Privacy Notice

  1. THE IMPORTANT PART

1.1. Your privacy is important to us. This privacy policy explains how PlanBforBreakfast OÜ (“we” or “our” or “us”) collects and processes the personal data of the visitors of the planbfornow.com website and of the company’s clients.

1.2. This Privacy Notice concerns you when you are viewing the website or are a prospective or actual client of PlanBforBreakfast. We will refer to any visitor and client as “you”, “your” or the “data subject”.

1.3. We are a data controller for all information that is processed when you visit our website or when you use any of our services. This means that we are responsible for making clear what is the purpose of processing your personal data and how is it done.

1.4. Whenever we amend this Notice, the changes will be published here on our website.

  1. CATEGORIES OF PERSONAL DATA

2.1. We may process the following categories of personal data of you as the data subject:

2.1.1. Client contact data:

2.1.1.1. First name and surname

2.1.1.2. Position

2.1.1.3. Company

2.1.1.4. Email address

2.1.1.5. Phone number

2.1.2. Client identification data:

2.1.2.1. Personal identification number (ID-code)

2.1.3. Client service data:

2.1.3.1. Content of the requested services

2.1.3.2. Communication with the Client

2.1.4. Client contract and transaction data:

2.1.4.1. Agreements related to the client(s)

2.1.4.2. Payment account details

2.1.4.3. Payment transaction details

2.1.5. Website usage data:

2.1.5.1. visitor’s external/public IP-address or corresponding hostname

2.1.5.2. visitor’s web browser user-agent string.

2.2. We do not wish to process any other categories of data. Therefore, we will delete all other kinds of data if it is, for any reason, submitted by the data subject.

  1. PURPOSE FOR COLLECTING PERSONAL DATA

3.1 Processing for the performance of the contract - we process your personal data to sign a contract with our clients and to fulfil that contract. To do that, we will process all of the data categories mentioned above. We include the following activities under “the performance of the contract”:

3.1.1. Establishing a contract

3.1.2. Developing an existing contract relationship

3.1.3. Identifying you as a client

3.1.4. Sending encrypted files using Estonian DigiDoc software

3.1.5. Delivering the service we agreed on in the contract, or deliver any additional support.

3.2. Processing based on the legitimate interest - we process all of the data categories mentioned above for “the legitimate interest”, which includes the following activities:

3.2.1. Managing information security, responding to security incidents and preventing data breaches

3.2.2. Answering your inquiries about PlanBforBreakfast OÜ.

  1. HOW DO WE PROCESS YOUR PERSONAL DATA

4.1. All data is processed in electronic format

4.2. You, the data subject(s), are instructed to read this Privacy Notice when we establish contact with you

4.3. We process the data subject’s personal data in accordance with the requirements of the GDPR

4.4. On our homepage, we do not use:

4.4.1. Cookies

4.4.2. Automated decision-making system for marketing activities

4.4.3. Visitor profiling for marketing activities

4.5. We set up the following retention policies for the personal data:

4.5.1. 15 years for personal data related to security incidents or data breaches

4.5.2. 10 years for personal data needed for the performance of the contract (started from the end of the financial year)

4.5.3. 1 year for web server statistical report of top visitors and their request counts

4.5.4. 3 months for web server logs.

4.6 We are not obliged to preserve the personal data of the data subjects longer as indicated above, unless required by applicable law.

  1. PROCESSORS

5.1 We are the controller and may be using the following processors for processing the data:

5.1.1. PlanBforBreakfast IT infrastructure service providers

5.1.2. PlanBforBreakfast expert partners.

  1. YOUR RIGHTS

6.1. You as the data subject are entitled, at any time and in accordance with GDPR, to:

6.1.1. Request information about your personal data processing

6.1.2. Request access to or copy of your personal data

6.1.3. Rectify inaccurate or incomplete personal data

6.1.4. Request that we erase your personal data.

6.2. In order to exercise these rights, the data subject shall forward respective applications to info@planbfornow.com.

  1. SECURITY OF YOUR PERSONAL DATA

7.1. We implement organisational, physical and technical security controls to make sure that your personal data is secure.

7.2. If you have concerns about any suspicious activity related to the confidentiality, integrity or availability of the data of you or other data subjects, please contact us on info@planbfornow.com.

7.3. We will promptly notify you of any information we have about a personal data breach that concerns you. In doing that, we will communicate in clear and plain language the nature of the breach and describe the likely consequences. We will also explain measures to limit the negative effects of the event for the data subject(s).

  1. TRANSFERRING OR DISCLOSING YOUR PERSONAL DATA

8.1. We will not forward, sell or disclose the personal data to third parties without informing you (please look at what processors we use in the section 5. PROCESSORS).

8.2. There may be circumstances when we are required to disclose personal data by law or governmental authorities. This is done in accordance with the GDPR.

  1. CONTACTS

9.1. The best way to contact us for any data protection related inquiry is the email: info@planbfornow.com.

9.2. Feel free to pass us encrypted emails with PGP using the public key fingerprint: have to find the fingerprint

9.3. Other contact details of us as the data controller are available here.

  1. COMPLAINTS

10.1. All your complaints and comments are welcome to us in the first hand. If you still wish to exercise your right to lodge a complaint to the supervisory authority, here are the contacts of Estonian Data Protection Inspectorate: www.aki.ee/en/contacts.

This policy is effective as of 1st January 2021