ZAGROZA OÜ — zagroza.agency
Effective date: 27 August 2026 · Last updated: 27 August 2026 · Version: 1.0
ZAGROZA OÜ (“ZAGROZA”, “we”, “us”, “our”) is a private limited company incorporated in Estonia and entered in the Estonian Commercial Register under registry code 16971792, VAT number EE102743168, with its registered office at Kaupmehe tn 7-120, Kesklinna linnaosa, Tallinn, Harju maakond, 10114, Estonia. We trade as “ZAGROZA digital agency” and operate the website at zagroza.agency (the “Website”).
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what rights you have. It applies when you:
visit, browse or interact with the Website;
submit a contact form, project enquiry or call-booking request, or subscribe to our newsletter;
correspond with us by email, telephone or messaging applications;
are a client, prospective client, supplier, partner, or a representative or employee of one; or
view or click one of our advertisements.
For all of the above, ZAGROZA OÜ is the data controller within the meaning of Regulation (EU) 2016/679 (the “GDPR”), the Estonian Personal Data Protection Act and, where it applies, the UK GDPR.
This policy does not cover personal data held inside systems we build, host or maintain for our clients. In those engagements our client is the controller and we act as a processor on its documented instructions — see section 12.
Contact for privacy matters: [email protected], or by post to the registered address above.
We are not required to appoint a Data Protection Officer under Article 37 of the GDPR and have not appointed one. Privacy requests sent to the address above are handled by a responsible member of our team.
We have not appointed a representative in the United Kingdom under Article 27 of the UK GDPR, because we consider our processing of personal data relating to people in the United Kingdom to be occasional, not to involve special categories of data or criminal-offence data on a large scale, and unlikely to result in a risk to individuals’ rights and freedoms. If you are in the United Kingdom you can contact us directly at [email protected].
We are a business-to-business web development agency. Most of the personal data we handle is ordinary professional contact data: a name, a work email address, a company and a description of what you want built.
We do not sell personal data for money and we do not disclose it to data brokers. Our use of advertising cookies may nonetheless count as a “sale” or a “share” under some US state privacy laws — see section 10.4.
We use Google Analytics 4, Google Tag Manager and Google Ads to understand how our Website and our advertising perform.
You can ask us at any time what we hold about you, ask us to correct or delete it, or tell us to stop sending you marketing: [email protected].
Enquiry and contact data — your name, work email address, company name, job title, telephone number (if you provide one), country, preferred contact channel, and the content of your message.
Project data — the information you choose to share about your project: goals, budget range, timelines, existing systems, technical requirements, and any documents, links, briefs or files you attach or send us.
Call-booking data — the date and time you request for a call and any details you add to the request.
Newsletter data — your email address, and the language or topics you select, if you subscribe.
Client, partner and supplier data — contact details of the individuals who act for your organisation, contract and correspondence records, project documentation, invoicing and payment details, and referral-partner records.
Recruitment data — if you send us a CV or apply for a role, the information contained in your application and in our correspondence with you.
Technical data — IP address, device type, operating system, browser type and version, screen resolution, language settings and referring URL.
Campaign data — advertising and campaign parameters carried in the link you arrived through, such as utm_source, utm_medium, utm_campaign, utm_term, utm_content and Google click identifiers (gclid, gbraid, wbraid).
Usage data — the pages you view, the order in which you view them, time spent, and the interaction events we record through Google Tag Manager: page_view, menu_click, footer_link_click, hero_cta_click, external_link_click, content_view, content_click, contact_click, form_start, form_submit, newsletter_subscribe, generate_lead, booking_call_popup_open, 404_view, form_error and js_error, together with parameters such as page, link_name, location, form_name, content_type and content_name.
Approximate location — city- and country-level location inferred from your IP address. We do not collect precise GPS location.
Cookies and identifiers — see section 5.
Referral partners and clients — where someone introduces you to us, or a client shares the contact details of its team members so that we can work together.
