Punane tn 6a, 13619 Tallinn, Estonia

Terms & conditions

Terms & conditions

1. General information

 

This Privacy Policy explains how STORENT OÜ processes the personal data of individuals in connection with equipment hire, other services provided by the Company, customer and business relationships, website use, recruitment, CCTV surveillance and other purposes set out in this policy.

 

Data Controller:

STORENT OÜ, registration code 11682327

Punane tn 6a, 13619 Tallinn, Estonia

For enquiries regarding the processing of personal data and the exercise of your rights, please write to: [email protected].

 

This policy applies to individuals whose data the Company processes as:

  • customers or potential customers;
  • representatives, contact persons and beneficial owners of customers, suppliers and business partners – legal entities – to the extent that the Company processes such data;
  • website users;
  • job applicants;
  • persons visiting the Company’s premises or facilities;
  • other individuals who contact the Company or whose data is required by the Company to protect its rights and fulfil its obligations.

 

 

2. In what circumstances and why do we process personal data

The Company processes personal data only for specific purposes and on the legal basis set out in this policy.

2.1. Provision of services to natural persons – customers

Where the customer is a natural person, the Company processes personal data in order to assess the request prior to concluding a contract, prepare a quotation, conclude and perform the contract, deliver and accept equipment, provide related services, communicate regarding the service and resolve issues relating to the performance of the contract.

Categories of data processed: first name, surname, personal identification code or date of birth, details of identity documents, contact details, billing and payment information, information regarding orders, quotations and rental transactions, including details of the rented equipment, the location where the service is provided, the rental period and additional services, as well as the content of communications.

Legal basis: performance of a contract or taking steps at the data subject’s request prior to entering into a contract – Article 6(1)(b) of the GDPR.

Retention period: for the duration of the contract and thereafter for as long as necessary to fulfil obligations laid down in legislation, resolve disputes or protect the Company’s legitimate interests. The Company retains accounting documents relating to the transaction for the period specified in applicable legislation.

 

2.2. Representatives and contact persons of legal entity clients, suppliers and business partners

Where the Company enters into or performs a contract with a legal entity, the Company may process the data of its representatives, authorised persons, contact persons and other natural persons involved in the performance of the contract.

Categories of data processed: first name, surname, position, place of work, contact details, information on representation or authorisation, content of communications, information relating to the conclusion or performance of the contract, and signature data, if included in the contract documents.

Legal basis: the legitimate interests of the Company and its contractual partner in organising business relations, verifying rights of representation, concluding and performing the contract, ensuring communication and protecting their rights – Article 6(1)(f) of the GDPR.

Retention period: for the duration of the contract and thereafter for as long as necessary to document the contract, fulfil obligations laid down in legislation, and bring, pursue or defend potential claims.

 

2.3. Solvency assessment, debt management and protection of claims

The Company may, to the extent necessary for assessing the risk of a specific transaction, monitoring settlements, recovering debts or protecting its rights, process information regarding the fulfilment of a customer’s payment obligations, the amount of debt, the occurrence and fulfilment of debt obligations, as well as receive or transfer data to debt recovery service providers, credit information companies, legal service providers or competent authorities.

Categories of data processed: identification and contact details, contractual and settlement data, information on late payments, the amount of debt, correspondence regarding the debt and debt recovery activities.

Legal basis:

  • the Company’s legitimate interests in assessing transaction risk, ensuring payment discipline, recovering debts and protecting its rights – Article 6(1)(f) of the GDPR;
  • compliance with a legal obligation where the specific processing requires it – Article 6(1)(c) of the GDPR.

Where data is exchanged with credit information companies, the Company complies with the specific regulations applicable to such data exchange and the conditions set out therein.

Retention period: for the duration of debt administration and protection of the claim, and thereafter until the expiry of the limitation period for the relevant claim or until the final conclusion of any legal or enforcement proceedings, whichever is later.

 

2.4. Accounting, taxation and compliance with other legal obligations

The Company processes personal data for the purposes of maintaining accounts, making payments, and fulfilling tax, financial accounting and other legal obligations applicable to the Company.

Categories of data processed: identification details, contact details, information relating to contracts, invoices, payments and other transaction-related information.

Legal basis: fulfilment of a legal obligation to which the Company is subject – Article 6(1)(c) of the GDPR.

Retention period: for the period specified in the applicable legislation for the relevant type of document or data.

 

2.5. Communication, handling of enquiries and service quality

The Company processes personal data when a person contacts the Company by telephone, email, via the contact form, social media or other communication channels, in order to provide a response, process a request, provide customer service and document relevant communications.

