Privacy policy and cookie usage

Privacy Policy and Cookie Usage

Published on May 6, 2021

Numtoo OÜ (hereinafter "Numtoo", we, us, or our), registered in the Estonian Commercial Register under registration number 16039501, with its legal address in Harju County, Kuusalu Parish, Pudisoo, Männimäe 1, 74626, Estonia, has prepared this Privacy Policy and Cookie Usage Policy (hereinafter "Privacy Policy") to inform you of our methods of collecting, using, and disclosing personal information that you provide to us when visiting our websites: www.popcorn.tel, www.numtoo.ee, (here in after "websites"). Furthermore, this Privacy Policy describes the type of information that may be collected when using cookies and other technologies on our websites.

This Privacy Policy applies to the websites and any authorized sub-sites that directly accept, display, or reference this Privacy Policy. By using the websites, you agree to the collection and use of your information in accordance with this Privacy Policy by us as the data controller of your personal data. If you do not agree with this Privacy Policy, please do not use our websites. It is important for you to understand that by using our services, you consent to the collection, use, disclosure, and storage of your personal data.

As we are a company registered in the Republic of Estonia, the processing of your personal data is governed by the data protection laws of the Republic of Estonia.

Please take the time to read this Privacy Policy. If you have any comments, questions, or concerns, please contact our Data Protection Officer (hereinafter "DPO") Tatiana Gromut at numtoo@numtoo.ee. We will respond to your request by email within one month. Please note that before we can provide you with the requested information, we need to verify your identity.

This Privacy Policy is not a contract between us and an individual. If we modify or amend our Privacy Policy, we will publish the latest version on our websites. It is recommended to periodically review this Privacy Policy for changes. Changes to this Privacy Policy are effective as of the date of publication on the page: www.popcorn.tel/privacy-policy-and-cookie-usage.

We will always be open and honest about how we handle personal information that can identify individuals. You have many rights that you can exercise to control your privacy. We want to help you exercise your rights, so below you will learn how to do so.

You have the right to lodge a complaint with a supervisory authority at any time. The Estonian Data Protection Inspectorate (registered office at Väike-Ameerika 19, 10129 Tallinn, phone: +372 627 4135, email: info@aki.ee) is the leading supervisory authority for data protection for Numtoo as an Estonian data controller.

Data Protection Principles

First and foremost, we emphasize that we comply with all relevant data protection principles when processing your personal data. These principles relate to:

  • Lawfulness, fairness, and transparency - we process your personal data lawfully, fairly, and transparently;
  • Purpose limitation - we collect your personal data only for specific, legitimate, and lawful purposes and only as long as necessary to fulfill these purposes;
  • Data minimization - we ensure that the personal data we process is adequate, relevant, and limited to what is necessary for the purpose of processing;
  • Accuracy - we take all reasonable steps to keep personal data up to date and accurate, and you have the right to request the correction or deletion of inaccurate data, which we will do within one month;
  • Storage limitation - we delete your personal data when it is no longer needed for the purposes it was collected;
  • Integrity and confidentiality - we ensure the security and protection of your personal data from unauthorized or unlawful processing and from accidental loss, destruction, or damage by using appropriate technical or organizational measures.

Personal Data We Collect and Purposes for Processing Personal Data

Personal data means any information relating to an identified or identifiable individual. You do not need to provide us with any personal information to use most of our websites. However, we may collect personal information that you voluntarily provide to us when requesting information about our services, sending us inquiries, subscribing to our services, or submitting your resume in relation to career opportunities posted on our websites. Any information you send us for a job application will be processed with the utmost care and only for that purpose.

For the purposes of this Privacy Policy, we are the data controller of your personal information and determine the purposes and means by which any personal data is processed or must be processed and collected on our websites. We do not sell, share, or disclose this information except as specified in this Privacy Policy. We use your information to improve our marketing, administration, and service delivery.

If you subscribe to our newsletter through our websites or otherwise provide us with your contact details, Numtoo may send you updates, newsletters, or other notifications that may be of interest to you. For marketing purposes, we may track whether you open and/or click on URLs in our newsletters.

How We Use Your Personal Data

Numtoo will use your personal data to serve customers, provide you with requested information, and customize the information provided to you on the websites. Your personal data is used by Numtoo to respond to your inquiries, develop offers for you, and for general internal business purposes.

