1. Who Is Responsible
Enigma Labs OÜ is the controller of personal data collected through https://www.enigmalabs.ee and https://www.enigmalabs.ee, and of business relationship data for services contracted with this Estonian entity.
| Company information | Details |
|---|---|
| Legal name | Enigma Labs OÜ |
| Legal form | Osaühing (Estonian private limited company) |
| Registry code | 17166408 |
| VAT number | EE102825316 |
| Registered address | Harju maakond, Tallinn, Kesklinna linnaosa, Juhkentali tn 8, 10132, Estonia |
| Privacy contact | hello@enigmalab.io |
This notice applies to visitors, prospective customers, customer representatives, suppliers and other people who communicate with Enigma Labs OÜ. It does not change the entity or policies applicable to other Enigma Labs domains or to a contract with another company. Our contact email uses the group's shared email domain; the controller for this notice remains Enigma Labs OÜ.
We process personal data under Regulation (EU) 2016/679 (the General Data Protection Regulation, GDPR) and Estonia's Personal Data Protection Act (Isikuandmete kaitse seadus). Cookie and electronic communications rules also apply under Estonia's Electronic Communications Act (Elektroonilise side seadus) implementing the EU ePrivacy framework.
2. Data, Purposes and Legal Bases
We collect information you submit, technical information needed to serve and protect the website, and information provided by your organisation in connection with an engagement.
| Data and source | Purpose | GDPR legal basis |
|---|---|---|
| Contact forms and correspondence: name, business email, phone, organisation, selected country, company size, security requirements, requested service, timeline and message | Answer enquiries, arrange meetings, prepare proposals and follow up on your request | Article 6(1)(f): our legitimate interest in responding to business enquiries and managing business relationships; Article 6(1)(b) where you personally request steps towards, or are a party to, a contract |
| Customer and supplier representatives' contact details, correspondence, contract and order records | Deliver and administer an engagement, communicate with your organisation, handle support and disputes | Article 6(1)(f): operating our business and performing contracts with organisations; Article 6(1)(b) for a contract with you personally |
| Invoice, transaction and accounting information | Billing, tax and statutory recordkeeping | Article 6(1)(c): applicable Estonian accounting and tax obligations |
| IP address, request time, requested URL, browser and device information, error records and security verification results | Deliver the website, prevent automated abuse, rate-limit submissions and investigate failures or attacks | Article 6(1)(f): maintaining secure, available services and preventing fraud and abuse |
| Cookie preferences and records of your choice | Respect and demonstrate your cookie preferences | Article 6(1)(c): meeting applicable consent obligations; Article 6(1)(f): remembering and applying your choice |
| Data from an optional browser feature, if introduced and enabled with your consent | Provide that particular feature | Article 6(1)(a): your consent, obtained before activating the feature |
Required form fields are identified in the form. Without the information needed to understand and respond to an enquiry, we may be unable to deal with it. Submitting an enquiry does not subscribe you to a marketing mailing list. Acknowledgement and follow-up emails respond to your request.
Please avoid sending passwords, payment-card details, sensitive personal data or incident evidence through a general enquiry form. If an engagement requires security evidence, we will agree an appropriate transfer method and processing scope with the customer. Information about customer personnel or users may also come from the customer, its authorised systems or representatives; this is addressed in Section 8.
The website uses automated checks to distinguish legitimate submissions from abuse. You can contact us by email if a form is blocked. These checks do not make decisions about you with legal or similarly significant effects within Article 22 GDPR.
Our services are intended for businesses and are not directed to children. If you believe a child has provided personal data to us without appropriate authorisation, contact us so we can investigate and take appropriate action.
3. Recipients and International Transfers
Access is limited to people and providers who need information for the purposes above, subject to applicable confidentiality and data-protection obligations.
The website uses the following services:
| Provider | Role and information involved |
|---|---|
| Vercel | Website hosting and request handling, including technical request data and contact-form processing |
| Cloudflare | Turnstile bot protection and, where used for delivery, network security; processes technical browser/request signals and verification tokens |
| Resend | Delivery of enquiry notifications and acknowledgement emails; processes contact details and the content of those emails |
| Upstash | Submission rate limiting; processes temporary counters keyed by IP address or email address |
| c15t | Consent management; choices are stored in your browser, and are also handled by the configured consent service when hosted mode is enabled |
Email recipients handling enquiries may include authorised personnel supporting Enigma Labs OÜ through a shared business inbox. We may also disclose necessary information to professional advisers, accountants, insurers, competent authorities or courts where lawful, and in connection with a business reorganisation subject to appropriate safeguards. We do not sell your personal data.
Providers or authorised support personnel may process information outside the European Economic Area (EEA). An Estonian website address does not mean that every provider processes data solely in Estonia. Where a transfer is subject to Chapter V GDPR, it must be covered by a valid adequacy decision or appropriate safeguards, such as the European Commission's Standard Contractual Clauses and any necessary supplementary measures. We use an adequacy framework only where the recipient and relevant processing are covered by it. You can request information about relevant recipients, processing locations and copies of applicable safeguards at hello@enigmalab.io, subject to necessary redactions.
Links to services such as our meeting scheduler, social networks and maps open those services when you choose to follow the link. Their operators provide their own privacy information.
