GDPR and Data Protection Policy

Last updated: 29 July 2026

Controller: Trementum Analytics OÜ
Registry code: 17397303
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
Data Protection Officer: appointed
Contact for data protection matters: dpo@trementum.net
General contact: contact@trementum.net
1. Introduction
Trementum Analytics OÜ is committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

This Data Protection Policy explains how we collect, use, store, protect and share personal data in connection with our website, communications, recruitment, business operations and services.

This policy should be read together with our Privacy Policy and Cookie Policy.
2. Scope of this Policy
This Policy applies to personal data processed by Trementum Analytics OÜ in connection with:
- visits to our website;
- contact, book demo and careers forms;
- business communications;
- recruitment;
- client and partner relationships;
- service delivery;
- research, monitoring and analytical projects;
- platform operations and support.

Depending on the context, Trementum Analytics OÜ may act as a data controller, processor or joint controller. The relevant role will be determined by the nature of the processing and, where applicable, by the agreement with the client.
3. Definitions
For the purposes of this Policy:
Personal data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on personal data, including collection, storage, use, analysis, disclosure, deletion or anonymisation.
Controller means the organisation that determines the purposes and means of processing personal data.
Processor means an organisation that processes personal data on behalf of a controller.
Data subject means the natural person to whom the personal data relates.
Special category data means sensitive categories of personal data, such as data revealing political opinions, health data, religious beliefs, trade union membership, biometric data or other categories defined by GDPR.
4. Data Protection Officer
Trementum Analytics OÜ has appointed a Data Protection Officer.

The Data Protection Officer can be contacted at: dpo@trementum.net

The Data Protection Officer acts as a contact point for data subjects and supervisory authorities and advises Trementum on data protection compliance, including data protection impact assessments, internal policies, training and privacy-related risk management.
5. Categories of Personal Data We Process
We may process the following categories of personal data.

Website and enquiry data
- name;
- email address;
- organisation;
- job title or role;
- phone number, if provided;
- message content;
- demo request details;
- communication history.

Recruitment data
- name;
- email address;
- phone number, if provided;
- CV, resume or portfolio;
- LinkedIn profile or professional links;
- employment history;
- skills and experience;
- interview notes;
- availability and recruitment communications.

Technical and usage data
- IP address;
- browser and device information;
- operating system;
- referral source;
- pages visited;
- date and time of visit;
- cookie identifiers;
- analytics events.

Client and business contact data
- names and contact details of client representatives;
- organisation and role;
- contract and billing contacts;
- project communications;
- meeting notes and correspondence.

Project and platform data
Depending on the project, Trementum may process data collected from online platforms, public sources, client-provided datasets or other agreed sources.This may include:
- account names or handles;
- public profile information;
- posts and comments;
- media assets;
- metadata;
- URLs;
- timestamps;
- public engagement metrics;
- categories, tags and analytical annotations.

Where project data may include special category data, we assess the lawful basis, necessity, proportionality and safeguards before processing.
6. Sources of Personal Data
We may collect personal data from:
- you directly, when you contact us, request a demo or apply for a role;
- your organisation, if you are a client, partner, supplier or stakeholder;
- website analytics and cookies;
- publicly available online sources;
- online platforms, where permitted and relevant to the project;
- client-provided datasets;
- service providers and professional advisers;
- partners or contractors supporting our operations.
7. Purposes and Legal Bases for Processing
Purpose
Examples
Legal basis
Responding to enquiries
Contact forms, demo requests, follow-up emails
Legitimate interests; steps prior to entering into a contract
Providing services
Platform access, monitoring, reporting, support
Contractual necessity; legitimate interests
Client relationship management
Communications, meetings, proposals, account management
Legitimate interests; contractual necessity
Recruitment
Reviewing applications, interviews, candidate communications
Steps prior to entering into a contract; legitimate interests
Website analytics
Understanding website use and improving content
Consent, where required
Website security and operation
Hosting, technical logs, security monitoring
Legitimate interests
Research and analytical projects
Reviewing applications, interviews, candidate communications
Steps prior to entering into a contract; legitimate interests
Legal and compliance
Accounting, tax, legal claims, regulatory compliance
Legal obligation; legitimate interests
Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
8. Data Processors and Service Providers
We may use trusted processors and service providers to support our operations.

