Legal
Privacy Policy
Last updated: 9 June 2026
1. The short version
This website collects very little. We don't run advertising trackers, we don't sell data, and the main personal data we receive is what you choose to send us when you get in touch. This policy explains the details, as required by the EU General Data Protection Regulation (GDPR).
2. Who is responsible for your data
The data controller is SanSoft OÜ, registered office at Sepapaja tn 6, Lasnamäe linnaosa, Tallinn, Harju maakond, 15551, Estonia. For anything related to your personal data, write to info@sansoftai.com.
3. What we collect and why
Contact enquiries. The contact form on this website opens a draft in your own email client - nothing is stored on our servers when you fill it in. When you send the email, we receive the details you included: typically your name, email address, company, and your message. We use this data to answer you and to discuss a possible project. The legal basis is our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR) and, where the enquiry leads towards a contract, taking steps prior to entering into one (Art. 6(1)(b) GDPR).
Server logs. Like almost every website, our hosting provider records standard technical logs (IP address, browser type, pages requested, timestamps) for security and troubleshooting. The legal basis is our legitimate interest in keeping the website secure and available (Art. 6(1)(f) GDPR).
4. Cookies
This website does not set advertising or analytics cookies. If that changes, we will update this policy and ask for consent where the law requires it.
5. Who we share data with
We do not sell or rent personal data. We share it only with:
- service providers we use to run the website and our email (hosting and email infrastructure), bound by data processing agreements;
- authorities, where the law requires us to.
Where a provider processes data outside the European Economic Area, we rely on safeguards recognised by the GDPR, such as adequacy decisions or standard contractual clauses.
6. How long we keep data
Enquiry correspondence is kept for as long as the conversation is live and up to three years afterwards, so we have context if you come back to us. Correspondence connected to a signed contract is kept for seven years, in line with Estonian accounting requirements. Server logs are kept for a short rolling period set by our hosting provider.
7. Your rights
Under the GDPR you can ask us to:
- tell you what personal data we hold about you (access);
- correct inaccurate data (rectification);
- delete your data (erasure), where we have no legal duty to keep it;
- limit how we use it (restriction);
- hand it over in a portable format (data portability);
- stop processing based on legitimate interest (objection).
Write to info@sansoftai.com and we will respond within one month. If you believe we have handled your data unlawfully, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority in your own EU country.
8. Security
The website is served over HTTPS, and access to enquiry correspondence is limited to the people who need it to reply. No system is perfectly secure, but we keep the amount of personal data we hold deliberately small - data we never collect is data that cannot leak.
9. Changes to this policy
If we change how we handle personal data - for example, by adding analytics or a server-side contact form - we will update this page and its "last updated" date before the change takes effect.