CPE Contact Person Estonia

Legal

Privacy Notice

Version 1.3 · 22 August 2026

1. Who we are

Contact Person Estonia is a trading name of JusTrust OÜ, registered in Estonia under registry code 16093920, address Viru väljak 2 (Metro Plaza), 10111 Tallinn, Estonia. JusTrust OÜ holds activity licence FIU000395 from the Estonian Financial Intelligence Unit.

JusTrust OÜ is the controller of the personal data described here. Write to hello@contactpersonestonia.ee with any question or request about your data.

Contact Person Estonia is not a separate company. The same services are also offered by JusTrust OÜ under other names and in packages that include advisory work, at a different price. Whichever name you approach us through, your contract is with JusTrust OÜ.

2. When you visit this website

WhatWhyLegal basis
Google reCAPTCHA on the contact form of our home page: your IP address, device and behaviour data, and cookies set by Googleto stop automated spam submissions Art 6(1)(f) legitimate interest in protecting the form
Google Maps, embedded on our home page to show where our office is: your IP address and browser data are received by Google when that map loadsto show the location of our office Art 6(1)(f) legitimate interest in telling you where to find us

We use no analytics, advertising or tracking tools, and we set no cookies of our own. Our fonts and stylesheets are served from our own server, so no content delivery network or font provider receives your data. This page and our Terms page load nothing at all from third parties — the two items above apply only to the home page.

3. When you write to us through the contact form

We collect the name, e-mail address and message you enter, use them to answer you, and send you an automatic confirmation. Legal basis: Art 6(1)(b) steps taken at your request before entering a contract, and Art 6(1)(f) our legitimate interest in responding to enquiries.

4. If we contacted you first — where we got your details

We may write to Estonian companies to offer our services. If you received such a message from us, this section explains it. This is the information required by Article 14 of the GDPR, because we did not obtain the data from you.

QuestionAnswer
Where did you get my address? From the open data of the Estonian Business Register (avaandmed), published by the Centre of Registers and Information Systems (RIK) and freely available to anyone.
What do you hold? The company's name, Estonian registry code, registered address, field of activity, the date it was entered in the register, and the e-mail address the company itself publishes in the register.
Whose data is it? Company data. Where a company e-mail address identifies a person, it is personal data and this notice applies to it.
Why are you writing to me? To offer Contact Person, Legal Address and Mail Forwarding services to companies that appear likely to need them — for example a company whose own address is outside Estonia.
On what legal basis? Art 6(1)(f) legitimate interest in offering a relevant business service to another business. We have weighed this against your interests: the data is already public, the message is addressed to a company about its own regulatory position, and you can stop it at any time.
How long do you keep it? 12 months, unless you become a client or ask us to keep your objection on record for longer.

Two limits we set ourselves, and you can hold us to them:

We use the e-mail address the company publishes in the register. We do not use the personal contact details of a company's contact person or board member taken from the register for this purpose.

We write to a company once about a given offer. We are not running a sequence, and we do not sell or share the list.

Your right to object is absolute here. Under Art 21(2) you may object to direct marketing at any time and without giving a reason, and we must stop. Reply to the message and say so, or write to hello@contactpersonestonia.ee. We keep a record of your objection so that we do not contact you again — that record is the one thing we keep after you object.

5. When you become our client

DataWhyLegal basis
Company name, registry code, address, contact details to provide the service and to be entered in the Commercial Register as your contact person Art 6(1)(b) contract
Identity data of board members, shareholders and beneficial owners: full name, personal identification code or date of birth, citizenship, identity document data and a copy of the document, address customer due diligence required by law (RahaPTS) Art 6(1)(c) legal obligation
Screening results: politically exposed person status, international sanctions checks due diligence and ongoing monitoringArt 6(1)(c) legal obligation
Correspondence received at our address for your company, and forwarding records to provide Mail Forwarding. This may incidentally contain personal data of the people who wrote to youArt 6(1)(b) contract; Art 6(1)(f) for the sender's data
Payment and billing datato invoice you and keep accounting records Art 6(1)(b) contract; Art 6(1)(c) Accounting Act

Due diligence is required by law, not by us, and it is the same for every client. It does not depend on the fee you pay or the package you choose. We cannot provide the service without it, and we cannot delete the records early.

6. Your data becomes public in the Commercial Register

If you use our Contact Person or Legal Address service, the fact that JusTrust OÜ is your company's contact person, and our address as your company's registered address, are entered in the Estonian Commercial Register and are publicly accessible. Data about a company's board members and shareholders is published by the Register itself under Estonian law.

We cannot restrict or withdraw that publication. It follows from Estonian law, not from your contract with us.

7. Who else receives your data

RecipientWhy
Estonian Commercial Registeras described in section 6
Estonian Financial Intelligence Unit (Rahapesu Andmebüroo) where we are required to report. We are prohibited by law from telling you that we have made such a report.
Estonian Tax and Customs Board, notaries, courts, other authorities where the law requires
Google (Gmail)We keep a copy of correspondence sent to hello@contactpersonestonia.ee in a mailbox operated by Google, so that we can manage and answer it
GooglereCAPTCHA and website resources (section 2)
Our service providers acting on our instructions: hosting, e-mail, identity verification and screening providersto run the service. They may use your data only on our instructions. The current list is available on request.

We do not sell your data and we do not share it for anyone else's marketing.

8. Where your data is kept, and transfers outside the EEA

Our own servers are located in the European Union (Germany).

In addition, a copy of e-mail correspondence sent to hello@contactpersonestonia.ee is held in a mailbox operated by Google, so that we can manage and answer it. Google also processes the data from the reCAPTCHA on our contact form.

Google may process this data outside the EEA, including in the United States. Where such a transfer takes place it relies on the European Commission's adequacy decision for the EU–US Data Privacy Framework or on standard contractual clauses.

9. How long we keep it

DataPeriod
Marketing contact data from the register (section 4)12 months
A record that you objected to marketingkept for as long as needed so that we do not contact you again
Enquiries that do not lead to a contract12 months
Due diligence data and documents, transaction records 5 years after the business relationship ends (RahaPTS)
Contract and service records5 years after the contract ends
Accounting source documents7 years (Accounting Act § 12)

Where a supervisory authority or a court requires longer retention, we keep the data for as long as that requirement lasts.

10. Automated decision-making

We do not make decisions about you by automated means alone. Every decision to accept, refuse or end a business relationship is taken by a person. If this changes, we will update this notice before the change takes effect.

11. Your rights

You may ask us for a copy of your data, ask us to correct inaccurate data, and — where the law allows — ask us to erase it, to restrict processing, or to receive it in a portable form. Where we rely on legitimate interests, you may object — and for direct marketing that right is absolute (section 4).

These rights are limited where we process data to meet a legal obligation. We cannot erase due diligence records before the statutory period ends, and we cannot tell you whether we have reported a suspicion.

Write to hello@contactpersonestonia.ee. We answer within one month.

You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, or to the supervisory authority where you live.

12. Security

Access to your data is limited to the people who need it for their work. Data is protected in transit by encryption and backed up regularly.

13. Changes to this notice

The version number and date at the top always show the current text. We keep earlier versions and can provide them on request.