These may include:
- website hosting providers;
- cloud infrastructure providers;
- analytics providers;
- email and communication tools;
- document and productivity tools;
- CRM or business management tools;
- recruitment tools;
- contractors and affiliated companies;
- professional advisers.

We require processors and service providers to process personal data only on our instructions, protect the data appropriately and comply with applicable data protection obligations.

An up-to-date list of key processors and service providers can be requested by contacting dpo@trementum.net.
9. International Data Transfers
Trementum may work with authorised personnel, contractors, affiliated companies and service providers located inside and outside the European Economic Area, including Ukraine.

Where personal data is transferred outside the European Economic Area, we use appropriate safeguards where required. These may include:
- contractual obligations;
- confidentiality commitments;
- access controls;
- internal security measures;
- Standard Contractual Clauses approved by the European Commission;
- other lawful transfer mechanisms available under GDPR.
10. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected.

Typical retention periods include:
Data category
Retention period
Contact and demo enquiries
Up to 24 months after the last interaction, unless a client relationship is established
Careers applications
Up to 12 months after the recruitment process, unless a longer period is agreed or required by law
Website analytics data
According to the applicable cookie or analytics retention settings
Security and technical logs
As long as necessary for security, troubleshooting and website operation
Contract-related or legal records
As long as required for legal, tax, accounting or dispute purposes
Project data
As defined in the relevant client agreement, project scope or data retention schedule
When personal data is no longer needed, we delete, anonymise or securely archive it where required by law or contract.
11. Security Measures
We apply technical and organisational measures appropriate to the nature and risk of the processing.

These may include:
- access controls;
- role-based access;
- authentication measures;
- encryption in transit where feasible;
- secure cloud infrastructure;
- logging and monitoring;
- confidentiality obligations;
- internal access limitation;data minimisation;
- staff and contractor awareness;
- review of processing activities;
- incident response procedures.

No system can be guaranteed to be completely secure, but we take reasonable steps to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
12. Data Protection Impact Assessments
Where processing is likely to result in a high risk to the rights and freedoms of individuals, Trementum may conduct a Data Protection Impact Assessment.

This may be relevant for certain monitoring, analytical, platform or research projects, especially where the scope, scale, sensitivity or context of the data requires additional assessment.

Where required, the Data Protection Officer is involved in DPIA-related review and advice.
13. Data Subject Rights
Under GDPR, data subjects may have the right to:
- request access to their personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- withdraw consent where processing is based on consent;
- request data portability where applicable;
- lodge a complaint with a supervisory authority.

To exercise these rights, contact: dpo@trementum.net

We aim to respond to data subject requests without undue delay and within the timeframe required by applicable law.
14. Cookies and Tracking Technologies
We use cookies and similar technologies on our website.

Some cookies are strictly necessary for the website to function. Others, such as analytics cookies, are used only where permitted and, where required, with consent.

More information is available in our Cookie Policy.
15. Minors
Our website and services are not directed to children.

We do not knowingly collect personal data from children under 16 through our website. If we become aware that we have collected such data without appropriate consent or lawful basis, we will take steps to delete it.
16. Automated Decision-Making
We do not use personal data collected through our website for automated decision-making that produces legal or similarly significant effects on individuals.

If automated processing is used in a client project, its scope, purpose and safeguards will be determined by the relevant agreement and applicable data protection requirements.
17. Supervisory Authority
Trementum Analytics OÜ is established in Estonia.

If you believe that your personal data has been processed unlawfully, you may contact us at dpo@trementum.net.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate:
Andmekaitse Inspektsioon
Website: aki.eeEmail: info@aki.ee
Address: Tatari 39, 10134 Tallinn, Estonia
18. Updates to this Policy
We may update this Data Protection Policy from time to time.

The updated version will be published on this page with a new effective date.
19. Contact
For questions about this Policy, data protection practices, data subject rights or the list of processors, contact:

Data Protection Officer
Trementum Analytics OÜ
Email: dpo@trementum.net