Legal
Privacy policy
- In force from
- Version
- 2026-08
This site sets no cookies and runs no third-party trackers, so there is nothing here to consent to and no banner to dismiss. The only personal data we collect is what you type into the contact form. This page explains what happens to it.
Who we are
Flexipy OÜ is the controller of the personal data described here. Our registered address is Sepapaja 6, Lasnamäe, Tallinn 15551, Estonia. For anything in this policy, including any request about your data, write to contact@flexipy.com and a person will answer.
What we collect
The contact form: your name, email address, and message, plus optionally your company and a budget range you select. We also record which page you sent it from and in which language, so we can reply in context.
Server logs: our web server processes your IP address in order to serve the page and to rate-limit the contact form against automated abuse. Rate-limit counters live in memory and are discarded when the service restarts. We do not store your IP address alongside your enquiry.
That is the complete list. There is no account to create, no profile built about you, and no data bought from anyone else.
Analytics
We measure page views with Plausible Analytics, which we run on our own infrastructure. It sets no cookies, collects no personal data, and does not follow you between sites. We use it to see which pages are read, not who reads them.
Why we may process your data
Answering an enquiry you sent us: to take steps at your request before entering into a contract, and our legitimate interest in responding to people who contact our business.
Keeping the site available and the form free of abuse: our legitimate interest in operating a working website.
Sending you marketing email: only with your consent, which you may withdraw at any time. We do not add people who sent an enquiry to a marketing list.
Who else sees it
We do not sell personal data and we do not share it for anyone else's marketing.
Two categories of provider process it on our behalf, under contract and only on our instructions: the hosting provider that runs our servers, and the email provider that delivers our mail. We may also disclose data where the law requires it.
Booking a call does not involve a third party either. Our scheduling runs on software we host ourselves, on our own infrastructure, so what you enter when you book a time comes straight to us and is covered by this policy.
How long we keep it
Enquiries that do not become work: 24 months from your last message, so that we have context if you come back, then deleted.
Enquiries that become work: kept for as long as the engagement runs, and afterwards for the period Estonian accounting and limitation rules require.
You can ask us to delete an enquiry sooner and we will, unless we are required to keep it.
Where it is processed
We are an Estonian company and our data is processed inside the European Economic Area. If a provider we use processes data outside the EEA, we rely on the European Commission's standard contractual clauses or an adequacy decision. Ask us and we will tell you which providers are involved.
Your rights
Under the GDPR you may ask us for a copy of your data, ask us to correct it or delete it, ask us to restrict how we use it, object to processing we base on legitimate interest, and ask for your data in a portable form. Where we rely on consent, you may withdraw it at any time.
Write to contact@flexipy.com. We will answer within one month. There is no charge, and you do not have to explain why you are asking.
If you think we have handled your data badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or to the supervisory authority where you live.
Security
The site is served over HTTPS only. Enquiries are stored in our own database, not in a third-party form service, and access is limited to the people who need it to reply to you. No system is perfectly secure; if a breach affects your data and is likely to put you at risk, we will tell you and the regulator as the GDPR requires.
Children
This is a business-to-business service and it is not directed at children. We do not knowingly collect personal data from children. If you believe a child has sent us data, write to us and we will delete it.
Changes to this policy
The version and effective date at the top of this page tell you which text you are reading. If we change anything that affects your rights, we will say so on this page rather than change it quietly.