We require all service providers to process your information securely and in accordance with EU data protection legislation. We use standard measures provided by EU legislation for legitimizing data transfers outside the EU.

If Numtoo is sold entirely or partially, merged with another company, or declared bankrupt, some or all of the data we have received from you may be transferred to a third party as part of the asset transfer. Numtoo may also disclose your data in response to legal requirements or for the protection of Numtoo's interests or security, another website, or visitors.

Processing of Special Categories of Personal Data

Numtoo will not collect or use information revealing your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, nor process genetic data, biometric data for the unique identification of individuals, health data, or data concerning the personal life or sexual orientation of individuals, or any other information considered sensitive.

Legal Basis for Processing Personal Data

We collect several types of information for various purposes to provide and improve our services. Our legal basis for collecting and using personal data described in this Privacy Policy depends on the data we collect and the specific context in which we collect it.

Numtoo may process your personal data because:

  • We need to perform a contract with you;
  • You have given us your consent to do so;
  • Processing is necessary for our legitimate interests and does not override your rights and/or legal compliance.

We use the collected data for various purposes:

  • To provide, maintain, and improve our websites;
  • To notify you of changes to our websites;
  • To collect, analyze, or generate valuable insights to improve our websites;
  • To monitor the use of our websites;
  • To provide support to visitors;
  • To create anonymous usage statistics;
  • To detect, prevent, and resolve technical issues;
  • To comply with legal requirements and regulatory authorities;
  • To protect your and our rights;
  • To respond to your questions;
  • To contact you for administrative purposes to resolve relevant issues related to you.

Links to Third-Party Websites and Applications

Our websites may contain links to third-party websites and applications that are not affiliated with us. We do not endorse or make any representations about such third-party websites or applications. Any information you provide on third-party websites or services is directly provided to the operators of those services and is governed by their privacy policy, even if accessed through our websites. We are not responsible for the content or privacy policies and security of third-party websites or services, links, or access provided through our websites. We recommend that you review the privacy policy and security practices of third parties before providing them with information.

We may employ third-party companies and individuals to facilitate the operation of our websites, provide services on our behalf, assist us in analyzing the use of our websites, or help us with related tasks. These third parties have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purposes.
Disclosure and Transfer of Personal Data

We process your personal data within the EEA, so your information may be transferred and stored on computers located outside of your country or other jurisdiction, where data protection laws may differ from the laws in your jurisdiction. We will comply with privacy requirements to ensure adequate protection, and take all reasonably necessary steps to ensure secure handling of your data in accordance with this Privacy Policy. Your personal data will not be transferred to an organization or country unless appropriate safeguards are in place, including the security of your data and other personal information.

In certain circumstances, we may be required to disclose your personal data if required by law or in response to valid requests from governmental authorities (e.g., courts or government agencies). We also reserve the right to disclose personal data or other information that we believe is relevant or necessary for:

  • Taking precautions against liability;
  • Protecting ourselves or others from fraud, abuse, or illegal activities;
  • Investigating and defending against any claims or allegations from third parties;
  • Protecting the security or integrity of services and any devices or equipment used to provide services, or protecting our property or other legal rights, ensuring compliance with our contracts, or protecting the rights, property, or security of others.

We will notify visitors through our communication channels about requests made by governmental authorities, provided such notification is permitted by law.

Cookies and Tracking Technologies

We use automatically collected information and other information gathered on our website and services through cookies and similar technologies. A cookie is a piece of data temporarily stored on a visitor’s hard drive that contains information about the visitor. The cookie contains your contact information and information that allows us to identify your computer through our websites. You may accept or reject cookies. Most web browsers automatically accept cookies, but you can usually change your browser settings to reject cookies if you wish. However, if you do not accept cookies, you may not be able to use some parts of our websites.

Google Analytics and Yandex Metrica

We use Google Analytics and Yandex Metrica to measure and evaluate access and traffic on our websites, as well as to create reports on visitor navigation for our administrators. Google and Yandex operate independently from us and have their own rules, which we strongly recommend you review. Google and Yandex may use information collected through Google Analytics and Yandex Metrica to evaluate visitor activity on our websites. For more information, see Google Analytics Privacy and Data Sharing and Yandex Metrica.

