Who controls your data
Vantrex Global OÜ, registry code 17572338, registered at Harju maakond, Tallinn, Mustamäe linnaosa, Kadaka tee 171, 12615, Estonia, is the controller of the personal data described in this notice. You can contact us at privacy@vantrexglobal.xyz.
Scope of this notice
This notice applies when you visit our website, create an account, contact us, request or purchase a service, receive an invoice, communicate with our team or otherwise interact with Vantrex Global.
Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
- identity and contact data, including your name, email address, country and organisation;
- account data, including login identifiers, account status and authentication records;
- enquiry and project data, including messages, selected services, meeting notes, files, instructions, feedback and other information you provide;
- contract and billing data, including agreed scope, invoices, payment status, transaction references and tax-related information;
- notice acknowledgement and preference records, including your communication choices;
- technical and usage data, including IP address, device and browser information, approximate location, pages viewed, referring page, timestamps and website interactions.
Where the data comes from
We normally receive personal data directly from you. We may also receive it from a person acting for your organisation, service providers that operate our website and communications, public business sources, or analytics providers.
Purposes and legal bases
We process personal data only where we have a lawful basis under the GDPR.
- To answer enquiries, assess your request and prepare a proposal or invoice: steps requested before entering into a contract and our legitimate interest in responding to business enquiries.
- To enter into and perform a contract, deliver services, arrange meetings and provide support: performance of a contract or steps requested before a contract.
- To issue invoices, maintain accounting records and comply with tax, regulatory and legal requirements: compliance with legal obligations.
- To operate accounts, protect the website, prevent abuse, maintain service reliability and defend legal claims: our legitimate interests in secure and effective business operations.
- To measure website use and improve content through analytics: our legitimate interests where this basis is available under applicable law; otherwise consent.
- To send marketing communications where applicable: your consent or another lawful basis permitted by applicable law. You may opt out at any time.
Who receives personal data
We share personal data only where necessary. Recipients may include hosting and infrastructure providers, database and authentication providers, email and communications providers, security and content-delivery providers, analytics providers, banks and payment providers used for invoice payments, accountants, professional advisers and public authorities where disclosure is legally required.
Our current website infrastructure may include Vercel, Supabase, Resend and Cloudflare. When configured, Google Analytics 4 and Microsoft Clarity measure website visits automatically. Providers process data under their own terms and applicable data-processing arrangements.
We do not sell personal data.
International transfers
Some service providers may process personal data outside Estonia or the European Economic Area. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, together with appropriate safeguards.
How long we keep data
We keep personal data only for as long as it is needed for the purpose for which it was collected or to meet legal requirements.
- general enquiries and related correspondence: normally up to 24 months after the last substantive contact;
- account data: while the account is active and until deletion or an inactivity review determines it is no longer required;
- contracts, invoices, payment records and accounting documents: at least seven years where required by Estonian accounting or tax law;
- project materials: for the duration of the engagement and a reasonable period afterwards to provide support and manage legal claims;
- consent records and technical logs: for the period needed to demonstrate preferences, maintain security and investigate incidents;
- analytics data: according to the retention settings of the relevant provider.
Security
We use proportionate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. Access is limited to people and providers that need the data for their work. No online system can be guaranteed to be completely secure.
Your rights
Subject to the GDPR and any applicable limitations, you may request access to your personal data, correction, erasure, restriction, portability or object to processing. Where processing is based on consent, you may withdraw consent at any time without affecting processing carried out before withdrawal.
Send a request to privacy@vantrexglobal.xyz. We may ask for information needed to verify your identity. You also have the right to complain to the Estonian Data Protection Inspectorate or, where applicable, the supervisory authority in the country where you live or work.
Changes to this notice
We may update this notice when our services, providers or legal obligations change. The current version and its last-updated date will remain available on this page.