LEGAL INFORMATION
Privacy Policy
Privacy Policy
Effective date: [insert date] Last updated: [insert date]
This Privacy Policy explains how Meretime Grupp OÜ (registry code: 10858669, registered address: Uus-Sadama tn 21-207, Kesklinna linnaosa, 10120 Tallinn, Harju maakond, Estonia), operating under the brand name NordVisa (“Company”, “we”, “us”), collects, uses, stores, shares, and protects personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian data protection legislation.
1. Data Controller
For the personal data processing activities described in this Privacy Policy, the Data Controller is:
Meretime Grupp OÜ (NordVisa) Registry code: 10858669 Uus-Sadama tn 21-207, Kesklinna linnaosa, 10120 Tallinn, Harju maakond, Estonia Email: info@nordvisa.ee
2. Personal Data We Collect
The personal data we process depends on how you interact with us and which services you request.
2.1. Inquiries and Communications
When you contact us through our website, by email, telephone, messaging service, or another communication channel, we may process:
• your full name;
• email address;
• telephone number, if provided;
• preferred method of communication;
• information contained in your inquiry or correspondence;
• information about your relocation, immigration, residence, citizenship, business, family, or other circumstances that you choose to provide and that are relevant to your inquiry.
2.2. Client and Service Data
If you engage NordVisa to provide services, we may process personal data necessary to assess your matter and provide the requested consulting, relocation, immigration, or application-support services, including, where relevant:
• identification and contact details;
• copies and details of identity or travel documents;
• nationality and residence information;
• immigration and visa-related information;
• employment, education, business, or professional information;
• family and relationship information where relevant to the requested service;
• financial or supporting information required for a particular application or procedure;
• correspondence and documents relating to your matter;
• information necessary for invoicing, accounting, and administration;
• other information reasonably necessary to provide the service you have requested.
We apply the principle of data minimisation and seek to process only personal data that is adequate, relevant, and necessary for the relevant purpose.
2.3. Special Categories of Personal Data
Certain immigration, residence, citizenship, family, or relocation matters may involve information falling within the special categories of personal data referred to in Article 9 GDPR.
We do not request or process such information unless it is relevant and necessary for the particular service or procedure.
Where special-category personal data is processed, we do so only where an applicable condition under Article 9(2) GDPR is available, including explicit consent where appropriate.
Please avoid sending sensitive personal information that is not necessary for your inquiry or the service requested.
2.4. Personal Data Relating to Other Persons
If you provide us with personal data concerning another person, for example a spouse, family member, employee, representative, or dependant, you should ensure that you are authorisedto provide that information where required.
We will process such information only to the extent necessary for the relevant service or another lawful purpose.
2.5. Technical Data
When you visit our website, limited technical information may be processed automatically as necessary for the operation and security of the website, such as:
• IP address;
• browser and device information;
• date and time of requests;
• basic server and security logs;
• information necessary for technically essential cookies or similar technologies.
We do not currently use third-party advertising or behavioural tracking technologies such as Meta Pixel or Google Analytics.
If this changes, this Privacy Policy and, where necessary, our cookie consent mechanism will be updated accordingly.
3. Purposes and Legal Bases for Processing
We process personal data only where there is an appropriate legal basis under the GDPR.
3.1. Responding to Inquiries and Taking Pre-Contractual Steps
When you contact us regarding our services, we may process your personal data to respond to your inquiry, assess your requirements, provide information about our services, prepare an offer, and take steps at your request before entering into a service agreement.
Legal basis: Article 6(1)(b) GDPR — taking steps at the request of the data subject prior to entering into a contract.
Where an inquiry is not related to a potential contractual relationship, processing may be based on our legitimate interest in responding to communications addressed to our business under Article 6(1)(f) GDPR.
3.2. Providing Services
Where a service agreement has been concluded, we process personal data to provide the agreed consulting, relocation, immigration, and application-support services and to communicate with you regarding your matter.
Legal basis: Article 6(1)(b) GDPR — performance of a contract.
3.3. Compliance With Legal Obligations
We may process personal data where necessary to comply with applicable accounting, tax, regulatory, record-keeping, or other legal obligations.
Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation.
3.4. Legitimate Interests
Where appropriate, we may process personal data on the basis of our legitimate interests, including:
• protecting the security and integrity of our website and information systems;
• preventing misuse, fraud, or security incidents;
• managing and documenting business communications;
• maintaining appropriate business records;
• establishing, exercising, or defending legal claims.
Legal basis: Article 6(1)(f) GDPR.
