Privacy Policy

Your privacy is important to Gerlyn Tiigemäe, and we are committed to complying with all applicable laws and regulations regarding any personal data that may be collected about you when you visit the website gerlyntiigemae.ee or interact with us as a representative of a client, partner, or potential client.

With this privacy policy, we want to explain what data we collect, how we use it, and what rights you have to protect your data. This privacy policy applies both to visitors of the website gerlyntiigemae.ee and to the contact persons of our clients, partners, and potential clients whose data we process in the course of providing services, preparing offers, and managing business relationships.

The controller of your data is Gerlyn Tiigemäe (Finnable OÜ), e-mail: gerlyn@tiigemae.ee

We collect and process information in accordance with the European Union General Data Protection Regulation (GDPR).

Data collection and use

What data we collect

The information we collect includes both information that you knowingly and actively provide to us when using or participating in our services or campaigns, and information that your devices send when accessing our products and services.

Your personal data may reach us in the following ways:

  • When you contact us by phone, e-mail, or online chat
  • When you browse the website gerlyntiigemae.ee
  • When you comment on, like, or share a post on our social media account
  • When you subscribe to our newsletter
  • When you comment on posts on our website
  • When you interact with us as a representative of a client, partner, or potential client (offers, contracts, meetings, trainings)
  • When you participate in a meeting organised by us that is recorded and transcribed with prior notice

Types of data collected

Personal data

We only ask for personal information when it is necessary to provide you with a service. When visiting our website or contacting us, you may share the following information with us:

  • First and last name
  • E-mail address

For contact persons of clients and partners, we may additionally process job title, employer information, phone number, and the content of our communication. This is described in more detail in the chapter “Processing of client and partner contact person data”.

Log files

Our website gerlyntiigemae.ee stores log files about its visitors. The information collected may include:

  • Type of device used
  • Internet Protocol (IP) address
  • Browser type
  • Internet service provider (ISP)
  • Date and time of the website visit
  • Entry and exit pages and the number of clicks made on the website

The information in log files is used to analyse trends, administer the website, track visitor activity, and gather demographic information. This information is not intended to, and does not, identify individuals.

Cookies

Like most websites, gerlyntiigemae.ee uses cookies. A cookie is essentially a text file that is stored on the user’s device when visiting a website. Cookies are used to set and store preferences, regional settings, service usage choices, and more.

If you wish, you can disable cookies in your browser settings, but in that case the service provided to you may be disrupted.

Cookies are divided into persistent and session cookies. Persistent cookies remain on your personal computer or mobile device even after you have closed your browser or computer. Session cookies are deleted immediately after the browser is closed.

By purpose, cookies are divided into:

  • Necessary cookies. Session cookies whose purpose is to enable you to use the services offered on our website. These cookies help authenticate users and prevent malicious use of user accounts. Without these cookies, we cannot provide you with the services you request.
  • Notification cookies. These cookies identify whether users have accepted the use of cookies on the website.
  • Functionality cookies. These cookies allow your browser to remember choices you make when using the website, such as saving your login details or language preferences. The purpose of these cookies is to provide you with a more personalised experience and to avoid re-entering your preferences.

How we use data

We may use the collected information for various purposes, including:

  • To maintain, manage, develop, personalise, and expand our website
  • To collect statistics so that we can offer better services and/or offers and understand and analyse the behaviour of our website visitors
  • To identify you by phone, message, or e-mail
  • To send you information and ask for feedback about our services
  • To prevent fraud and protect our website
  • To enable us to stay in contact with you via social media accounts
  • To enable reading of conversation history in order to speed up the provision of relevant advice
  • To improve the quality of our service and offer more efficient browsing solutions
  • To develop new products and services or improve their functionality
  • To simplify and speed up our interactions when you contact us
  • For other purposes, such as analysing data, researching trends, and evaluating the effectiveness of our advertising campaigns

Processing of client and partner contact person data

In addition to website visitor data, we process the data of contact persons of our clients, partners, and potential clients. This may include:

  • first and last name, job title, and employer
  • contact details (e-mail address, phone number)
  • the content of our communication (e-mails, offers, contracts)
  • meeting notes, recordings, and their transcriptions, where recording has been announced in advance
  • information related to participation in trainings and services

We generally receive this data directly from you, from your employer or colleagues, or from public sources (e.g. company website, business register, LinkedIn).

We process this data for the following purposes and on the following legal bases:

  • preparation and performance of a contract (GDPR Art. 6(1)(b)): preparing offers, providing services, invoicing
  • legitimate interest (GDPR Art. 6(1)(f)): managing client relationships, preparing meeting summaries, developing services, and maintaining business communication
  • compliance with a legal obligation (GDPR Art. 6(1)(c)): for example, accounting and tax obligations

You have the right to object at any time to processing based on legitimate interest by writing to gerlyn@tiigemae.ee.

Use of AI tools in data processing

We use artificial intelligence tools as aids in our work (Anthropic Claude, OpenAI ChatGPT, Google Gemini, and Microsoft Copilot), including for preparing meeting summaries, offers, documents, and analyses. This means that your contact details and the content of our communication may reach the systems of these service providers, who act as our data processors.

