Submit a request
Submit a request
#personal_data_processing_policy

1. General Provisions

This Privacy Policy has been prepared in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and sets out how Dasten Assets OÜ (the "Controller") collects, processes, and protects personal data, as well as the measures taken to safeguard the rights of individuals.
1.1. The Controller considers the protection of individual rights and freedoms in the course of personal data processing — including the right to privacy and the confidentiality of personal and family matters — to be a fundamental principle and an essential condition of its operations.
1.2. This Policy applies to all information the Controller may collect about visitors to the website https://dasten.eu/.

2. Key Definitions

2.1. Automated processing — the processing of personal data by means of computer systems.
2.2. Restriction of processing — the temporary suspension of personal data processing, except where processing is required to verify or correct the data.
2.3. Website — the collection of content, software, and databases accessible via the internet at https://dasten.eu/.
2.4. Personal data information system — the set of databases containing personal data together with the information technologies and technical infrastructure used to process them.
2.5. Anonymisation — the process of rendering personal data impossible to attribute to a specific individual without the use of additional information.
2.6. Processing of personal data — any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, restriction, erasure, or destruction.
2.7. Controller — any public authority, legal entity, or individual that independently or jointly with others determines the purposes and means of processing personal data.
2.8. Personal data — any information that relates directly or indirectly to an identified or identifiable visitor of https://dasten.eu/.
2.9. Publicly disclosed personal data — personal data that a data subject has made available to an unrestricted audience by providing consent to their disclosure in accordance with applicable law.
2.10. User — any visitor to the website https://dasten.eu/.
2.11. Disclosure of personal data — actions aimed at making personal data available to a specific person or a defined group of persons.
2.12. Dissemination of personal data — any action that makes personal data available to an unrestricted audience, including publication in the media, posting on telecommunications networks, or otherwise enabling access by the general public.
2.13. Cross-border transfer of personal data — the transfer of personal data to a foreign state, a foreign authority, or a foreign individual or legal entity.
2.14. Erasure of personal data — any action resulting in the permanent and irrecoverable deletion of personal data from an information system and/or the physical destruction of data storage media.

3. Rights and Obligations of the Controller

3.1. The Controller is entitled to:
  • request accurate information and documents containing personal data from the data subject;
  • continue processing personal data without the data subject's consent if the data subject withdraws their consent or requests cessation of processing, provided that a lawful basis for continued processing exists under applicable data protection law;
  • independently determine the scope and nature of the measures necessary to fulfil its obligations under applicable data protection legislation, unless otherwise required by law.
3.2. The Controller is obligated to:
  • provide data subjects, upon request, with information about how their personal data is being processed;
  • organise the processing of personal data in accordance with applicable law;
  • respond to requests from data subjects and their authorised representatives in accordance with applicable data protection legislation;
  • provide the relevant supervisory authority with any requested information within 10 days of receiving such a request;
  • make this Privacy Policy publicly available;
  • implement appropriate legal, organisational, and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, restriction, copying, disclosure, dissemination, or other unauthorised actions;
  • cease the transfer, processing, and storage of personal data in the circumstances and manner prescribed by law;
  • fulfil any other obligations imposed by applicable data protection legislation.

4. Rights and Obligations of Data Subjects

4.1. Data subjects have the right to:
  • receive information about the processing of their personal data in a clear and accessible form, provided that such information does not disclose personal data relating to other individuals (unless lawfully justified);
  • request that the Controller rectify, restrict, or erase their personal data where it is incomplete, outdated, inaccurate, unlawfully obtained, or no longer necessary for the stated purpose of processing;
  • object to the processing of their personal data for direct marketing purposes;
  • withdraw consent to the processing of personal data at any time, or request that processing cease;
  • lodge a complaint with the relevant supervisory authority or seek judicial redress in the event of unlawful processing by the Controller;
  • exercise any other rights provided under applicable law.
4.2. Data subjects are obligated to:
  • provide the Controller with accurate personal data;
  • notify the Controller of any changes to their personal data.
4.3. Any individual who provides the Controller with false information, or submits another person's personal data without their consent, shall bear liability in accordance with applicable law.

5. Principles of Personal Data Processing

5.1. Personal data is processed lawfully, fairly, and transparently.
5.2. Personal data is collected for specified, explicit, and legitimate purposes and is not processed in a manner incompatible with those purposes.
5.3. Databases containing personal data processed for incompatible purposes shall not be merged.
5.4. Only personal data that is relevant and necessary for the stated purpose of processing is collected and used.
5.5. The scope and content of the personal data processed is proportionate to the stated purposes. Excessive data collection is not permitted.
5.6. The Controller takes all necessary steps to ensure that personal data is accurate, adequate, and — where necessary — kept up to date. Inaccurate or incomplete data is promptly corrected or deleted.
5.7. Personal data is stored in a form that allows identification of the data subject only for as long as is necessary for the purposes for which it was collected, unless a longer retention period is required by contract or applicable law. Upon fulfilment of the processing purpose, personal data is erased or anonymised.

