service requirements submitted via our contact form.
- Communication data: emails, messages, and other correspondence exchanged with us.
- Usage data: IP address, browser type, pages visited, and time spent on our website (collected via Google Analytics).
- Payment and billing data: invoicing details necessary to process payments (we do not store full payment card details).
3. How We Use Your Data
We process your personal data for the following purposes and on the following legal bases:
- To respond to service requests (Legal basis: Legitimate interest / Pre-contractual steps)
- To deliver agreed services (Legal basis: Performance of a contract)
- To issue invoices and process payments (Legal basis: Legal obligation / Contract)
- To communicate about ongoing projects (Legal basis: Contract / Legitimate interest)
- To improve our website and services (Legal basis: Legitimate interest)
- To comply with legal and regulatory obligations (Legal basis: Legal obligation)
We do not use your data for automated decision-making or profiling.
4. How We Share Your Data
We do not sell, rent, or trade your personal data. We may share data with:
- Service providers: trusted third-party tools and platforms used to operate our business (e.g. email hosting, analytics, payment processing), who are bound by data processing agreements.
- Legal authorities: where required by law or to protect our legal rights.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
5. Google Analytics
Our website uses Google Analytics to understand how visitors use our site. Google Analytics collects anonymised usage data via cookies. You can opt out by installing the Google Analytics Opt-out Browser Add-on. For more information, see Google's Privacy Policy.
6. Data Retention
We retain personal data only for as long as necessary:
- Client project and communication records are retained for up to 7 years to comply with Estonian accounting and tax law.
- Service request enquiries that do not result in a project are deleted after 12 months.
- Website analytics data is retained in accordance with Google Analytics' default retention settings.
7. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of access — you can request a copy of the personal data we hold about you.
- Right to rectification — you can ask us to correct inaccurate data.
- Right to erasure — you can request deletion of your data, subject to legal retention obligations.
- Right to restrict processing — you can ask us to limit how we use your data.
- Right to data portability — you can request your data in a machine-readable format.
- Right to object — you can object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please email support@hillool.com. We will respond within 30 days.
If you believe your rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. Our website uses HTTPS encryption. Access to personal data is restricted to authorised personnel only.
9. International Data Transfers
Where we use third-party service providers based outside the European Economic Area (EEA), we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) in accordance with GDPR requirements.
10. Cookies
Our website uses cookies primarily for analytics purposes (Google Analytics). By continuing to use our website, you consent to the use of cookies as described. You can manage cookie preferences through your browser settings.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be published on this page with a revised date. We encourage you to review this policy periodically.
12. Contact Us
For any data protection queries or to exercise your rights, contact our data controller at:
Hillool OÜ
Pärnu mnt. 139B (3rd floor), 11317 Tallinn, Estonia
Registry code: 16212483
Email: support@hillool.com