Privacy Policy
Last updated: March 2026
1. Introduction
This privacy policy describes how 27kay.com - operated by 27kay OÜ ("we", "us", "our company") - collects, uses, and protects personal data you provide when using our website and services.
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and applicable Estonian law.
2. Data We Collect
Data provided by you
When you fill out the contact form on our website, we collect:
- Name
- Email address
- Company name (optional)
- Message content
Automatically collected data
We use Plausible Analytics - a fully GDPR-compliant web analytics service. Plausible does not use cookies, does not collect personal data, and does not track visitors across websites. The collected data includes only aggregate website visit statistics.
3. How We Use Data
We use the collected data solely to:
- Respond to your inquiries and communicate with you
- Provide the services you have requested
- Improve our website based on aggregate statistics
4. Legal Basis
We process your personal data on the following legal bases:
- Consent - when you fill out and submit the contact form
- Legitimate interest - to improve our services and website
- Contractual obligation - to provide the services you have requested
5. Third-Party Sharing
Contact form data is processed through Formspree - a form processing service. Formspree processes data in accordance with their terms of service and privacy policy.
We do not sell or share your personal data with third parties for marketing purposes.
6. Data Retention
We retain your personal data only for the period necessary for the purposes for which it was collected. Contact form data is retained for up to 12 months, unless longer retention is required to fulfill contractual obligations.
7. Your Rights
Under the GDPR, you have the right to:
- Access your personal data
- Rectification of inaccurate data
- Erasure of your data ("right to be forgotten")
- Restriction of processing
- Data portability
- Object to processing
- Withdraw consent at any time
To exercise your rights, please contact us via the contact form.
8. Cookies
Our website does not use cookies. Plausible Analytics works without cookies and does not require a cookie consent banner.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or destruction.
10. Policy Changes
We reserve the right to update this privacy policy. All changes will be published on this page with an updated date.
11. Contact
If you have questions about this privacy policy or the processing of your personal data, please contact us via the contact form.