We take measures to protect the technical information collected through Google Analytics and Yandex Metrica. The collected data will only be used if necessary to address technical issues, administer services, and determine visitor preferences, but in this case, the data will be in an anonymized form. We do not use this information to identify our visitors.

You can opt-out of having your actions on websites tracked by Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sending information about visits to Google Analytics.

You can opt-out of having your actions on websites tracked by Yandex Metrica. To do this, download and install the Yandex Metrica opt-out plugin at: https://yandex.ru/support/metrica/general/opt-out.html.

Community Features

Websites may offer visitors chats, forums, message boards, and/or other community features. Please remember that any information you disclose in these areas becomes publicly available, and you should exercise caution when deciding to disclose your personal, financial, or other information.

Security and Retention of Personal Data

Numtoo will take reasonable steps to ensure the accuracy, completeness, and relevance of the data we collect, use, or disclose.

Numtoo will take all reasonable steps to ensure that your personal information stored by us is protected from unauthorized use, loss, or unauthorized access, alteration, or disclosure.

However, please note that no electronic transmission or storage of information is 100% secure. Therefore, despite the security measures we have taken to protect your personal data, we cannot guarantee that data loss, misuse, or alteration will never occur. If we become aware of a security breach, we will notify you and the authorities about the breach in accordance with applicable law.

Numtoo will also take reasonable steps to destroy or anonymize personal data that we no longer need, unless required to retain it under applicable law.

To determine the appropriate retention period, we consider the volume, nature, and confidentiality of personal data, as well as the purposes for which we process it. We also must take into account periods during which we may need to retain personal data to fulfill our legal obligations or address complaints, requests, and protect our legal rights in the event of claims.

We use collected statistical data for analysis for up to three years. Cookies are typically valid for a short time (day, week, or month), although in some cases, they may remain valid for up to a year.

Your Data Protection Rights

Under certain circumstances, you have the right by law to:

Request information on whether we store personal information about you, and if so, what that information is and why we store or use it; Request access to your personal data (Data Subject Access Request). This allows you to obtain a copy of your personal data that we store; Request correction of personal data we store about you. This allows you to correct any incomplete or inaccurate data we hold about you. Please note that in this case, we may delete your profile and/or suspend (temporarily or permanently) the provision of services to you; Request the deletion of your personal data. This allows you to ask us to delete your personal data if we no longer have a reason to process it. You also have the right to request that we delete or remove your personal data if you have exercised your right to object to processing. Please note that in this case, we may delete your profile and/or suspend (temporarily or permanently) the provision of services to you; Object to the processing of your personal data, if we rely on legitimate interests (or the interests of a third party), and there is something in your particular situation that causes you to object to processing on this basis. You also have the right to object when we process your personal information for direct marketing purposes. Please note that in this case, we may delete your profile and/or suspend (temporarily or permanently) the provision of services to you; Object to automated decision-making, including profiling, which does not involve automated decision-making using your personal data or profiling of you. Please note that in this case, we may delete your profile and/or suspend (temporarily or permanently) the provision of services to you; Request restriction of processing your personal data. This allows you to ask us to suspend processing personal data about you, for example, if you want us to establish its accuracy or the reason for processing. Please note that in this case, we may delete your profile and/or suspend (temporarily or permanently) the provision of services to you; Request the transfer of your personal data in an electronic and structured format to you or another party (commonly known as the right to "data portability"). This allows you to receive your data from us in an electronic format and have the ability to transmit it to another party in electronic format; Withdraw consent. If you have given your consent to the collection, processing, and transfer of your personal information for a specific purpose, you have the right to withdraw your consent to that specific processing at any time. Once we receive notification that you have withdrawn your consent, we will no longer process your data for the purposes you initially consented to, unless we have another legal basis for processing. Please note that in this case, we may delete your profile and/or suspend (temporarily or permanently) the provision of services to you; File a complaint. If you believe your rights have been violated, you have the right to file a complaint with the data protection authority about the collection and use of your personal data. For more information, please contact your local data protection authority within the EEA or the Estonian Data Protection Inspectorate (contact details can be found at the beginning of this Privacy Policy).

If you wish to exercise any of these rights, you can contact us through our contact page or contact our DPO.

By using our websites, you consent to the collection and use of any personal data in the manner described.