We rely on legitimate interests only where those interests are not overridden by your interests, fundamental rights, or freedoms.
3.5. Consent
Where processing requires your consent, we will request it separately and explain the relevant purpose.
Legal basis: Article 6(1)(a) GDPR and, where applicable, Article 9(2)(a) GDPR.
You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to comply with applicable legal obligations.
As a general rule:
• information relating to inquiries that do not result in a client relationship is normally retained for up to 12 months after the last substantive communication and then securely deleted or anonymised, unless a longer period is reasonably necessary (for example, where a follow-up communication is expected or a legal claim is reasonably anticipated);
• personal data processed for the performance of a service agreement is retained for the duration of the client relationship and thereafter only for as long as necessary for legal, contractual, accounting, tax, or legitimate record-keeping purposes;
• accounting records and documents are retained for the period required by applicable Estonian law;
• personal data relevant to an actual or reasonably anticipated legal dispute may be retained for the period necessary to establish, exercise, or defend legal claims;
• technical and security logs are retained only for the period reasonably necessary for security and operational purposes.
Different categories of information may therefore have different retention periods.
When personal data is no longer required, it will be securely deleted or anonymised, subject to applicable legal requirements and reasonable technical limitations relating to backup systems.
5. Data Security
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Depending on the relevant system and processing activity, these measures may include:
• encrypted communications, including SSL/TLS;
• access controls and authentication measures;
• restriction of access according to operational need;
• appropriate confidentiality requirements;
• secure storage and communication practices;
• appropriate management of service providers and access permissions.
No electronic transmission or storage system can be guaranteed to be completely secure. We therefore regularly consider the nature and sensitivity of the information processed and apply safeguards appropriate to the associated risks.
Where a personal data breach occurs, we will assess it and, where required by Articles 33 and 34 GDPR, notify the competent supervisory authority and/or affected individuals.
6. Sharing Personal Data
We do not sell personal data.
We may disclose personal data only where necessary for the relevant purpose, including to the following categories of recipients.
6.1. Service Providers
We may use service providers that process personal data on our behalf, such as providers of:
• website hosting and technical infrastructure;
• email and communication services;
• document storage or business software;
• IT support and security services.
Where a service provider acts as our processor, we take appropriate measures required by Article 28 GDPR, including entering into a data processing agreement where required.
Our website is currently built and/or hosted using Framer infrastructure. As our technical infrastructure may change over time, the specific providers used by us may also change.
6.2. Professional and Service Partners
Where necessary for the service you have requested, personal data may be shared with relevant professional or service partners, such as:
• notaries;
• translators and translation service providers;
• business registration or corporate service providers;
• accountants or tax specialists;
• other professional advisers or service providers involved in your matter.
Depending on the circumstances, such recipients may act as independent data controllersrather than processors acting on our instructions — for example, a notary certifying a document or a public translator issuing a certified translation typically determines the purposes and means of their own processing under their applicable professional obligations, independently of NordVisa.
Where a partner acts as an independent controller, they are responsible under the GDPR for their own processing of your personal data, and requests concerning that specific processing (for example, access, rectification, or erasure requests relating to work carried out by that partner) should be directed to the partner in question. We will, where reasonably possible, assist you in identifying the correct contact for such a request.
We disclose personal data to such recipients only where reasonably necessary for the requested service and where you have been informed of the disclosure, or where disclosure is otherwise permitted or required by law.
6.3. Public Authorities
Where necessary for the service you have requested, or where required or permitted by law, personal data may be submitted or disclosed to competent public authorities or other official bodies.
Depending on the relevant matter, these may include immigration, citizenship, consular, taxation, business registration, or other competent authorities.
Such authorities generally process personal data as independent data controllers under the laws applicable to them, and are themselves responsible for that processing.
7. International Data Transfers
Some service providers or communication platforms used by us may process or store personal data outside the European Economic Area (EEA).
Where personal data is transferred outside the EEA, such transfers are carried out in accordance with Chapter V of the GDPR and, where applicable, on the basis of:
• an adequacy decision adopted by the European Commission;
• Standard Contractual Clauses approved by the European Commission;
• another transfer mechanism recognised under the GDPR.
Depending on your chosen method of communication, third-party communication platforms such as WhatsApp or Telegram may process personal data in accordance with their own privacy policies and international data transfer arrangements.
You may contact us for further information regarding international transfers relevant to the processing of your personal data.
8. Cookies and Similar Technologies
Our website may use cookies or similar technologies that are technically necessary for the website to function correctly, maintain security, or provide features requested by the visitor.
