Privacy policy
This policy explains what personal data Europlabs collects, why, on what legal basis, how long we keep it and what rights you have. It is written to be read, not to be impenetrable.
1. Who is responsible
The data controller for the processing described here is Europlabs OÜ, Näidise tee 12, 10115, Tallinn, Estonia. You can reach us at privacy@europeplabs.com.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy enquiries go to the address above and are handled by the person named in our legal notice.
2. What we collect, and why
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| Name, email, organisation, website URL and message you submit through the contact form | To answer your enquiry and prepare a quote | Art. 6(1)(b) — steps prior to entering a contract; Art. 6(1)(f) — our legitimate interest in responding to business enquiries | 24 months from last contact |
| Client contact details, billing details, contract and correspondence | To deliver the engagement and invoice for it | Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation for accounting records | Duration of the engagement, then as required by tax law (typically 7 to 10 years for invoices) |
| Test credentials and account data you supply for auditing | To reach the parts of your service that sit behind a login | Art. 6(1)(b) — performance of a contract | Deleted within 14 days of report delivery |
| Screenshots, recordings and findings produced during an audit | To evidence findings in the report | Art. 6(1)(b) — performance of a contract | 90 days after delivery, unless you ask us to keep them for a retest |
| Server log data: IP address, user agent, requested URL, timestamp | To operate the website securely and diagnose faults | Art. 6(1)(f) — legitimate interest in the security and availability of our site | Maximum 30 days |
3. What we do not do
- We do not sell personal data. Not to anyone, in any form.
- We do not run advertising or profiling cookies on this website.
- We do not add enquirers to a marketing list. If you contact us about an audit, you get an answer about the audit.
- We do not use your audit findings for anything other than delivering your engagement. Findings are never published or shared.
4. Cookies and analytics
This website sets no cookies of its own and loads no third-party scripts, fonts or trackers. There is nothing to consent to, which is why you have not been shown a banner. If that ever changes, we will add a compliant consent mechanism before making the change, not afterwards. Details are in our cookie policy.
5. Who else sees your data
We use a small number of processors, each bound by a data processing agreement under Article 28 GDPR:
- Website hosting — serving this site and retaining short-term server logs.
- Business email — sending and receiving correspondence.
- Accounting software — issuing and recording invoices.
- Video conferencing — scope calls and walkthroughs, where you join one.
We do not disclose personal data to anyone else except where we are legally required to. A current list of processors, with their locations, is available on request from privacy@europeplabs.com.
6. International transfers
We prefer processors that store data within the European Economic Area. Where a processor transfers personal data outside the EEA, that transfer is covered by an adequacy decision under Article 45 GDPR or by Standard Contractual Clauses under Article 46, together with any supplementary measures required. You can request details of the safeguards applying to a specific transfer.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectify inaccurate or incomplete data (Art. 16).
- Erasure of your data where the conditions apply (Art. 17).
- Restrict processing in certain circumstances (Art. 18).
- Portability — receive your data in a machine-readable format (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, where we rely on consent, without affecting processing already carried out.
To exercise any of these, email privacy@europeplabs.com. We respond within one month as required by Article 12(3), and we will tell you if we need to extend that period and why. There is no charge unless a request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. Our lead supervisory authority is the authority of Estonia.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) for this website and our email, encrypted storage for audit artefacts, access limited to the people working on your engagement, multi-factor authentication on all business accounts, and scheduled deletion of test credentials and audit artefacts as set out in section 2.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours under Article 33 and inform you where Article 34 requires it.
9. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
10. Children
Our services are provided to organisations. This site is not directed at children and we do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects how we process your personal data, we will notify affected clients directly rather than relying on you to re-read the page.
Questions about this document? Email privacy@europeplabs.com. Our full company details are on the legal notice.