Categories of data processed: first name, surname, contact details, content of communications, information contained in the enquiry, and data necessary for processing the enquiry.

Legal basis:

  • performance of a contract or pre-contractual measures, where the request relates to a contract or service – Article 6(1)(b) of the GDPR;
  • the Company’s legitimate interest in ensuring effective communication, customer service and protection of its rights – Article 6(1)(f) of the GDPR.

Retention period: until the request has been processed and for no longer than 12 months thereafter, unless the correspondence forms part of contract documentation, dispute materials or another matter to which a longer retention period applies.

 

2.6. Direct marketing and commercial communications

The Company may send commercial communications regarding its services, offers and news.

Where the data subject’s consent is required to send a commercial communication, the Company processes personal data on the basis of consent – Article 6(1)(a) of the GDPR. Consent may be withdrawn at any time, for example by using the opt-out link in the communication or by writing to [email protected].

The Company may use a customer’s electronic contact details for direct marketing of its own similar products or services only if the conditions set out in subsection 3 of § 103¹ of the Estonian Electronic Communications Act are met. Each such communication provides a clear, free and easy-to-use option to opt out of receiving further communications.

Categories of data processed: first name, surname, email address, telephone number, status as a customer or potential customer, communication preferences, and information regarding the sending, opening or receipt of the communication.

Retention period: until consent is withdrawn or an objection is received, or until the Company ceases the relevant marketing activity. The Company retains information regarding consent or withdrawal for as long as necessary to demonstrate compliance and ensure that the opt-out is respected.

 

2.7. Personalisation and profiling of offers

The Company may carry out limited profiling to categorise customers or potential customers into groups based on their previously used services, enquiries, sector of activity or communication preferences, and to send them more relevant information about the Company’s services.

Legal basis: legitimate interests in accordance with Article 6(1)(f) of the GDPR.

General rationale: the system uses the aforementioned categories of data to determine which information about the Company’s services may be more relevant to the individual concerned. Profiling is not used to make decisions that produce legal effects concerning the individual or similarly significantly affect them.

Expected consequences: the individual may receive more personalised marketing communications. The individual may withdraw consent or object to direct marketing, including related profiling, at any time.

Retention period: until consent is withdrawn or an objection to direct marketing is made, or until the Company ceases the relevant profiling activity.

 

2.8. Processing of job applicants’ data

The Company processes job applicants’ personal data in order to organise and carry out the selection process for a specific vacancy, assess the applicant’s suitability for the vacancy, communicate with the applicant and make a decision regarding the applicant’s progression through the selection process.

Categories of data processed: first name, surname, contact details, CV, cover letter, information on education, work experience, professional skills, language skills, references, interview notes and other information provided by the candidate or generated during the selection process.

Legal basis: the Company’s legitimate interests in conducting staff recruitment and selecting a suitable candidate for a specific vacancy – Article 6(1)(f) of the GDPR.

Retention period: the Company retains a candidate’s personal data for the purposes of the specific recruitment process for three months following the completion of the relevant recruitment process, unless there are grounds to retain it for longer, for example, to protect the Company’s rights in connection with a potential dispute.

Applying for a specific vacancy is not conditional upon the candidate’s consent to the retention of their personal data for future recruitment purposes.

If the Company wishes to retain a candidate’s CV and application documents in order to contact them regarding future vacancies, the Company will seek separate and voluntary consent. The legal basis for such processing is the candidate’s consent – Article 6(1)(a) of the GDPR. The candidate may withdraw their consent at any time by writing to [email protected].

The retention period for data for future recruitment purposes is 12 months from receipt of consent.

 

2.9. Video surveillance

The Company may carry out video surveillance on its premises and facilities in order to protect the safety of employees, visitors and other persons, prevent and investigate breaches, and protect the Company’s property.

Categories of data processed: video footage which may show a person’s image, location and time of visit.

Legal basis: the Company’s legitimate interests in ensuring the safety of persons and property – Article 6(1)(f) of the GDPR.

CCTV zones are marked with information signs. CCTV surveillance is not carried out in areas where a person may reasonably expect a higher level of privacy.

Retention period: up to 30 days, except where the recording is necessary for the investigation of an incident, the establishment, exercise or defence of legal claims, or for submission to a competent authority.

 

2.10. Use of the website and cookies

The Company’s website uses cookies and similar technologies. For information on cookie categories, their purposes, the tools used, consent management, data recipients and the possible transfer of data outside the European Economic Area, please see the Cookie Policy.

