Privacy Policy

Last updated:

This Privacy Policy explains how personal information is collected, used, stored, and protected when you use Zooks.ee (the “Website”), make inquiries, book or purchase services, or otherwise engage in transactions through the Website.

1. Data Controller

1. The data controller responsible for personal data processed through the Website is as follows:

Legal Entity: KUJIRA OÜ
Registration Code: 17427056
Address: Tornimäe 5, Tallinn, 10145, Estonia
Contact Email: contact@kujira.ee

2. If you have any questions regarding this Privacy Policy or the handling of personal information, please contact us through the Website’s contact form or by email.

2. Information We Collect and Purpose

1. When you make an inquiry, book or purchase services, or otherwise use the Website, we may collect the following information:

  1. Name
  2. Telephone number
  3. Email address
  4. Content of inquiries or messages
  5. Information relating to services booked or purchased
  6. Information relating to orders, payments, and transactions
  7. Any other information voluntarily provided by the user through the Website

2. We use this information for the following purposes:

  1. Responding to inquiries and contacting users
  2. Processing service bookings and orders
  3. Providing purchased services
  4. Communicating with users where necessary
  5. Managing payments and transactions
  6. Handling refunds, cancellations, and other matters necessary in connection with transactions
  7. Creating and retaining records required for accounting, taxation, and other legal purposes
  8. Complying with legal obligations

3. We will not sell or provide personal information obtained from users for third-party marketing purposes without the user’s consent or another lawful basis.

3. Payment Services

1. As a general rule, payments for certain services offered through the Website are processed using third-party payment services, including but not limited to Stripe (the “Payment Services”).

2. Card information and other payment information necessary for payment processing may be processed by the Payment Services. The Website does not directly store full credit card numbers or similar information processed by such Payment Services.

3. The handling of personal information by the Payment Services is subject to the privacy policies and other applicable terms established by the respective Payment Services.

4. To the extent necessary for transaction verification, accounting, refund handling, and other aspects of service provision, the Website may receive from the Payment Services information such as names, email addresses, payment status, transaction amounts, and other transaction-related information.

4. Legal Bases for Processing Personal Data (GDPR)

1. Depending on the purpose of processing, personal data is processed primarily on the following legal bases:

a. Consent

  • Where information is collected on the basis of the user’s consent, including through a contact form, personal data will be processed on the basis of that consent.
  • By checking the consent box and submitting the relevant form, the user is deemed to have consented to the processing of personal data associated with that form.

b. Performance of a contract or steps prior to entering into a contract

  • Personal data necessary for service bookings, purchases, orders, payments, communications with users, and other matters required to provide services requested by the user will be processed for the performance of a contract or in order to take steps prior to entering into a contract.

c. Legal obligations

Where information must be retained or processed in accordance with accounting, taxation, or other applicable laws, personal data will be processed on the basis of the relevant legal obligation.

5. Data Retention Period

1. Personal data will be retained only for as long as necessary to achieve the purposes for which it was collected.

2. Information relating to inquiries will, as a general rule, be deleted within 12 months after the inquiry has been resolved and any necessary communications have ended. However, where retention is necessary to comply with legal obligations or to resolve disputes, the information will be retained for as long as necessary.

3. Information relating to service bookings, purchases, payments, and other transactions will be retained for the period necessary to process the transaction and provide the relevant services, as well as for any period during which retention is required under applicable accounting, taxation, or other laws.

6. Disclosure to Third Parties and External Services

1. To the extent necessary for the provision of services, the Website may disclose personal data to, or have personal data processed by, the following types of third parties:

  1. Payment service providers or financial institutions
  2. Technical service providers necessary for the operation of the Website, email, and other services
  3. Accounting, tax, legal, and other professional service providers
  4. Government authorities or other public bodies where disclosure is required by law

2. In such cases, personal information will be handled only to the extent necessary for the provision of the relevant service or compliance with legal obligations.

3. In connection with the use of third-party services, personal data may be processed in countries or regions outside the EEA (European Economic Area). In such cases, appropriate safeguards will be implemented in accordance with applicable data protection laws.

7. User Rights

1. Under applicable data protection laws, users have the following rights in relation to their personal data, depending on the circumstances:

  1. Right of Access: The right to request access to personal data held by the Website and information concerning its processing
  2. Right to Rectification: The right to request correction of inaccurate or incomplete personal data
  3. Right to Erasure (Right to Be Forgotten): The right to request deletion of personal data where the data is no longer necessary for the purposes for which it was collected, where the processing is unlawful, or in other circumstances provided for under the GDPR
  4. Right to Restriction of Processing: The right to request restriction of the processing of personal data where the accuracy of the data is disputed, where the lawfulness of the processing is in question, or in other circumstances permitted under the GDPR
  5. Right to Data Portability: The right to receive personal data provided by the user, where such data is processed by automated means on the basis of consent or a contract, in a structured, commonly used, and machine-readable format
  6. Right to Object: The right to object to the processing of personal data where such processing is based on legitimate interests, public interest, or other applicable legal grounds
  7. Right to Withdraw Consent: Where processing is based on consent, the right to withdraw that consent at any time

2. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.

3. To exercise any of these rights, please contact us through the Website’s contact form or by email.

4. Users also have the right, under applicable data protection laws, to lodge a complaint with the competent data protection supervisory authority.

5. The supervisory authority in Estonia is Andmekaitse Inspektsioon.

8. In the Event of a Personal Data Leak or Breach

1. If personal data managed by the Website is subject to a leak, loss, unauthorised access, unauthorised disclosure, alteration, or any other personal data breach, the Website will assess the nature and impact of the incident and take necessary measures to prevent further damage and otherwise address the incident appropriately.

2. Where a personal data breach is likely to result in a risk to the rights and freedoms of users, the Website will determine, in accordance with the GDPR and other applicable laws, whether notification to the competent data protection supervisory authority is required.

3. Where notification of a personal data breach to a supervisory authority is required, the Website will notify the competent data protection supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.

4. Where the breach is likely to result in a high risk to the rights and freedoms of users, the Website will, in accordance with applicable laws, notify the affected users of the necessary information without undue delay.

9. Links to External Websites

1. The Website may contain links to external shops, payment services, or other third-party websites.

2. The handling of personal information on such third-party websites or services is subject to the privacy policies established by their respective operators.

3. When accessing a third-party website through the Website, please review the privacy policy of the relevant website.

10. Changes to This Privacy Policy

1. This Privacy Policy may be amended as necessary due to changes in the services provided, operational reasons, changes in laws or regulations, or other circumstances.

2. If material changes are made, the updated content and the latest revision date will be published on this page.