1. General Information & Data Controller
This Privacy Policy explains how Teakoht OÜ (Registry code: 16835244, registered in Tallinn, Estonia; hereinafter referred to as "we", "us", or "our") collects, processes, and protects your personal data when you visit and use the website teakoht.ee (hereinafter the "Website" or "Service").
We are fully committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Personal Data Protection Act of the Republic of Estonia.
Contact details of the Data Controller:
Company: Teakoht OÜ (Reg. code 16835244)
Address: Tallinn, Estonia (further postal/return details provided upon request)
Email: kontor@teakoht.ee
2. Server Locations & Data Storage
All primary databases, technical logs, and customer information are stored on high-security server infrastructure physically located within the European Union (EU/EEA):
- Primary Hosting & Server Infrastructure: Wavecom AS data center located in Tallinn, Estonia (ISO 27001 certified).
- Cloud & Backup Servers: Hetzner Online GmbH data centers located in Germany (Falkenstein/Nuremberg).
3. Categories of Personal Data We Collect
Depending on how you interact with our platform, we may collect and process the following categories of data:
- Order & Contact Data: Name, phone number, email address, company name and VAT number (if applicable), billing address, and selected shipping destination / parcel locker (Omniva, DPD, SmartPost).
- Payment Information: Transaction ID, payment status, payment method. Note: Full payment card details are never stored on our servers; they are processed securely directly by our licensed payment provider (Stripe).
- Customer Inquiries & Chat Data: Text messages, technical vehicle inquiries (make, model, year, VIN or engine code), uploaded photos or images of damaged/needed parts, and selected technical diagram positions.
- Technical & Usage Data: IP address, device type, operating system, browser type, timestamps, and essential technical Cookies required for session persistence and shopping cart functionality.
4. Legal Bases and Purposes of Data Processing
Under Article 6 of the GDPR, we process your personal data based on the following legal grounds:
- Performance of a Contract (Art. 6(1)(b) GDPR): To process online store purchases, fulfill customer search requests for rare vintage spare parts, coordinate shipping via logistics partners, and send order status updates.
- Legal Obligation (Art. 6(1)(c) GDPR): To comply with statutory accounting, taxation, and consumer protection requirements under Estonian and European Union laws.
- Legitimate Interest (Art. 6(1)(f) GDPR): To ensure platform security, prevent fraudulent activity, maintain technical stability, and optimize the quality and accuracy of part catalog searches.
- Consent (Art. 6(1)(a) GDPR): Where you have granted explicit consent for direct marketing or specific optional communications (which you may withdraw at any time).
5. Use of Artificial Intelligence (AI) and Search Tools
Our website features an intelligent assistant (AI Consultant) and an interactive technical exploded-view catalog (Knowledge Master) to help identify automotive spare parts from historical diagrams and technical documentation.
Important Privacy Guarantee:
- Only technical automotive queries (part names, OEM numbers, vehicle models) and uploaded part photographs are processed by our automated language and vision models (via secure, encrypted API endpoints such as OpenRouter / Google AI / OpenAI).
- Your personal identifying information (name, phone number, email) is never sold, shared, or used to train third-party public AI models.
6. Data Sharing and Third-Party Processors
We do not sell or rent your personal data to third parties. We share data only with trusted, GDPR-compliant service providers strictly necessary to deliver our services:
- Payment Service Provider: Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland) — PCI-DSS Level 1 certified payment gateway for processing credit cards, Apple Pay, Google Pay, and online bank payments.
- Shipping & Logistics Platform: SIA Swotzy (logistics aggregation platform for automated shipping label generation and parcel routing).
- Carriers & Parcel Terminals: AS Eesti Post (Omniva), DPD Eesti AS, and Itella SmartPost for physical delivery of parcels.
- Hosting & Server Infrastructure: Wavecom AS (Estonia) and Hetzner Online GmbH (Germany).
- Order Management & Customer Service: Secure cloud CRM systems (Notion Labs Inc.) protected under Standard Contractual Clauses (SCCs) and GDPR safeguards.
- State Authorities: Law enforcement or tax authorities only when strictly required by mandatory applicable law.
7. Data Retention Period
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Accounting and invoice data: 7 years from the end of the respective financial year in compliance with the Estonian Accounting Act.
- Customer inquiries and chat histories: Retained for the duration of the active inquiry, or deleted upon the customer's request.
- Technical session logs: Retained for a limited security period (up to 90 days).
8. Your Rights under the GDPR
As a data subject residing in the European Union, you have the following guaranteed rights:
- Right of Access (Art. 15 GDPR): You may request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16 GDPR): You may request corrections to any inaccurate or incomplete data.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You may request deletion of your personal data, provided it is not required to be kept by law (e.g. accounting).
- Right to Restriction of Processing (Art. 18 GDPR) & Data Portability (Art. 20 GDPR).
- Right to Object (Art. 21 GDPR) to processing based on legitimate interests.
To exercise any of your rights, please send an email to kontor@teakoht.ee. If you believe your data protection rights have been violated, you also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, website: www.aki.ee, email: info@aki.ee.
9. Cookies and Storage
We use strictly necessary functional Cookies and local storage to maintain your shopping cart, selected language, and active chat session. We do not employ invasive third-party cross-site advertising trackers.
10. Amendments to this Policy
We may update this Privacy Policy from time to time to reflect changes in our legal obligations or operational workflows. The latest version is always accessible on this page.