Legal

Privacy policy

How 3A-Services OÜ handles personal data on this website, under Regulation (EU) 2016/679 (the General Data Protection Regulation) and the Estonian Personal Data Protection Act.

Last reviewed 22.08.2026. Build 2026-09-02.1.

The short version

  • The controller is 3A-Services OÜ, registry code 12890660, Tallinn, Estonia.
  • This site sets no advertising, analytics or tracking cookies, and loads nothing from any other domain — no fonts, no scripts, no images, no embeds.
  • The only personal data you actively give us is what you type into the enquiry form. Every field on it is required and is used solely to answer you.
  • We do not ask for consent, because consent is not the lawful basis this rests on. There is no tick-box on the form and none is needed.
  • Your enquiry is kept for 24 months from the last communication about the enquiry and then deleted.
  • The website is hosted by Hostinger International Limited. On 23.08.2026 the infrastructure serving this domain was located in United Kingdom, which is outside the European Economic Area — §6 explains what that means and why it is lawful.
  • Nothing is sold, and nothing is shared with anyone for their own purposes.

1. Who is responsible

The data controller for everything described here is:

Legal name
3A-Services OÜ (Osaühing (private limited company))
Registry code
12890660
VAT number
EE102070857
Registered address
Astangu tn 19/3-147, 13519 Tallinn, Haabersti linnaosa, Harju maakond, Estonia
Contact for data protection
info@3a-services.net

The company has not appointed a Data Protection Officer. It is not required to: its core activities do not consist of large-scale regular monitoring of data subjects, nor of large-scale processing of special categories of data. Data protection questions go to the address above and are answered by the management board.

2. What is collected, and why

This section lists every field, matching the live form and the records the server writes. If you find something on the form that is not described here, tell us — that is a defect and we will fix it.

2.1 The enquiry form

All five fields are required. That is deliberate: Article 6(1)(b) covers only processing that is necessary for steps taken at your request, so a field the form itself called optional could not rest on that basis. We would rather not collect a field than invent a second lawful basis for a convenience.

Enquiry form — field inventory
Field Why it is necessary Lawful basis Retention
Your name To address a reply to a person rather than to an organisation in the abstract. Art. 6(1)(b) 24 months from the last communication about the enquiry
Organisation We contract with organisations. It determines whether the enquiry is one we can act on at all. Art. 6(1)(b) 24 months from the last communication about the enquiry
Work e-mail address The only channel by which we can answer. Nothing else is sent to it. Art. 6(1)(b) 24 months from the last communication about the enquiry
What this is about Routes the enquiry and tells us before reading whether it falls outside what we accept. Art. 6(1)(b) 24 months from the last communication about the enquiry
Description of the problem The substance of the request. Without it there is nothing to respond to. Art. 6(1)(b) 24 months from the last communication about the enquiry
On consent

We do not rely on consent (Article 6(1)(a)) for the enquiry form, and the form contains no consent tick-box. Two reasons. Answering a business enquiry is a pre-contractual step under Article 6(1)(b), which is a different basis; and consent that you would have to give in order to send the form would not be freely given within the meaning of Article 7(4), so it would not be valid consent either. What the law requires here is information, not permission, and that information is on the contact page beside the submit button as well as in this policy.

2.2 Server logs

The web server records each request: the IP address, the time, the page requested, the HTTP status, the referring page and the browser's user-agent string. This is ordinary web server operation and is used to keep the site running and to investigate abuse or attack. The lawful basis is Article 6(1)(f), our legitimate interest in the security and availability of our own systems. Logs are retained for no more than 30 days.

The application keeps a second, smaller log of events — that an enquiry was stored, that a rate limit was reached, that a mail send failed. It records that something happened, never the content of a message or the address of the person who sent it.

2.3 Abuse prevention

To stop the enquiry form being used to send bulk messages, the server keeps a short-lived count of submissions per connection. Your IP address is not stored for this: it is combined with a secret value and hashed, and only the hash is written. The hash cannot be read back into an address, and the record expires within an hour. Lawful basis: Article 6(1)(f), our legitimate interest in preventing misuse of our own form.

2.4 What we do not collect

  • No telephone number — the form does not ask for one.
  • No account, no login, no password: this site has no user accounts.
  • No payment details. Invoices are issued and paid outside this website.
  • No special categories of personal data under Article 9, and none should be sent through the form.
  • No data about children. This site is addressed to organisations and is not directed at anyone under 18.
  • No profiling, and no automated decision-making producing legal or similarly significant effects (Article 22).

3. Cookies and local storage

This site uses only storage that is strictly necessary or that you switch on yourself with a control on the page. Article 5(3) of the ePrivacy Directive, as implemented in Estonia by the Electronic Communications Act, does not require consent for storage strictly necessary to provide a service the user has requested — which is why you meet a dismissible notice here rather than a consent gate. The complete list is:

Complete cookie inventory
Name Purpose Type Expires
3as_csrf Holds the one-time token that proves a contact form submission came from a form this site served. Strictly necessary security measure. Session cookie Deleted when the browser is closed
3as_notice Remembers that the storage notice at the foot of the page has been dismissed, so it is not shown again. First-party cookie 180 days
3as_theme Remembers a light or dark appearance chosen with the control in the page header. Set only if that control is used. First-party cookie 365 days

That is the entire list. There is no third-party cookie of any kind, because there is no third-party code of any kind — see §4. You can delete all three at any time in your browser; the site continues to work, and the only effect is that the notice reappears and any appearance choice is forgotten.

4. Third parties on this page — there are none

Every asset this site loads comes from 3a-services.net. The two typefaces are served from this domain rather than from a font service, the stylesheet and the one small script are our own, and the diagrams are drawn in the page rather than fetched as images. The site's Content-Security-Policy is set to default-src 'self' with connect-src 'none', so a third-party request would be refused by your browser rather than quietly succeeding.

