Quintum OÜ is a company registered in Estonia under registry code 17024619, at Harju maakond, Tallinn, Kesklinna linnaosa, Viru väljak 2, 10111, Estonia. We provide accounting services to companies.
Quintum OÜ is the controller of the personal data described in this notice. Write to privacy@quintum.ee with any question or request about your data.
We collect what any web server records: the pages you open, the time, your browser and device type, and your IP address. We use this to keep the site available and secure and to understand which pages are read. The legal basis is our legitimate interest in running a working website (Art 6(1)(f) GDPR).
If you use a contact form or write to us by e-mail, we process what you send — your name, your e-mail address, the company you write about, and the content of your message — in order to answer you. The legal basis is our legitimate interest in responding to an enquiry, or the steps taken at your request before entering into a contract (Art 6(1)(b) and (f) GDPR).
We may write to Estonian companies to offer accounting services. If you received such a message from us, this section explains it. This is the information required by Article 14 of the GDPR, because we did not obtain the data from you.
| Where did you get my address? | From the open data of the Estonian Business Register (avaandmed), published by the Centre of Registers and Information Systems (RIK) and freely available to anyone. |
|---|---|
| What do you hold? | The company's name and Estonian registry code; the date it was first entered in the register; its VAT number where it has one; the countries of the company's founders as recorded in the register; whether the company has a contact person entered in the register; and the e-mail address the company itself publishes in the register. |
| Whose data is it? | Company data. Where a company e-mail address, or a founder's country of residence, identifies a person, it is personal data and this notice applies to it. |
| Why are you writing to me? | To offer accounting services to companies that appear likely to need them — for example a company with foreign founders, or one that has recently been registered. |
| On what legal basis? | Art 6(1)(f) legitimate interest in offering a relevant business service to another business. We have weighed this against your interests: the data is already public, the message is addressed to a company about its own administration, and you can stop it at any time. |
| How long do you keep it? | 12 months, unless you become a client or ask us to keep your objection on record for longer. |
Two limits we set ourselves, and you can hold us to them:
Your right to object is absolute here. Under Art 21(2) GDPR you may object to direct marketing at any time and without giving a reason, and we must stop. Reply to the message and say so, or write to privacy@quintum.ee. We keep a record of your objection — your registry code and e-mail address on a suppression list — so that we do not contact you again. That record exists only to honour your objection.
To provide accounting services we process the data your business gives us: contact details of the people we deal with, and the accounting source documents, invoices, bank data, payroll data and tax filings we handle on your behalf. The legal basis is the performance of our contract (Art 6(1)(b)) and our legal obligations as an accounting service provider (Art 6(1)(c)).
Quintum OÜ provides accounting services and is therefore an obliged entity under the Estonian Money Laundering and Terrorist Financing Prevention Act (rahapesu ja terrorismi rahastamise tõkestamise seadus, RahaPTS § 2(1) p 7). This section tells you, before we enter into a business relationship, how we process personal data for that purpose.
What we do. Before we begin working for you, and periodically afterwards, we identify and verify the client, its representatives and its beneficial owners; we establish the purpose and nature of the business relationship; we screen against international sanctions lists; and we monitor the relationship on an ongoing basis.
What we process. Identity-document data, personal identification codes, dates of birth, citizenship and residence, beneficial-ownership information, information on the origin of funds and wealth where the law requires it, sanctions-screening results, and records of the checks we carried out.
Legal basis. Article 6(1)(c) GDPR — compliance with a legal obligation to which we are subject. Where special-category or criminal-offence data appear in sanctions or adverse-media results, we process them on the basis of substantial public interest under Article 9(2)(g) and Article 10 GDPR, as given effect by RahaPTS.
Retention. Five years after the end of the business relationship, or longer where a supervisory authority or a court requires it (RahaPTS § 47).
Purpose limitation — this is a limit on us, and you can hold us to it. Personal data we obtain for money laundering prevention is never used for marketing. RahaPTS § 48(2) prohibits it expressly, and our systems keep the two data sets separate: the marketing prospect data described in section 4 is held apart from due diligence data and neither feeds the other.
Your rights are narrower here. We cannot erase due diligence records before the statutory period ends, and where we have reported a suspicion to the Financial Intelligence Unit we are prohibited by law from telling you.
We use service providers who process data on our behalf and only on our instructions: our website host, our e-mail provider, and the accounting software we use to deliver the service. We disclose data to the Estonian Tax and Customs Board and to other authorities where the law requires it. We do not sell personal data.
Your data is held on servers in the European Economic Area. If a provider we use processes data outside the EEA, we rely on the safeguards permitted by Chapter V of the GDPR.
We do not carry out automated decision-making that produces legal effects for you or similarly significantly affects you, and no decision about entering into a contract is taken automatically.
Whether a company receives a message is determined by objective attributes recorded in the public register — its legal form, whether it is active, and whether it publishes an e-mail address in its own contact field — together with the exclusions described in section 4. The order in which messages are sent is determined by registry code.
We do not rank or prioritise recipients by the nationality or country of residence of their founders or managers, and we do not score individuals.
| Data | Period | Basis |
|---|---|---|
| Marketing contact data from the register (section 4) | 12 months from the last verification or the last message we sent you | our own policy — not a statutory period |
| A record that you objected to marketing | kept for as long as we run marketing at all, so that we do not contact you again | GDPR Art 21(3); ESS § 1031(4) |
| Enquiries that do not lead to a contract | 12 months | our own policy |
| Accounting source documents | 7 years from the end of the financial year they relate to | Raamatupidamise seadus § 12(1) |
| Accounting registers, contracts and other business records needed to explain transactions | 7 years | Raamatupidamise seadus § 12(2), and § 12(3) for documents concerning long-term rights and obligations |
| Customer due diligence records (section 6) | 5 years after the business relationship ends | RahaPTS § 47 |
| Other contracts that fall outside the accounting and AML categories above | assessed case by case against the applicable limitation period | TsÜS § 146(1) — three years as a rule, ten years for an intentional breach |
Where a supervisory authority or a court requires longer retention, we keep the data for as long as that requirement lasts.
Why the objection record is not deleted with the rest. If we erased it after 12 months, we would re-import the public register, find your address again and write to you a second time — exactly what you told us not to do. Keeping the minimum needed to honour your objection (your registry code and e-mail address, and the date) is how we make “we must stop” mean something.
You may ask us for a copy of your data, ask us to correct inaccurate data, and — where the law allows — ask us to erase it, to restrict processing, or to receive it in a portable form. Where we rely on legitimate interests, you may object — and for direct marketing that right is absolute (section 4).
These rights are limited where we process data to meet a legal obligation. We cannot erase accounting records before the statutory period ends, we cannot erase customer due diligence records before the period in section 6 ends, and we cannot tell you whether we have reported a suspicion to the Financial Intelligence Unit.
Write to privacy@quintum.ee. We answer within one month.
You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, or to the supervisory authority where you live.
We keep your data on access-controlled systems, we limit who inside Quintum OÜ can see it, and we use encrypted connections for the website and for e-mail in transit.
If we change this notice we publish the new version here with a new version number and date. If a change materially affects how we use data we already hold, we say so.