Publicly available professional sources — where we contact an organisation about possible cooperation, we may use business contact information published on company websites, professional networks such as LinkedIn, business directories and public registers.
Advertising and analytics platforms — mostly aggregated and statistical reports about how our campaigns perform, and conversion measurement data.
We do not ask for and do not want to receive special categories of personal data (such as data about health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or sexual orientation), and we do not collect government identification numbers from Website visitors. We do not process payment card data — client payments are made by bank transfer against an invoice. Please do not send us this kind of information through our forms.
Your name, work email address and a description of what you want built are needed so that we can answer your enquiry, prepare a proposal and enter into a contract with you. If you do not provide them, we cannot deal with your request. Your telephone number, job title, country and any further project detail are optional, and there is no consequence if you leave them out. Once we are engaged, providing the details we need to issue a compliant invoice is a statutory requirement under the Estonian Accounting Act and the Value Added Tax Act, and we cannot invoice you without them.
We only process personal data where we have a legal basis to do so under Article 6 of the GDPR. The table below sets out each purpose, the basis we rely on and our retention period.
|
Purpose |
Legal basis |
Retention |
|---|---|---|
|
Answering enquiries, preparing proposals, estimates and statements of work |
Art. 6(1)(b) — steps taken at your request before entering a contract; Art. 6(1)(f) — our legitimate interest in responding to business enquiries |
24 months from our last contact with you, if no engagement follows |
|
Delivering our services, running the project and managing the client relationship |
Art. 6(1)(b) — performance of a contract; Art. 6(1)(f) where the contract is with your employer |
For the duration of the engagement and 3 years afterwards (the general limitation period under Estonian law) |
|
Invoicing, accounting, tax and statutory reporting |
Art. 6(1)(c) — compliance with a legal obligation (Estonian Accounting Act, Value Added Tax Act) |
7 years from the end of the financial year in which the document was created (Accounting Act § 12) |
|
Maintaining our CRM records and developing business relationships |
Art. 6(1)(f) — our legitimate interest in managing and growing our business |
24 months from the last meaningful contact, then deleted or anonymised |
|
Sending our newsletter and marketing emails |
Art. 6(1)(a) — your consent; Art. 6(1)(f) for existing clients receiving information about similar services |
Until you unsubscribe or object; the record proving consent is kept for 3 years afterwards |
|
Measuring and improving how the Website performs |
Art. 6(1)(a) — your consent, where consent is required for the cookies or identifiers involved; otherwise Art. 6(1)(f) |
Google Analytics 4 user and event data: up to 14 months |
|
Advertising, conversion measurement and remarketing |
Art. 6(1)(a) — your consent |
Generally up to 13 months for advertising identifiers, in line with the platform’s retention settings |
|
Keeping the Website secure, preventing spam, fraud and abuse, and diagnosing faults |
Art. 6(1)(f) — our legitimate interest in protecting our systems and our visitors |
Server and security logs: up to 12 months |
|
Establishing, exercising or defending legal claims, and complying with lawful requests |
Art. 6(1)(f); Art. 6(1)(c) where a legal obligation applies |
Until the matter is closed and the relevant limitation period has expired |
|
Considering job applications |
Art. 6(1)(b) — steps before an employment contract; Art. 6(1)(a) where you consent to us keeping your details on file |
6 months after the hiring decision, or longer if you have consented |
Legitimate interests. Where we rely on legitimate interests, we have weighed our interests against your rights and freedoms and concluded that our processing is proportionate and would be reasonably expected. You can ask us for details of that assessment, and you can object at any time — see section 10.
Retention in practice. At the end of a retention period we delete the data or irreversibly anonymise it. Data that has been deleted from our live systems may remain in encrypted backups for a limited further period until those backups are overwritten in the ordinary course.
Cookies are small text files that a website stores on your device. We also use similar technologies such as pixels, local storage and software development kits, which work in comparable ways. In this policy we refer to all of them as “cookies”.