4. Retention
We retain personal data only for as long as needed for its purpose, subject to legal obligations and the establishment, exercise or defence of legal claims.
| Category | Retention period or criteria |
|---|---|
| Enquiries and related correspondence | For the enquiry and resulting business relationship; subsequent retention is limited by the need to follow up, document commitments or resolve claims, with obsolete information deleted |
| Contracts and business relationship records | During the relationship and for applicable statutory retention or limitation periods afterwards |
| Accounting source documents and records | Generally seven years from the end of the relevant financial year under Estonian accounting requirements; longer where a specific legal requirement applies |
| Website/security logs | For operational troubleshooting and security investigation, according to the relevant hosting/security service retention settings; records relating to an incident may be preserved while the incident or related claims are addressed |
| Rate-limit counters | Expire automatically at the end of the configured rate-limit window, currently up to one hour |
| Consent preferences | The consent cookie lasts up to 365 days; a browser local-storage copy may remain until cleared. See the Cookie Policy |
| Personal data processed for a customer | According to the agreed engagement and our Data Processing Agreement |
At the end of the applicable period, we delete or anonymise data. Data preserved to comply with a law or a legal hold is restricted to that purpose.
5. Security and Personal Data Breaches
We use technical and organisational measures appropriate to the nature and risks of processing. Website controls include HTTPS, restricted server-side processing, validation of contact submissions, origin checks, bot protection and submission rate limiting. Access to personal data must be limited to authorised personnel and providers. No system can guarantee absolute security.
When acting as controller, we notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. If notification is later, we explain the reasons. We notify affected individuals without undue delay where the breach is likely to result in a high risk, unless a GDPR exception applies.
When acting as processor, we notify the customer without undue delay after becoming aware of a personal data breach, as described in the Data Processing Agreement.
6. Your GDPR Rights
Subject to the conditions in the GDPR, you may:
- Request access to your personal data and information about its processing.
- Correct inaccurate or incomplete data.
- Request erasure or restriction of processing.
- Receive portable data where processing is automated and based on consent or a contract with you.
- Object, on grounds relating to your situation, to processing based on legitimate interests. We must stop unless we demonstrate overriding compelling grounds or need the data for legal claims.
- Object to direct marketing at any time, in which case processing for that purpose must stop.
- Withdraw consent at any time, without affecting the lawfulness of earlier processing.
- Exercise applicable rights concerning solely automated decisions with legal or similarly significant effects.
Send requests to hello@enigmalab.io, identifying Enigma Labs OÜ and the request. We ask only for additional identity information reasonably necessary to verify a request; do not send an identity-document copy unless it is needed and requested.
We respond without undue delay and within one month of receipt. Where necessary because of complexity or the number of requests, this may be extended by two further months; we will explain the extension within the first month. Requests are generally free. A reasonable fee or refusal is permitted only in the circumstances provided by the GDPR, and we will explain our decision and your complaint rights.
You can complain directly to Andmekaitse Inspektsioon (AKI), the Estonian Data Protection Inspectorate, at https://www.aki.ee, or to a supervisory authority in the EU/EEA country of your habitual residence, place of work or the alleged infringement. You do not have to contact us first. Your rights to a judicial remedy, including under Articles 78 and 79 GDPR, and compensation under Article 82 remain unaffected.
7. Cookies and Browser Data
Our Cookie Policy explains browser storage and how to change your choices using Cookie Settings in the footer.
The Estonian entity is selected by the website domain. We do not send browser timezone or language lists to the regional-selection endpoint on these domains, and we do not set regional-selection cookies there. Old regional-selection cookies encountered on visits are removed. A country signal supplied with a hosting request may be used to prefill the enquiry form; it does not change the legal entity.
The current website application does not embed a live-chat widget or advertising pixels. Optional features requiring consent must remain inactive until you choose to enable them. Security and hosting providers still process technical request information as described above.
8. Personal Data Processed for Customers
For personal data examined in an authorised security audit, penetration test, incident-response engagement, development project or other agreed service, the customer normally determines the purposes and means of processing. Enigma Labs OÜ acts as a processor, or as a sub-processor where the customer itself acts as a processor.
Our Data Processing Agreement governs that processing when incorporated into the engagement. It covers documented instructions, confidentiality, security, sub-processors, transfers, breach assistance, rights requests, audits, and return or deletion. The customer must establish an appropriate lawful basis and inform the affected individuals. Requests concerning data controlled by a customer will be referred to that customer, with our assistance as required by the GDPR.
For these engagements, our infrastructure providers are Vercel, Amazon Web Services (AWS) and Microsoft Azure, with global use across provider regions, subject to the agreed processing scope and applicable transfer safeguards. Enigma Labs personnel may access customer data from the EEA, Canada, the United Arab Emirates and Singapore. The DPA requires disclosure of the applicable provider legal entities, actual processing locations and transfer safeguards before processing begins; a specific residency restriction must be agreed for the engagement. All accounts used by Enigma Labs for the services enforce MFA and access restrictions. Special-category and criminal-offence data are excluded from the standard processing scope. The DPA provides for deletion of residual backups no later than 90 days after service end, unless law requires otherwise.
9. Changes and Contact
We may update this notice to reflect changes to processing or legal requirements. The effective date identifies the published version. We will give an appropriate additional notice of material changes and seek new consent where required. Reading this notice or continuing to browse is not consent to processing that requires consent.
For questions, requests or concerns, write to Enigma Labs OÜ, registry code 17166408, VAT number EE102825316, at Harju maakond, Tallinn, Kesklinna linnaosa, Juhkentali tn 8, 10132, Estonia, or email hello@enigmalab.io.
Estonian law and applicable EU law govern this notice, without restricting mandatory GDPR rights or available supervisory-authority and court remedies.