You can confirm all of this yourself in a browser's network tab. Specifically, we do not use:

  • No content delivery network
  • No analytics or measurement product
  • No advertising or remarketing tag
  • No social media plug-ins, embeds or share buttons
  • No live chat widget
  • No customer relationship management integration
  • No third-party web fonts — the two typefaces are served from this domain

5. Who else sees the data

Personal data from this site is not disclosed to third parties for those parties' own purposes, and it is never sold. It is not, however, accurate to say that nobody else touches it: running a website means using a processor, and a controller-to-processor transfer is still a transfer. The complete list of processors is:

Processors
Processor What it does for us Country
Hostinger International Limited Website hosting and storage of enquiry-form submissions United Kingdom

Beyond that, we would disclose personal data only where we are legally obliged to — for example to a court or a supervisory authority acting within its powers — or to our own professional advisers under a duty of confidentiality, and only so far as necessary.

6. Where the data is processed, and transfers

Stated as measured, not as assumed

The site is served from 168.231.114.69. RIPE RDAP records that assignment to Hostinger with country GB, and round-trip times measured from the server itself — 0.24 ms to London against 24.8 ms to Falkenstein and 80.1 ms to Ashburn — place it in the London metropolitan area. Measured 23.08.2026. We state what we measured rather than a general claim about a region, and if the hosting arrangement changes this section is corrected on the day it changes — every sentence below is generated from a single configuration value used across the whole site, so they cannot drift out of step with one another.

The website and its e-mail for this domain are operated on infrastructure provided by Hostinger International Limited. The infrastructure serving this domain is located in London, United Kingdom. Enquiry-form submissions are stored on this server only; the website does not send them by e-mail while outbound mail from the site is disabled. The domain mailbox at info@3a-services.net is operated on the same provider's infrastructure and can be used for direct written contact.

United Kingdom is outside the European Economic Area. Personal data submitted through this website is therefore transferred to a third country within the meaning of Chapter V of the GDPR. The transfer takes place under Article 45 GDPR – European Commission adequacy decision for the United Kingdom, renewed 19 December 2025 and applicable until 27 December 2031.

In practice that means the European Commission has formally decided that this country's law provides a level of protection essentially equivalent to the GDPR, so no additional safeguard such as standard contractual clauses is required for the transfer to be lawful. Should that decision be withdrawn or lapse, we would need a different mechanism, and this section would be updated before the change took effect.

Work carried out under a client contract may involve other arrangements — a client's own cloud tenancy, for example. Those are governed by the data processing agreement signed for that engagement, not by this policy, which covers this website only.

7. How long anything is kept

Retention periods
WhatKept forThen
Enquiry form submissions 24 months from the last communication about the enquiry Deleted
Web server request logs Up to 30 days Rotated and deleted
Application event log Up to 90 days Deleted. Contains no message content and no e-mail addresses
Rate-limit records (hashed) Up to 1 hour Expires automatically

Where an enquiry turns into an engagement, the correspondence moves into the contract file for that engagement and is kept under the retention rules of that contract and of Estonian accounting law, which requires business records to be preserved for seven years.

8. Security

  • The site is served over HTTPS, with HTTP Strict Transport Security enabled.
  • A Content-Security-Policy restricts the page to first-party resources and blocks framing, plug-ins and outbound connections.
  • The enquiry form is protected by a one-time token bound to your session, so a submission cannot be forged from another site.
  • Submissions are written outside the public web root, so they cannot be requested over the web even if a path were guessed.
  • IP addresses in the abuse-prevention store are hashed with a secret value; the store never holds an address.
  • Access to enquiry records is limited to the people who answer them.

No arrangement makes a system immune, and we do not claim certification we do not hold: the company holds no ISO/IEC 27001 or comparable certificate, and nothing on this site should be read as saying otherwise. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, and notify you directly where the regulation requires.

9. Your rights

Under the GDPR you may:

  • Ask what we hold and receive a copy (Article 15).
  • Have inaccurate data corrected or incomplete data completed (Article 16).
  • Ask for erasure, where one of the grounds in Article 17 applies.
  • Ask us to restrict processing while a dispute about accuracy or grounds is resolved (Article 18).
  • Receive the data you gave us in a structured, machine-readable form, or have it sent to another controller (Article 20).
  • Object to processing that rests on legitimate interests — that is the server logs and the abuse-prevention count described in §2.2 and §2.3 (Article 21).
  • Withdraw consent — noted for completeness only: we rely on no consent, so there is nothing to withdraw.

Write to info@3a-services.net. We answer within one month of receiving the request, as Article 12(3) requires; if a request is complex we may extend that by two further months and will tell you within the first month if we do. We may need to confirm your identity before disclosing personal data, and we will not charge a fee unless a request is manifestly unfounded or excessive.

You also have the right to complain to a supervisory authority. The Estonian authority is the Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, aki.ee. You may also complain to the authority in your own EU or EEA country of residence. We would rather hear from you first, but nothing here requires you to contact us before contacting them.

10. Changes to this policy

If this policy changes, the revised version is published here with a new review date and a new build identifier. Both are shown at the top of this page and in the footer of every page. If you have been sent an assessment of this site that quotes wording you cannot find above, check the build identifier against /version.php before assuming the page has not been corrected — a cached copy is the usual explanation.

Material changes affecting people who have already contacted us are notified by e-mail to the address they used.

11. Questions

Anything in this policy that is unclear, or appears not to match what the site actually does, should go to info@3a-services.net. A mismatch between this page and the live site is a defect worth reporting and we will correct it.