Depending on which pages you visit and the choices you make, the following cookies and identifiers may be used. Exact names and lifetimes are set by the provider and may change when a provider updates its product.
|
Cookie / identifier |
Set by |
Purpose |
Typical lifetime |
|---|---|---|---|
|
__cf_bm, cf_clearance |
Cloudflare |
Strictly necessary. Distinguishes humans from bots, protects the Website against automated abuse and denial-of-service attacks. |
30 minutes / up to 1 year |
|
Session and anti-spam tokens |
ZAGROZA |
Strictly necessary. Keeps your session and our forms working and prevents automated form submissions. |
Session |
|
_ga |
Google Analytics 4 |
Analytics. Distinguishes one visitor from another. |
2 years (Google default) |
|
_ga_<container ID> |
Google Analytics 4 |
Analytics. Maintains the session state used for reporting. |
2 years (Google default) |
|
_gcl_au, _gcl_aw |
Google Ads / conversion linker |
Advertising. Attributes a form submission or other conversion to the advertisement you clicked. |
Up to 90 days |
|
IDE (doubleclick.net) |
|
Advertising. Measures advertising performance and, where remarketing is active, shows our ads on other sites. |
13 months in the EEA and the UK; 24 months elsewhere |
|
test_cookie (doubleclick.net) |
|
Advertising. Checks whether your browser accepts advertising cookies. |
15 minutes |
Strictly necessary cookies are required for the Website to function and cannot be switched off through our Website. Analytics and advertising cookies are not necessary for the Website to work, and you can refuse or remove them using the controls described below.
Consent. Where your consent is required before an analytics or advertising cookie is set, we ask for it before the cookie is placed, and you can change or withdraw your choice at any time — as easily as you gave it. Withdrawing consent does not affect anything we did before you withdrew it.
Your browser. Every major browser lets you view, block and delete cookies, and open a private browsing window. Look for “Cookies”, “Site data” or “Privacy” in your browser settings. Blocking strictly necessary cookies may stop parts of the Website from working.
Google Analytics. Install the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout.
Google advertising. Manage the advertising you see and the data Google uses at myadcenter.google.com and adssettings.google.com.
Industry opt-out tools. youronlinechoices.eu for Europe, and optout.aboutads.info for the United States and Canada.
Ask us. Write to [email protected] and we will stop using your data for analytics and advertising purposes.
There is no agreed industry standard for “Do Not Track” browser headers, and our Website does not respond to them. If your browser or a browser extension sends a Global Privacy Control (GPC) signal, we treat it as a valid request to opt out of the sale and sharing of personal information and of targeted advertising, and we apply it to that browser automatically, without asking you to do anything further. You can also use the browser and Google controls listed in section 5.3, or email us at [email protected].
We share personal data only where it is necessary for the purposes described in section 4. Our recipients fall into the following categories.
|
Recipient |
Role |
What they receive and why |
Where |
|---|---|---|---|
|
Google Ireland Limited and Google LLC |
Processor (Analytics, Tag Manager); independent controller for parts of its advertising services |
Website usage and event data, advertising identifiers and conversion data, so that we can measure how our Website and campaigns perform. Also our business email and document tools (Google Workspace). |
Ireland, United States |
|
Cloudflare, Inc. |
Processor |
IP address and request metadata, to deliver the Website quickly and to protect it against attacks and automated abuse. |
United States and global network |
|
Our CRM provider (NetHunt) |
Processor |
Enquiry and client contact records, correspondence history and deal status, so that we can manage the relationship. |
European Union, United States |
|
Hosting, infrastructure and email providers |
Processors |
The data needed to host the Website and to send and receive our correspondence. |
European Union, United States |
|
Subcontractors and freelance specialists engaged by us |
Processors |
Only the project data needed for the work assigned to them, under written confidentiality and data processing terms. |
European Union, Ukraine, United Kingdom |
|
Accountants, auditors, lawyers, banks and insurers |
Independent controllers or processors, depending on the service |
Contract, invoicing and correspondence records, where needed for accounting, audit, legal advice or payment. |
Estonia, European Union |
|
Public authorities and courts |
Independent controllers |
Only what we are legally required to disclose, or what is needed to establish or defend a legal claim. |
As required by law |
Every processor acting on our behalf is engaged under a written data processing agreement that meets Article 28 of the GDPR, is bound to act only on our instructions, and is subject to confidentiality and security obligations. We do not sell personal data for money, and we do not disclose it so that a third party can market its own products to you. Our use of advertising cookies may nonetheless be treated as a “sale” or a “share” under some US state privacy laws — see section 10.4.
