01
Introduction
The Regia.ee platform is provided by Codester OÜ (registry code 16353798) to offer a transparent overview of companies registered in the Estonian Business Register. Our service is based on publicly available information and strictly follows the data protection rules of the European Union.
This document explains how we handle personal data related to corporate activities. Our processing is based on the General Data Protection Regulation (GDPR) and Estonian legislation.
02
What Data We Publish
Published data:
- Public data of company board members and owners (name, date of birth)
- Registry data from the Business Register
- Public economic indicators
- Business activities and contact details that are publicly available
Source of data:
All data displayed on the platform comes from public sources—primarily the Estonian Business Register and other official registers. We do not collect data directly from private individuals and do not use non-public information.
Timeliness:
The database is updated automatically every day. Changes in the Business Register are generally reflected on our platform within 48 hours.
03
Why We Publish Data
Main purposes:
- Transaction security – Helping businesses and individuals make informed decisions when choosing business partners
- Increased transparency – Supporting fair competition and a transparent business environment
- Public interest – Providing society with essential information about the economic environment
- Risk mitigation – Enabling assessment of potential business risks before entering into transactions
04
Account and Customer Data
When you create an account or use paid services, we process:
- your name, email address and, if you choose, phone number;
- the organisations you belong to and your roles in them;
- the organisation's billing details (name, registry code, address, email, VAT number);
- the services used and usage (e.g. API requests, monitored companies), invoices and payments.
The purpose is providing the service, billing and customer support. The legal basis is the contract (GDPR Art. 6(1)(b)) and, for invoices, the accounting obligation (Art. 6(1)(c)).
05
Identity Verification for Billing
When you confirm an organisation's billing through eeID (Smart-ID, Mobile-ID, ID-card), we receive from eeID your name, personal identification code, authentication method and time. We store them encrypted; other members see only your name and the last four digits of the code.
We also store the text of the accepted agreement, the time and IP address of acceptance, and email a copy of the agreement to you. The purpose is to establish who is responsible for paying the invoices and to prevent fraud. The legal basis is the contract and legitimate interest (Art. 6(1)(b) and (f)).
06
Technical Data
Our servers log IP addresses, the pages requested and the time. We use them for security, rate limiting and troubleshooting, and keep them for a limited time. The legal basis is legitimate interest (Art. 6(1)(f)).
07
Service Providers
We use the following processors:
- Hetzner Online GmbH – servers and backups (Finland, EU);
- Cloudflare – network protection, DNS, email routing and bot checks (Turnstile);
- eeID – identity verification for billing;
- our email provider (veebimajutus.ee) – sending emails.
- Google Ireland Limited – visitor analytics (Google Analytics), only with your consent, and sign-in with a Google account if you choose it (Google shares your name and email address with us);
Data is stored in the European Union. Cloudflare's and Google's services are global; any transfer outside the EU relies on the European Commission's standard contractual clauses.
08
Retention
- Account data – until the account is deleted;
- Invoices and accounting records – 7 years (Accounting Act);
- Billing confirmations – as long as needed to prove billing responsibility, at least as long as the related invoices;
- Backups – up to 6 months.
09
Your Rights
Under the GDPR you have the following rights:
- Right of access
You have the right to know which of your data we process and how. You may request a copy of your data. - Rectification
If your data is inaccurate or out of date, you can request a correction. Please note that we can only amend data that does not originate directly from official registers. - Erasure
In certain cases, you may request the deletion of your data. This right is limited where retention is required by law. - Restriction of processing
You may request temporary suspension of processing, for example while disputed data is being verified. - Object to processing
You have the right to object to the processing of your data. We will balance your objections against the public interest.
10
Security and Protection
Measures in place:
- Encrypted connections (HTTPS/TLS)
- Identity verification data is encrypted in the database
- Server access only for administrators, with key-based authentication
- Daily encrypted backups
- Rate limiting and protection against automated attacks
12
Contact and Complaints
For data protection questions and requests (e.g. access, rectification, erasure), write to info@codester.ee. We generally reply within one month.
If you are not satisfied with our response to your data protection request, you have the right to file a complaint with the Estonian Data Protection Inspectorate.
Questions?
Write to us: info@regia.ee