Privacy Policy
Last updated: March 2026
1. Introduction
This privacy policy describes how aims.consulting - a trade name of 27kay OÜ ("we", "us", "our company") - collects, uses, and protects the personal data you provide when using our website and services.
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and applicable Estonian and EU legislation.
2. What data we collect
Data you provide
When you fill out the contact form on our website, we collect:
- Name
- Email address
- Company name (optional)
- Message content
Automatically collected data
We use Plausible Analytics - a fully GDPR-compliant web analytics service. Plausible does not use cookies, does not collect personal data, and does not track visitors across websites. The collected data includes only aggregate website visit statistics.
3. How we use data
We use the collected data solely for:
- Responding to your inquiries and communicating with you
- Providing the services you have requested
- Improving our website based on aggregate statistics
4. Legal basis for processing
We process your personal data on the following legal bases:
- Consent - when you fill out and submit the contact form
- Legitimate interest - for improving our services and website
- Contractual obligation - for providing the services you have requested
5. Third-party data sharing
Contact form data is processed through Formspree - a form processing service. Formspree processes data in accordance with their terms of service and privacy policy.
We do not sell or share your personal data with third parties for marketing purposes.
6. Data retention
We retain your personal data only for the period necessary for the purposes for which it was collected. Contact form data is retained for up to 12 months, unless a longer period is required to fulfill contractual obligations.
7. Your rights
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
To exercise your rights, please contact us via the contact form.
8. Cookies
Our website does not use cookies. Plausible Analytics operates without cookies and does not require a cookie consent banner.
9. Data security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or destruction.
10. Changes to this policy
We reserve the right to update this privacy policy. Any changes will be published on this page with an updated date.
11. Contact
If you have questions about this privacy policy or the processing of your personal data, please contact us via the contact form.