If our business, or part of it, is ever sold, merged or reorganised, personal data may be transferred to the acquirer as part of that transaction. We will tell you before your data becomes subject to a different privacy policy.
We are based in Estonia and store data primarily inside the European Economic Area (“EEA”). Some of our providers and subcontractors, in particular those listed in section 6, process data in the United Kingdom, Ukraine or the United States, or through global infrastructure. The United Kingdom is covered by a European Commission adequacy decision. Ukraine is not, and transfers to subcontractors there are made under the Standard Contractual Clauses described below. Where personal data leaves the EEA, we rely on one of the following safeguards:
An adequacy decision of the European Commission — including Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection under the EU–US Data Privacy Framework, where the recipient is certified under that framework;
Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and, where needed, additional technical and organisational measures such as encryption in transit and at rest and strict access control; or
Another lawful transfer mechanism permitted by Chapter V of the GDPR.
For transfers out of the United Kingdom we rely on the UK International Data Transfer Addendum to the Standard Contractual Clauses, or on the UK extension to the EU–US Data Privacy Framework.
You can request a copy of the relevant safeguard, with commercially confidential terms redacted, by writing to [email protected].
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure or alteration. These include:
encryption of data in transit using HTTPS/TLS across the Website and our working tools;
access to personal data on a need-to-know basis, with individual accounts and authentication requirements on our business-critical systems;
regular updating and patching of the software and infrastructure we rely on;
confidentiality obligations for everyone who works with us, whether employed or engaged as a contractor;
written data processing agreements with our processors and vetting of new providers before we engage them; and
an internal procedure for handling security incidents.
No method of transmitting or storing data is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, as required by Article 33 of the GDPR, and we will inform you without undue delay where the breach is likely to result in a high risk to you.
We do not make decisions about you that produce legal effects or similarly significantly affect you based solely on automated processing. Advertising and analytics platforms may build audience segments and optimise ad delivery using cookies and identifiers; this does not produce legal effects for you, and you can opt out at any time using the controls in section 5.3.
Subject to the conditions and exceptions in the applicable law, you have the right to:
be informed about how we use your data — which is the purpose of this policy;
access the personal data we hold about you and receive a copy of it;
rectify inaccurate data and complete data that is incomplete;
erase your data (“the right to be forgotten”) where we no longer have a lawful reason to keep it;
restrict our processing while a dispute about accuracy or lawfulness is resolved;
data portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
object to processing based on our legitimate interests. Where you object to direct marketing, we will stop immediately and without exception;
withdraw consent at any time where we rely on consent — for cookies, through the controls described in section 5.3; otherwise by emailing [email protected] — without affecting the lawfulness of processing carried out before the withdrawal; and
not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see section 9.
Write to [email protected] and tell us what you would like us to do. Exercising your rights is free of charge. We may ask you for information to confirm your identity before we act, so that we do not disclose your data to someone else. We will respond within one month. If your request is complex, or if you have made several requests, we may extend that period by up to two further months and will tell you within the first month if we do.
If you are unhappy with how we handle your personal data, please tell us first at [email protected] — we will acknowledge your complaint within 30 days and resolve it without undue delay. You also have the right to lodge a complaint with a supervisory authority:
Estonia (our lead authority): Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), Tatari 39, 10134 Tallinn, Estonia. Telephone +372 627 4135, email [email protected], www.aki.ee.
