Skip to content

Privacy policy

Last updated 2026-09-20

This page explains what personal data Estonian Companies handles, why, and which rights you have. It covers two groups: people who could be affected by the company pages, and people who visit the site or write to us.

Who is responsible

The controller is Ökrös László EV., a sole proprietorship in Hungary. The controller is established in the European Union, so the General Data Protection Regulation (GDPR) applies to everything described here, including data about companies and people in Estonia. The way to reach us is the contact form. Choose the topic that fits: general question, data correction or removal request.

1. Company data

Source

Company pages are built from open data of the e-Business Register (Centre of Registers and Information Systems, RIK) and of the Estonian Tax and Customs Board (EMTA). The datasets, the download dates and the rules for selecting companies are ondata sources and methodology. We take no data from other sources and we do not contact the companies.

Companies and persons

A company is a legal person, and data about it is not personal data. The site publishes registered companies only. Sole proprietors (FIE) are excluded completely, because their records are about one individual. The register and tax data also list persons in other roles, such as board members, shareholders and beneficial owners. We do not download the files that hold that data, and no page shows a person's name in that role.

Two situations can still touch a person, and we treat them as personal data cases.

If either applies to you, you can object and we remove the page. See "Your rights" below.

What a company page shows

The registry code, name, legal form, VAT number, status, county and settlement, the main activity code, annual report figures and quarterly tax, turnover and employee figures. The full street address is shown only for a public limited company (AS) and for companies with at least 10 employees, because a registered office can be a private home. We never show phone numbers, e-mail addresses, websites, the text of representation rights or board members.

Purpose and legal basis

The purpose is to help buyers, suppliers, investors, journalists and job seekers check a company's basic facts and financial trend in a form that is easier to read than the raw files. The legal basis for the cases where a page can concern a person is our legitimate interest and the interest of these readers, GDPR Article 6(1)(f). We have carried out and documented a balancing test. You can ask for a copy through the contact form.

Information under Article 14

We do not contact the people concerned, since we hold no contact details for them and the data is already public in the register. This page is the information we owe them, and it is linked from the footer of every page. Every company page repeats the removal option.

How long we keep it

A company page exists while the source publishes the company as active and it meets the selection rules. Each refresh rebuilds the data from the current source files, so data that a source no longer publishes disappears from the site at the next refresh. A page that disappears returns a "not found" response and is not redirected to another company.

If you ask for removal, we keep the registry code, the date and an internal reference on a removal list for as long as the site operates. The list stops the next refresh from creating the page again. It holds no name and no e-mail address.

Your rights

2. Visitors

The site sets no cookies. The search runs in your browser. It fetches one small file of company names, chosen by the first three characters you type, so those three characters are part of the file address that reaches our server. We do not keep a record of them beyond the hosting logs described below.

Our hosting provider, Cloudflare, processes your IP address, your browser's user agent and the pages you request, to deliver the site and to defend it against abuse. It keeps these logs under its own retention rules. The legal basis is our legitimate interest in running a secure site (Article 6(1)(f)).

We measure visits with Cloudflare Web Analytics. It sets no cookies and does not track you across sites. It reports page views, referrers and country to us in aggregate.

The site shows no advertising today. Before we add any, we will update this policy and ask for consent from visitors in the EEA, the UK and Switzerland.

3. Contact form

When you use the form we process your name, your e-mail address, the topic, your message and the country your connection comes from. We use them only to answer you and to do what you asked, such as a correction or a removal. The legal basis is our legitimate interest in answering enquiries (Article 6(1)(f)). For a removal request it is also our legal obligation to act on the request (Article 6(1)(c)).

To stop automated abuse, the form uses Cloudflare Turnstile, which checks that a person is filling it in, and a limit of three messages per five minutes for each IP address. The limit counter holds the IP address for five minutes.

A copy of the message is stored in Cloudflare's storage for 12 months, and then it is deleted automatically. The message also arrives in our mailbox, which is hosted by Google. We delete the message and your contact details from the mailbox 12 months after the request is closed. After a removal request, only the removal-list entry remains.

Who receives data

Company pages are public, so anyone can read them and search engines can list them. We use two processors. Cloudflare, Inc. provides hosting, the content delivery network, Web Analytics, Turnstile, e-mail forwarding and the storage for the contact form. Google LLC hosts the mailbox that receives the messages.

Transfers outside the EU

Both processors are in the United States and are certified under the EU-U.S. Data Privacy Framework. The European Commission has found that framework to provide an adequate level of protection (Article 45).

Complaints

You can complain to the data protection authority of the EU country where you live or work. Our lead authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9-11, Hungary; postal address 1363 Budapest, Pf. 9; ugyfelszolgalat@naih.hu;naih.hu. For a company in Estonia you can also contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): Tatari 39, 10134 Tallinn, Estonia;info@aki.ee; aki.ee. The right to complain does not depend on where you live. We would like the chance to fix the problem first, through the contact form.

Changes

When this policy changes, the date at the top changes with it. A change that affects the people concerned, such as publishing a new type of data, is made here before the data goes live.