We do not currently use cookies for third-party behavioural advertising or marketing tracking and do not currently use Google Analytics or Meta Pixel.
Our current website infrastructure may place technically necessary cookies or use similar technologies required for the operation, delivery, or security of the website.
Where we introduce analytics, advertising, marketing, or other non-essential cookies or similar technologies that require consent, we will provide an appropriate consent mechanism before such technologies are activated.
Where appropriate, additional information may be provided in a separate Cookie Policy.
9. Automated Decision-Making
We do not use personal data for solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
Any decision taken by an immigration, consular, citizenship, registration, or other public authority is made independently by that authority and is not an automated decision made by NordVisa.
10. Your Rights Under the GDPR
Subject to the conditions and limitations provided by applicable law, you may have the right to:
• access your personal data and receive information about how it is processed;
• rectify inaccurate or incomplete personal data;
• request erasure of personal data where the conditions of Article 17 GDPR are met;
• restrict processing in the circumstances provided by Article 18 GDPR;
• object to processing based on legitimate interests in accordance with Article 21 GDPR;
• receive your personal data in a portable format where the conditions of Article 20 GDPR apply;
• withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
• object at any time, free of charge, to the processing of your personal data for direct marketing purposes, including any related profiling, in accordance with Article 21(2) GDPR — if you exercise this right, we will stop such processing;
• lodge a complaint with a competent data protection supervisory authority.
Please note that where personal data is processed by a professional or service partner acting as an independent controller (see Section 6.2), or by a public authority (see Section 6.3), these rights should be exercised directly against that controller in relation to their own processing.
To exercise your rights in relation to processing carried out by NordVisa, contact us at:
or:
Meretime Grupp OÜ (NordVisa) Uus-Sadama tn 21-207, Kesklinna linnaosa, 10120 Tallinn, Harju maakond, Estonia
We will respond to requests without undue delay and in any event within one month of receipt, as required by Article 12(3) GDPR.
Where permitted by the GDPR, this period may be extended by up to two additional months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension and the reasons for it within one month of receiving your request.
Where we have reasonable doubts concerning the identity of the person making a request, we may request additional information necessary to confirm their identity.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) if you believe that your personal data has been processed in violation of applicable data protection law.
Andmekaitse Inspektsioon Tatari 39, 10134 Tallinn, Estonia Email: info@aki.ee Website: www.aki.ee
11. Data Protection Officer
We have not appointed a Data Protection Officer. If you have any questions or concerns about how we process your personal data, please contact us using the details provided in Section 16.
12. Provision of Personal Data
Certain personal data is necessary for us to assess your inquiry, enter into or perform a service agreement, or provide the service you have requested.
You are generally not required to provide personal data to us unless it is necessary for the requested service or required by applicable law.
If you do not provide information that is necessary for a particular service, application, or procedure, we may be unable to provide some or all of the requested services.
13. Children’s Personal Data
Our services are not marketed or offered directly to children, meaning individuals under the age of 18.
However, immigration, residence, citizenship, family reunification, and relocation matters may require us to process personal data relating to children or other minors as part of services provided to their parents, guardians, or families.
Where this occurs, we process children’s personal data only where it is relevant and necessary for the requested service and in accordance with applicable data protection requirements.
Where appropriate, communications and instructions concerning a minor’s matter will be handled through the minor’s parent, legal guardian, or other authorised representative.
14. Sources of Personal Data
We normally obtain personal data directly from you.
Where relevant to the service you have requested, we may also receive personal data from:
• your authorised representatives;
• family members or other persons involved in your matter;
• professional or service partners involved in providing the requested service;
• public authorities, registers, or publicly available official sources, where permitted by law.
This section applies only where we actually receive personal data about you from a source other than yourself.
Where Article 14 GDPR applies, we will provide the required information within the time limits prescribed by the GDPR, including, where applicable, no later than one month after obtaining the personal data, at the time of our first communication with you, or before the personal data is first disclosed to another recipient, whichever applies in the circumstances.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, processing activities, technical infrastructure, service providers, or applicable legal requirements.
The current version will be published on our website together with the applicable “Last updated” date.
Material changes may be communicated through additional appropriate means where required.
16. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns regarding the processing of your personal data, please contact:
Meretime Grupp OÜ (NordVisa) Registry code: 10858669 Uus-Sadama tn 21-207, Kesklinna linnaosa, 10120 Tallinn, Harju maakond, Estonia Email: info@nordvisa.ee