AVAL Holdings
Language
/ Legal

Privacy policy

Last updated · July 2026

This Privacy Policy explains how AVAL Holdings OÜ processes personal data in connection with this website and related business communications, in accordance with Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) and other applicable data-protection laws.

§ 01

1. Data controller

The controller within the meaning of Article 4(7) GDPR is:

AVAL Holdings OÜ, registry code 17446786, registered office at Narva mnt 5, 10117 Tallinn, Estonia (hereinafter "AVAL", "we", "us" or "our").

For any request or enquiry relating to the processing of your personal data, please contact us at hello@aval.holdings. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR.

§ 02

2. Categories of personal data

We process the following categories of personal data:

  • Identification and contact data — name, surname, email address, telephone number, position and employer, when voluntarily provided by you through any contact channel.
  • Communication content — the content of your enquiries, messages, attachments and any subsequent correspondence.
  • Technical and log data — IP address, browser type and version, operating system, referring URL, date and time of access, requested resources, and similar server-log information automatically collected by our hosting infrastructure.
  • Contractual and financial data — where you enter into a business relationship with us, data strictly necessary to conclude and perform such relationship, including invoicing details.

We do not knowingly collect special categories of personal data within the meaning of Article 9 GDPR through this website.

§ 03

3. Purposes and legal bases

We process personal data on the following legal bases under Article 6(1) GDPR:

  • Legitimate interests (Art. 6(1)(f) GDPR) — to respond to enquiries, manage and develop business relationships, ensure the security, integrity and availability of the website, prevent fraud and enforce our legal claims.
  • Contractual necessity (Art. 6(1)(b) GDPR) — where processing is necessary to take steps at your request prior to entering into a contract or to perform a contract to which you are a party.
  • Legal obligation (Art. 6(1)(c) GDPR) — to comply with statutory obligations, in particular under the Estonian Accounting Act, tax legislation, anti-money- laundering rules and other mandatory EU and national law.
  • Consent (Art. 6(1)(a) GDPR) — where you have provided explicit consent for a specific purpose, which you may withdraw at any time with effect for the future.
§ 04

4. Recipients and processors

Personal data is accessible only to authorised personnel bound by confidentiality obligations. We may share personal data with:

  • IT service providers, including hosting, email and infrastructure providers, acting as processors under data-processing agreements pursuant to Article 28 GDPR;
  • professional advisors, including auditors, lawyers, notaries and tax consultants, bound by statutory professional secrecy;
  • public authorities and courts, where required by mandatory law or in order to establish, exercise or defend legal claims.

We do not sell personal data, and we do not use it for automated individual decision-making, including profiling, that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR.

§ 05

5. International data transfers

Personal data is processed primarily within the European Economic Area (EEA). Where processing involves a transfer of personal data to a country outside the EEA, we ensure that an appropriate level of protection is provided in accordance with Chapter V GDPR, in particular by relying on:

  • an adequacy decision of the European Commission; or
  • Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented where necessary by additional technical and organisational safeguards.

You may request a copy of the applicable safeguards by contacting us at the address indicated above.

§ 06

6. Retention periods

Personal data is retained only for as long as necessary to achieve the purposes for which it was collected and to comply with statutory obligations. In particular:

  • general business correspondence — up to three (3) years from the last substantive contact;
  • contractual and accounting documentation — up to seven (7) years, in accordance with § 12 of the Estonian Accounting Act;
  • data required to establish, exercise or defend legal claims — until the expiry of the applicable limitation period, plus a reasonable buffer.

Once retention is no longer required, personal data is either securely deleted or irreversibly anonymised.

§ 07

7. Security of processing

We implement appropriate technical and organisational measures in accordance with Article 32 GDPR to ensure a level of security appropriate to the risk, including encryption of data in transit (TLS), strict access controls, logging, regular software updates, secured infrastructure and confidentiality obligations for all personnel and processors.

§ 08

8. Your rights as a data subject

Subject to the conditions of the GDPR, you have the right to:

  • request access to your personal data (Art. 15 GDPR);
  • request rectification of inaccurate data (Art. 16 GDPR);
  • request erasure of your personal data ("right to be forgotten", Art. 17 GDPR);
  • request restriction of processing (Art. 18 GDPR);
  • receive your data in a structured, commonly used and machine-readable format and transmit it to another controller (Art. 20 GDPR);
  • object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 21 GDPR);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal (Art. 7(3) GDPR).

You also have the right to lodge a complaint with a competent supervisory authority, in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), without prejudice to any other administrative or judicial remedy.

§ 09

9. Provision of data

The provision of personal data is neither a statutory nor a contractual requirement, unless expressly indicated. However, certain functionalities of the website — in particular the ability to contact us — require the provision of at least a valid email address and a message. Failure to provide such data means we will not be able to respond to your enquiry.

§ 10

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities or in the applicable legal framework. The current version is always available on this page, indicating the date of the last update. Material changes will be communicated by appropriate means where required by law.