6. Purposes of Personal Data Processing


Purpose - Communicating with Users via email
Personal Data Processed:
  • Full name
  • Email address
  • Phone number(s)
Legal Basis - Contracts entered into between the Controller and the data subject
Processing Operations:
  • Collection, recording, organisation, accumulation, storage, erasure, and anonymisation of personal data.
  • Sending informational emails to the provided email address.

7. Legal Bases for Processing

7.1. Personal data is processed on the basis of the data subject's consent.
7.2. Processing is carried out to the extent necessary to fulfil obligations arising from international agreements to which the Republic of Estonia is a party, or from applicable Estonian and EU law, including the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
7.3. Processing may be necessary for the administration of justice, the enforcement of a court order, or the execution of acts issued by other competent authorities in accordance with Estonian enforcement proceedings legislation.
7.4. Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the data subject's request prior to entering into a contract.
7.5. Processing is necessary for the purposes of the legitimate interests pursued by the Controller or a third party, provided that such interests do not override the data subject's fundamental rights and freedoms.
7.6. The Controller may process personal data that the data subject has made publicly available or consented to making publicly available.
7.7. The Controller processes personal data that is required to be published or disclosed under applicable law.

8. Collection, Storage, Transfer, and Other Processing Operations

The security of personal data processed by the Controller is ensured through the implementation of legal, organisational, and technical measures in full compliance with applicable data protection legislation.
8.1. The Controller takes all reasonable steps to safeguard personal data and to prevent access by unauthorised parties.
8.2. User personal data will not be disclosed to third parties under any circumstances, except where required by applicable law or where the data subject has explicitly consented to such disclosure for the purposes of fulfilling a civil law contract.
8.3. If a User identifies inaccuracies in their personal data, they may request an update by sending an email to info@dasten.eu with the subject line "Personal Data Update".
8.4. Personal data is retained for as long as is necessary to fulfil the purpose for which it was collected, unless a longer retention period is prescribed by contract or applicable law. A User may withdraw their consent to the processing of personal data at any time by sending an email to info@dasten.eu with the subject line "Withdrawal of Consent to Personal Data Processing".
8.5. Information collected by third-party services — including payment processors, communication platforms, and other service providers — is stored and processed by those parties in accordance with their own terms of service and privacy policies. The Controller is not responsible for the actions of third-party service providers.
8.6. Restrictions imposed by a data subject on the transfer or processing of their publicly disclosed personal data do not apply where processing is required in the public interest as defined by applicable law.
8.7. The Controller maintains the confidentiality of all personal data it processes.
8.8. Personal data is stored in a form that allows identification of the data subject only for as long as is necessary for the purposes for which it was collected, unless a longer retention period is required by law or contract.
8.9. Processing of personal data shall cease upon fulfilment of the processing purpose, expiry of the data subject's consent, withdrawal of consent, a valid request to cease processing, or identification of unlawful processing.

9. Processing Operations Performed by the Controller

9.1. The Controller carries out the following operations on personal data: collection, recording, organisation, accumulation, storage, rectification (updating), retrieval, use, transfer (dissemination, disclosure, provision of access), anonymisation, restriction, deletion, and destruction.
9.2. The Controller may process personal data by automated means, with or without the transmission of data over telecommunications networks.

10. Cross-Border Transfer of Personal Data

10.1. Prior to initiating any cross-border transfer of personal data, the Controller shall notify the relevant supervisory authority of its intention to do so. This notification is submitted separately from the general notification of processing activities.
10.2. Before submitting such notification, the Controller shall obtain the relevant information from the foreign authorities, individuals, or legal entities to whom personal data is to be transferred.

11. Confidentiality of Personal Data

The Controller and any other parties who obtain access to personal data are required to keep such data confidential and must not disclose or disseminate it to third parties without the data subject's consent, unless otherwise required by law.

12. Final Provisions

12.1. Users may request clarification on any matter relating to the processing of their personal data by contacting the Controller at info@dasten.eu.
12.2. Any changes to the Controller's personal data processing practices will be reflected in an updated version of this Policy. This Policy remains in effect indefinitely until superseded by a new version.
12.3. The current version of this Policy is publicly available at https://dasten.eu/.

Dasten Assets OU
12618 Tallinn, Vinkli tn.12, Estonia
© 2026, All rights reserved
Made on
Tilda