Non-essential cookies and similar technologies are used only with the user’s consent. The user may change their preferences at any time by using the “Cookie settings” link in the website footer.

 

 

3. Sources of personal data

The Company usually receives personal data from the individual themselves, the company they represent, or a person designated to the Company as a contact person.

In certain cases, the Company may also obtain data from:

  • publicly available registers and sources, where necessary to verify the individual’s identity, right of representation or transaction details;
  • credit information companies, debt recovery service providers or other business partners, where this is necessary for assessing creditworthiness, managing debts or protecting legal rights;
  • recruitment platforms or recruitment service providers, where a candidate has applied through them;
  • service providers used by the Company, where the data is generated in the course of providing a service or performing a contract.

 

 

4. Recipients of personal data

The Company may transfer personal data only to the extent necessary for a specific purpose to the following categories of recipients:

  • authorised employees of the Company who require the data to carry out their duties;
  • providers of IT, hosting, data storage, communications, customer relationship management, accounting, payment, rental equipment management and other services who process personal data on the Company’s behalf;
  • the provider of the recruitment platform;
  • debt recovery service providers, credit information companies, insurers, legal service providers, auditors and consultants, where necessary for the relevant purpose;
  • banks and payment service providers;
  • state and local government authorities, courts, bailiffs and other competent persons, where the Company has a legal obligation to disclose the data or where this is necessary to protect the Company’s rights;
  • transaction partners in the event of a reorganisation, disposal of the company or part thereof, or any other similar corporate transaction, in accordance with the applicable legal framework.

The Company enters into contracts with data processors which set out obligations regarding the protection of personal data, to the extent necessary.

 

 

5. Transfer of personal data outside the European Economic Area

The Company primarily processes personal data within the European Union and the European Economic Area.

However, when using certain IT, cloud, analytics or advertising services, personal data may be transferred or made available outside the European Economic Area. This may apply in particular to Google and Meta services used on the website, provided the user has given consent to the relevant category of cookies.

In such cases, the Company ensures that there is an appropriate legal basis for the transfer of data and adequate safeguards, such as a European Commission decision on the adequacy of the level of protection or standard contractual clauses approved by the European Commission, accompanied by the necessary additional safeguards.

An individual may request information regarding the relevant safeguards for the transfer of data by writing to [email protected].

 

 

6. Retention of personal data

The Company retains personal data for no longer than is necessary for the specific purpose of processing, in accordance with the time limits set out in legislation and the Company’s need to protect its rights.

The Company determines retention periods by assessing:

  • the purpose of the data processing and whether that purpose still exists;
  • the duration of the contractual or business relationship;
  • the retention obligations laid down in legislation;
  • the time required to bring, pursue or defend potential claims;
  • the validity of the data subject’s consent, where processing is based on consent.

Upon expiry of the applicable retention period, personal data is erased, anonymised or archived, provided that such archiving is justified by applicable legislation and appropriate safeguards are in place.

 

 

7. Rights of the data subject

A person has the following rights, insofar as they apply to the specific processing:

  • to request access to their personal data;
  • to request the rectification of inaccurate or incomplete personal data;
  • to request the erasure of personal data;
  • to request restriction of the processing of personal data;
  • to object to processing based on the Company’s legitimate interests;
  • to object to the processing of personal data for direct marketing purposes, including profiling related to such marketing;
  • to receive their personal data in a structured, commonly used and machine-readable format and, where technically feasible, to request that it be transmitted to another controller where the processing is based on consent or a contract and is carried out by automated means;
  • to withdraw consent at any time where processing is based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise your rights, please contact the Company by emailing [email protected]. The Company may request additional information necessary to verify the identity of the person making the request.

An individual has the right to lodge a complaint with the Estonian Data Protection Inspectorate if they consider that the processing of their personal data does not comply with the applicable legal framework. Information about the Estonian Data Protection Inspectorate is available at: www.aki.ee.

 

 

8. Security of personal data

The Company implements technical and organisational measures commensurate with the risk to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, damage, unauthorised disclosure or access.

Access to personal data is restricted to those individuals within the Company and service providers who require it for the performance of specific work duties or contractual obligations and who are bound by confidentiality and data protection obligations.

 

 

9. Changes to the Policy

The Company may update this policy from time to time, for example if there are changes to the Company’s data processing activities, applicable regulations or technical solutions. The current version of the policy is always available on the Company’s website, indicating the date of its latest update.

If the changes significantly affect the rights of data subjects or require new consent, the Company will provide appropriate notice before such changes take effect.