Elsewhere in the EEA: the supervisory authority of the country where you live, work, or where the issue arose.
United Kingdom: the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Telephone 0303 123 1113, ico.org.uk. Under the Data (Use and Access) Act 2025, in force since 19 June 2026, you have the right to complain to us directly first; we will acknowledge your complaint within 30 days.
This section applies to the extent that the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), applies to us.
Categories of personal information collected in the last 12 months: identifiers (name, email address, telephone number, IP address, online identifiers); commercial information (details of services enquired about or purchased); internet and network activity (browsing and interaction data on our Website); approximate geolocation derived from IP address; and professional or employment-related information (employer, job title, and the content of a job application if you send us one).
Sources, purposes and disclosures are described in sections 3, 4 and 6 of this policy. We disclose personal information to service providers and contractors for the business purposes set out in section 4.
Sensitive personal information. We do not collect sensitive personal information as defined by the CCPA, and we therefore do not use or disclose it for purposes that would trigger the right to limit its use.
Sale and sharing. We have not sold personal information for money in the preceding 12 months. Our use of advertising cookies may nonetheless be treated as a “sale” or as “sharing” of personal information for cross-context behavioural advertising under the CCPA and comparable US state laws. You can opt out at any time using the controls in section 5.3, by sending a Global Privacy Control signal from your browser, or by emailing [email protected]. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Your California rights: to know what we collect, use, disclose and share; to access a copy; to correct inaccurate information; to delete; to opt out of sale or sharing; and not to be discriminated against for exercising any of these rights. You may use an authorised agent, who must provide proof of authorisation. To make a request, email [email protected]. We will verify your request by matching the information you provide against our records, and will respond within the statutory time limits.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have comparable rights to access, delete and obtain a copy of their personal data, and to opt out of targeted advertising and the sale of personal data. Most of those laws — though not Utah’s — also give a right to correct inaccurate data and a right to appeal a refusal. We extend all of these rights to every user, wherever you live. Email [email protected] and we will handle your request under the law that applies to you.
Our Website links to third-party websites and profiles, including LinkedIn, Instagram, Facebook and directories such as Clutch. Following those links takes you to services we do not control and that have their own privacy policies. We are not responsible for how they handle your data, and we encourage you to read their policies before sharing anything with them.
When we design, build, host, integrate or maintain a system for a client, that system may contain personal data belonging to the client’s customers, employees or users. In relation to that data our client is the controller and ZAGROZA acts as a processor: we process it only on the client’s documented instructions, under a data processing agreement that meets Article 28 of the GDPR, and we do not use it for our own purposes.
If you are a customer or user of one of our clients and you want to exercise your rights over data held in their systems, please contact that organisation directly — it is the controller and it decides how the data is used. If you contact us instead, we will forward your request to the client and tell you that we have done so, but we cannot act on it ourselves without the client’s instruction.
Our Website and services are directed at businesses and professionals. They are not intended for children and we do not knowingly collect personal data from them. If you believe that a child has provided us with personal data, please contact [email protected] and we will delete it.
We may update this Privacy Policy to reflect changes in our services, our providers or the law. When we do, we publish the new version on this page and update the “Last updated” date at the top. If the changes materially affect how we use your personal data, we will give you clear notice — by email where we hold your address, or by a prominent notice on the Website — before the changes take effect. Previous versions are available on request.
ZAGROZA OÜ
Registry code 16971792 · VAT number EE102743168
Kaupmehe tn 7-120, Kesklinna linnaosa, Tallinn, Harju maakond, 10114, Estonia
Email: [email protected] · Website: zagroza.agency
Entered in the Estonian Commercial Register (Äriregister), maintained by the Tartu County Court Registration Department.
Supervisory authority: Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia · +372 627 4135 · [email protected] · www.aki.ee