Legal
Privacy Policy
How 021 OÜ collects, uses, stores and deletes personal data. Last updated 11 August 2026.
1. Who is responsible for your data
The controller for personal data collected through zero21ou.com is 021 OÜ, an Estonian Osaühing (private limited company) with registry code 11728851 and EU VAT number EE101488194, registered at Kaupmehe tn 7-115, 10144 Tallinn, Kesklinna linnaosa, Harju maakond, Estonia.
For any question about this policy or to exercise a right described below, write to admin@zero21ou.com or call +372 5123-4567. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; requests go to the address above and are handled by a director.
2. What we collect, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Consultation request: company name, contact name, business email, optional phone, the scope selections you made, and your project description | To assess the request, reply to it, and prepare a proposal | Art. 6(1)(b) — steps at your request prior to a contract | 24 months from the last contact |
| Contact form: name, email, optional company, subject, message | To answer your message | Art. 6(1)(f) — our legitimate interest in responding to enquiries | 12 months |
| Server access logs: IP address, timestamp, requested URL, user agent, response status | Security, abuse prevention and fault diagnosis | Art. 6(1)(f) — legitimate interest in running a secure service | 14 days |
| Rate-limit counters: a salted SHA-256 hash of your IP address and a request count | To stop automated abuse of the forms | Art. 6(1)(f) — legitimate interest in preventing spam | Up to 24 hours |
| Contract and invoicing records for clients | Performing the engagement and meeting accounting obligations | Art. 6(1)(b) and Art. 6(1)(c) — contract and legal obligation | 7 years (Estonian Accounting Act) |
We do not collect special categories of data through this website, we do not profile visitors, and we make no automated decisions producing legal effects.
3. What this website does not do
- No advertising, marketing or analytics cookies are set. No cookies at all are set by us.
- No third-party scripts, fonts, maps, chat widgets, pixels or embeds are loaded. Fonts are served from our own domain, so your browser makes no request to any other party while reading this site.
- We do not sell, rent or share personal data for anyone else’s marketing purposes. Ever.
- We do not send unsolicited marketing email. You will hear from us only in reply to your message.
The one item stored in your browser is a local key recording that you dismissed our privacy notice. It is listed in full in the Cookie Policy.
4. When we act as a processor for our clients
During an engagement we may access personal data held in a client’s systems. In that relationship the client is the controller and 021 OÜ is a processor. We sign an Article 28 data processing agreement before access is granted, and under it:
- we process personal data only on the client’s documented instructions;
- engineers are bound by written confidentiality obligations;
- production data is not copied to developer machines — test environments use anonymised data;
- sub-processors are named in advance and may be objected to;
- access is revoked and working copies destroyed at the end of the engagement, on request in writing.
5. Who else can see your data
Our sub-processors for this website are limited to:
- Hosting provider. Our servers are located inside the European Union. Access logs and database contents reside there.
- Email provider. Notification and reply email for zero21ou.com is handled by an EU-based mail provider.
The current provider names are available on request to admin@zero21ou.com. We do not transfer personal data outside the European Economic Area for the operation of this website. Where a client engagement requires a transfer, it is covered in that engagement’s data processing agreement using Standard Contractual Clauses.
6. How your data is protected
- All traffic is served over HTTPS; plain HTTP is redirected.
- Form submissions are validated server-side and written using prepared statements.
- Access to the database and to the server is limited to named administrators using key-based authentication.
- Rate limiting and honeypot fields protect the forms without profiling you.
- Retention periods above are enforced by scheduled deletion, not by manual housekeeping.
Our controls are modelled on ISO/IEC 27001 Annex A. 021 OÜ is not certified to ISO/IEC 27001 and does not claim to be.
7. Your rights
Under the GDPR you may:
- request access to the personal data we hold about you;
- have inaccurate data corrected;
- have data erased where we have no continuing legal basis to keep it;
- ask us to restrict processing while a dispute is resolved;
- receive the data you gave us in a portable, machine-readable format;
- object to processing based on our legitimate interests.
Write to admin@zero21ou.com. We respond within one month. We ask for enough information to confirm your identity and nothing more.
If you are not satisfied with our answer you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, www.aki.ee/en, or to the supervisory authority in your own EU country of residence.
8. Changes to this policy
Material changes are published on this page with a new date at the top. This version is dated 11 August 2026. If a change affects how we process data you have already given us, we contact you before it takes effect.