Privacy policy
Last updated 2026-09-20
This page explains what personal data Estonian Companies handles, why, and which rights you have. It covers two groups: people who could be affected by the company pages, and people who visit the site or write to us.
Who is responsible
The controller is Ökrös László EV., a sole proprietorship in Hungary. The controller is established in the European Union, so the General Data Protection Regulation (GDPR) applies to everything described here, including data about companies and people in Estonia. The way to reach us is the contact form. Choose the topic that fits: general question, data correction or removal request.
1. Company data
Source
Company pages are built from open data of the e-Business Register (Centre of Registers and Information Systems, RIK) and of the Estonian Tax and Customs Board (EMTA). The datasets, the download dates and the rules for selecting companies are ondata sources and methodology. We take no data from other sources and we do not contact the companies.
Companies and persons
A company is a legal person, and data about it is not personal data. The site publishes registered companies only. Sole proprietors (FIE) are excluded completely, because their records are about one individual. The register and tax data also list persons in other roles, such as board members, shareholders and beneficial owners. We do not download the files that hold that data, and no page shows a person's name in that role.
Two situations can still touch a person, and we treat them as personal data cases.
- A company name that contains a person's name, for example a company named after its founder. The name is the registered name of the legal person, and we publish it as such.
- A company with a single owner, where the company's figures say something about the owner's finances.
If either applies to you, you can object and we remove the page. See "Your rights" below.
What a company page shows
The registry code, name, legal form, VAT number, status, county and settlement, the main activity code, annual report figures and quarterly tax, turnover and employee figures. The full street address is shown only for a public limited company (AS) and for companies with at least 10 employees, because a registered office can be a private home. We never show phone numbers, e-mail addresses, websites, the text of representation rights or board members.
Purpose and legal basis
The purpose is to help buyers, suppliers, investors, journalists and job seekers check a company's basic facts and financial trend in a form that is easier to read than the raw files. The legal basis for the cases where a page can concern a person is our legitimate interest and the interest of these readers, GDPR Article 6(1)(f). We have carried out and documented a balancing test. You can ask for a copy through the contact form.
Information under Article 14
We do not contact the people concerned, since we hold no contact details for them and the data is already public in the register. This page is the information we owe them, and it is linked from the footer of every page. Every company page repeats the removal option.
How long we keep it
A company page exists while the source publishes the company as active and it meets the selection rules. Each refresh rebuilds the data from the current source files, so data that a source no longer publishes disappears from the site at the next refresh. A page that disappears returns a "not found" response and is not redirected to another company.
If you ask for removal, we keep the registry code, the date and an internal reference on a removal list for as long as the site operates. The list stops the next refresh from creating the page again. It holds no name and no e-mail address.
Your rights
- Objection (Article 21) and erasure (Article 17). If a page concerns you, ask for its removal through the contact form with the topic "Removal request", and name the company or its registry code. You do not need to give a reason. We remove the page, its entries in lists and in the search, and add the registry code to the removal list, within 30 days.
- Access (Article 15). Everything we hold about a company is on its page, apart from a removal-list entry. We confirm this in writing on request.
- Rectification (Article 16). If a page differs from the current source record, we correct it. If the source record is wrong, it has to be corrected with the register or the tax board.
- Restriction (Article 18). While we check a disputed page, we take it offline if you ask.
2. Visitors
The site sets no cookies. The search runs in your browser. It fetches one small file of company names, chosen by the first three characters you type, so those three characters are part of the file address that reaches our server. We do not keep a record of them beyond the hosting logs described below.
Our hosting provider, Cloudflare, processes your IP address, your browser's user agent and the pages you request, to deliver the site and to defend it against abuse. It keeps these logs under its own retention rules. The legal basis is our legitimate interest in running a secure site (Article 6(1)(f)).
We measure visits with Cloudflare Web Analytics. It sets no cookies and does not track you across sites. It reports page views, referrers and country to us in aggregate.
The site shows no advertising today. Before we add any, we will update this policy and ask for consent from visitors in the EEA, the UK and Switzerland.
3. Contact form
When you use the form we process your name, your e-mail address, the topic, your message and the country your connection comes from. We use them only to answer you and to do what you asked, such as a correction or a removal. The legal basis is our legitimate interest in answering enquiries (Article 6(1)(f)). For a removal request it is also our legal obligation to act on the request (Article 6(1)(c)).
To stop automated abuse, the form uses Cloudflare Turnstile, which checks that a person is filling it in, and a limit of three messages per five minutes for each IP address. The limit counter holds the IP address for five minutes.
A copy of the message is stored in Cloudflare's storage for 12 months, and then it is deleted automatically. The message also arrives in our mailbox, which is hosted by Google. We delete the message and your contact details from the mailbox 12 months after the request is closed. After a removal request, only the removal-list entry remains.
Who receives data
Company pages are public, so anyone can read them and search engines can list them. We use two processors. Cloudflare, Inc. provides hosting, the content delivery network, Web Analytics, Turnstile, e-mail forwarding and the storage for the contact form. Google LLC hosts the mailbox that receives the messages.
Transfers outside the EU
Both processors are in the United States and are certified under the EU-U.S. Data Privacy Framework. The European Commission has found that framework to provide an adequate level of protection (Article 45).
Complaints
You can complain to the data protection authority of the EU country where you live or work. Our lead authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9-11, Hungary; postal address 1363 Budapest, Pf. 9; ugyfelszolgalat@naih.hu;naih.hu. For a company in Estonia you can also contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): Tatari 39, 10134 Tallinn, Estonia;info@aki.ee; aki.ee. The right to complain does not depend on where you live. We would like the chance to fix the problem first, through the contact form.
Changes
When this policy changes, the date at the top changes with it. A change that affects the people concerned, such as publishing a new type of data, is made here before the data goes live.