Quick application

    Privacy Policy

    Last updated: 28 August 2026

    This Privacy Policy (hereinafter referred to as the “Policy”) sets out the principles and procedures governing the collection, processing, and protection of personal data of individuals using the website https://eurosert.eu (hereinafter referred to as the “Website”), requesting certification, training, or audit services, or communicating with EUROSERT OÜ.

    EUROSERT OÜ is committed to respecting your privacy and protecting your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation — GDPR) and the Personal Data Protection Act of the Republic of Estonia.

    The data controller responsible for the processing of your personal data is:

    • Company Name: EUROSERT OÜ
    • Registry Code: 16534270
    • Address: Meistri tn 6, Tallinn 13517, Harju County, Estonia
    • Email: info@eurosert.eu
    • Phone: +372 5531733
    • Official Website: https://eurosert.eu

    2. Categories of Personal Data We Collect and Process

    Depending on how you interact with EUROSERT OÜ, we may process the following categories of personal data:

    2.1. Information submitted via inquiry and application forms:

    • First and last name / Contact person name;
    • Name of represented company or organisation;
    • Email address;
    • Contact telephone number;
    • Field of certification or service requested (such as certification of metal structures under EN ISO 3834 and EN 1090, conformity assessment, personnel training, etc.);
    • Message content, comments, or technical documentation attached to your inquiry.

    2.2. Information processed during contract performance and service delivery:

    • Position and representation authority of company representatives;
    • Company details, billing information, and bank details;
    • Technical documentation required for certification, factory production control (FPC) audits, and surveillance inspections;
    • Communication history, audit reports, and certification decisions.

    2.3. Technical and website usage data:

    • IP address;
    • Web browser type and version, operating system;
    • Date, timestamp, and duration of page visits;
    • Language preferences (ET / RU / EN);
    • Cookie data.

    3. Purposes and Legal Bases for Data Processing

    We process personal data strictly on lawful grounds pursuant to Article 6 of the GDPR:

    Processing Purpose Data Categories Legal Basis (GDPR)
    Handling inquiries and requests (via “Quick Application”, contact forms, email) Name, contact details, company, inquiry text Article 6(1)(b) — taking steps at the request of the data subject prior to entering into a contract
    Execution and performance of contracts (certification, audits, training) Contact details, representative roles, technical audit data Article 6(1)(b) — performance of a contract
    Compliance with statutory and accreditation obligations (accounting, archiving, ISO/IEC 17065 conformity standards) Contractual, financial, and certification files Article 6(1)(c) — compliance with a legal obligation
    Website security, technical maintenance, and fraud prevention IP address, technical logs, necessary cookies Article 6(1)(f) — legitimate interest (ensuring cyber security and system reliability)
    User experience optimization and website analytics Functional and analytics cookies Article 6(1)(a) — consent of the data subject

    4. Data Sharing and Third-Party Processors

    EUROSERT OÜ does not sell, lease, or distribute your personal data to third parties for commercial or marketing purposes.

    We may disclose personal data only under the following circumstances:

    1. Authorized data processors (service partners): IT infrastructure and web hosting providers, email service providers, IT maintenance specialists, and accounting software vendors. All processors are bound by strict contractual confidentiality and data processing agreements in compliance with GDPR requirements.
    2. Accreditation and oversight bodies: such as the Estonian Accreditation Centre (Eesti Akrediteerimiskeskus – EAK) within the scope of regular surveillance audits and mandatory quality compliance inspections.
    3. Public authorities and law enforcement: only where required by applicable law and upon formal, lawful request.

    All personal data is stored and processed on secure servers located within the European Union (EU) and European Economic Area (EEA).


    5. Data Retention Periods

    Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws:

    • General inquiries and web form submissions (without contract conclusion): up to 3 years from the date of the last communication.
    • Contractual, accounting, and certification records: retained for 7 years pursuant to Estonian accounting legislation, or up to 10 years in compliance with accreditation rules for certification bodies.
    • Server logs and technical cookies: from 30 days up to 12 months.

    Upon expiration of the retention period, data is securely erased or permanently anonymized.


    6. Use of Cookies

    Our Website utilizes cookies — small text files placed on your device to ensure proper functionality and improve user experience.

    Cookie categories used:

    • Strictly Necessary (Technical) Cookies: Essential for the core operation of the website, security, language switching (Polylang), and form submission. These cookies do not require prior consent.
    • Functional Cookies: Remember user preferences (such as selected language and display settings).
    • Analytical Cookies (if enabled): Help gather anonymous statistics regarding website visits to improve navigation and content structure.

    Managing Cookies:

    You can manage or delete cookies at any time through your browser settings (Chrome, Firefox, Safari, Edge, etc.). Please note that disabling essential cookies may impact certain functionalities of the Website.


    7. Rights of Data Subjects

    Under the GDPR, you have the following rights regarding your personal data:

    • Right of Access (Article 15): The right to obtain confirmation as to whether your personal data is being processed and to receive a copy of that data.
    • Right to Rectification (Article 16): The right to request the correction of inaccurate or incomplete personal data.
    • Right to Erasure (“Right to be Forgotten”, Article 17): The right to request the deletion of your personal data under certain statutory conditions.
    • Right to Restriction of Processing (Article 18): The right to request the restriction of data processing in specified circumstances.
    • Right to Data Portability (Article 20): The right to receive your personal data in a structured, commonly used, and machine-readable format.
    • Right to Object (Article 21): The right to object to data processing based on our legitimate interests.
    • Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing.

    8. Exercising Your Rights and Supervisory Authority

    To exercise any of your data protection rights, please submit a written request to info@eurosert.eu. We will respond to your request within 30 calendar days of verifying your identity.

    If you consider that our processing of your personal data infringes your rights or violates data protection laws, you have the right to lodge a complaint with the competent supervisory authority:

      • Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon – AKI):

    9. Data Security

    EUROSERT OÜ implements appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. All data transmissions on the Website are protected using SSL/TLS encryption (HTTPS).


    10. Amendments to the Privacy Policy

    EUROSERT OÜ reserves the right to update this Privacy Policy from time to time to reflect changes in legal requirements or operational practices. The latest version will always be published on this page with the updated revision date.