When using AI tools, we follow these principles:

  • we use the services on business accounts and under terms according to which the data we enter is not used for training AI models
  • data processing is governed by the service providers’ standard data processing terms (Data Processing Addendum), which comply with the requirements of Article 28 of the GDPR
  • we only enter data into the tools that is necessary for the specific task and avoid entering special categories of personal data (e.g. health data)
  • where we process data on behalf of our client as a data processor, we use AI tools only in accordance with the terms of the contract concluded with the client

Transfer of data outside the European Union

Some of the service providers we use (including AI service providers) are located outside the European Economic Area, mainly in the United States. In such cases, we transfer data only in compliance with GDPR requirements: the service provider has joined the EU-U.S. Data Privacy Framework, or we have concluded the Standard Contractual Clauses approved by the European Commission.

When we may share your data

  • We may share or transfer your personal data in connection with a change of ownership, merger, sale of assets, financing, or acquisition of our company. We will notify you of the transfer of your personal data and if it becomes subject to the provisions of another privacy policy.
  • We may share your data with our affiliated companies, requiring them to comply with this privacy policy. Affiliated companies include our parent and subsidiary companies, joint venture partners, or companies owned by us.
  • We may share your data with our business partners in order to offer you certain products, services, or campaigns.
  • With your consent, we may disclose your personal data for any other purpose.
  • We are obliged to disclose your personal data if required by law. In good faith, we may also disclose your data to comply with a legal obligation, protect our rights or property, prevent or detect possible legal violations related to the use of our service, and ensure the safety of service users.

Retention of your personal data

The company retains your personal data only for as long as necessary for the purposes set out in this privacy policy. We retain and use your personal data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

We retain the data of client and partner contact persons for the duration of the business relationship and for up to three years after its end, based on the limitation period for claims. We retain accounting documents for seven years as required by law. We delete meeting recordings and transcriptions when they are no longer needed for preparing summaries or evidencing agreements.

The company also retains log files for internal analysis purposes. Log files are usually retained for a shorter period, except where this data is used to strengthen security or improve the functionality of our service, or where we are required by law to retain this data for a longer period.

Processing of children’s data

None of our products or services are directed at children under the age of 13, and we do not knowingly collect data from children under 13. If we suspect that we are processing the data of a person under 13, we will remove that person from all our databases.

Your rights to protect your data

You always have the right not to share your data with us, with the understanding that this may affect your experience on our website. If you choose not to share your data with us, we will not treat you any worse because of it. If you provide us with personal information, you understand that we collect, store, use, and disclose it in accordance with this privacy policy. You have the right to request details of the data collected about you.

If we receive personal information about you from a third party, we protect it in accordance with this privacy policy and the laws of the Republic of Estonia. If you share third-party data yourself, you confirm that you have the right and permission to do so.

Even if you have previously consented to sharing your personal data with us for marketing purposes, you retain the right to change your mind at any time. You always have the right to opt out of communication with us and to request that we remove your data from our databases. From time to time, we may also ask for information about you to verify your identity. If you find that the data we have collected about you is inaccurate, outdated, incomplete, irrelevant, or misleading, please contact us by e-mail: gerlyn@tiigemae.ee. We will do our best to correct inaccurate, incomplete, misleading, or outdated information.

If you believe that we have violated applicable data protection law and wish to file a complaint, please contact us using the contact details in this document and provide us with all details of the alleged violation. We will investigate your complaint promptly and respond to you in writing, setting out the results of the investigation and the steps we will take to resolve your complaint. You also have the right to contact the supervisory authority; in Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).

GDPR data protection rights

We want to make sure you are aware of all your data protection rights. Every data subject is entitled to the following:

  • Right of access. You have the right to request copies of your personal data.
  • Right to rectification. You have the right to request that we correct data you believe is inaccurate, and to request that we complete data you believe is incomplete.
  • Right to erasure. Under certain conditions, you have the right to request the erasure of your personal data.
  • Right to restriction of processing. Under certain conditions, you have the right to request the restriction of the use of your personal data.
  • Right to object. Under certain conditions, you have the right to object to the use of your personal data.
  • Right to data portability. Under certain conditions, you have the right to request that we transfer the collected data to a third party or directly to you.

Security of your data

The security of your personal data is important to us, but please remember that no method of transmitting information over the internet or method of electronic storage is one hundred percent secure. Although we do our utmost to protect your data, we cannot guarantee its complete security.

Finnable OÜ takes all reasonably necessary measures to ensure that your data is processed securely and in accordance with this privacy policy and the laws of the Republic of Estonia.

Links to other websites

Our website may contain links to other websites that are not owned by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly recommend that you review the privacy policy of every site you visit.

We have no control over third-party sites and assume no responsibility for their content, privacy policies, services, or anything else.

Updates to the privacy policy

Where necessary, we have the right to make changes to this privacy policy. After the privacy policy is updated, we will change the document revision date at the bottom of the policy. If you visit and use our website after the privacy policy has been updated, we will treat this as your implied consent to the changes.

Last updated 13/08/2026

Scroll to Top