Privacy Policy

Effective date
29 July 2026
Version
1.0
Last updated
29 July 2026
On this page

1. Who we are

This Privacy Policy explains how LNOKS Tech OÜ (“we”, “us”, “our”) collects and uses personal data when you visit https://lnoks.com (the “Website”) or contact us through it.

We are the controller of the personal data described in this Policy.

Legal name LNOKS Tech OÜ
Registry code 17099600
Registered address Harju maakond, Tallinn, Kesklinna linnaosa, Kaupmehe tn 7-120, 10114, Estonia
Email office@lnoks.com
Website https://lnoks.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”). You can raise any privacy question by writing to the email address above.

2. Scope of this Policy

This Policy covers personal data we process as a controller in connection with the Website — that is, data about visitors to the Website and people who submit an enquiry to us.

It does not cover personal data that we process on behalf of our clients while delivering services to them. In those engagements we normally act as a processor, and that processing is governed by the data processing terms agreed with the relevant client rather than by this Policy.

3. Personal data we collect, and why

3.1 Enquiries submitted through our contact form

When you complete the contact form on the Website, we collect:

  • your name;
  • your work email address;
  • your phone number (optional);
  • the service you are interested in;
  • your estimated budget;
  • your ideal timeline;
  • your project details;
  • any attachments you choose to upload; and
  • the page you were on when you opened the form and the button you clicked to reach it, so we can see which part of the Website prompted your enquiry. See Section 4.
Why we use it
To read and respond to your enquiry, to discuss your requirements, to prepare a proposal or quotation, and to keep a record of the exchange.
Where it is stored
Enquiries are held in our own customer relationship management (CRM) system, which we operate ourselves on servers we rent in Frankfurt, Germany. That is the only place they are stored — they are not kept in the platform that publishes this Website. The CRM is accessible only to LNOKS personnel who need it in order to respond to you, and it is not a third party — see Section 5.
Legal basis
Where you are approaching us about a possible engagement, we process this data to take steps at your request prior to entering into a contract (Article 6(1)(b) GDPR). Where you contact us for another reason, or where you write on behalf of an organisation rather than in your own name, we rely on our legitimate interests in responding to enquiries and pursuing our business activities (Article 6(1)(f) GDPR).
Please note
The form is intended for business enquiries. Please do not include, in the free-text fields or in any attachment, more personal data than is necessary — and in particular please do not send us special categories of personal data (such as health, biometric, political, religious or trade union information) within the meaning of Article 9 GDPR. If your attachment contains personal data about other individuals, you are responsible for ensuring you may lawfully share it with us.

3.2 Technical data collected automatically

When you visit the Website, Cloudflare — which hosts, delivers and protects the Website for us — automatically records technical information, including your IP address, browser type and version, device and operating system, referring page, the pages you view, and the date and time of your visit.

Why we use it
To deliver the Website to your device, to keep it secure and available, to detect and block malicious traffic and abuse, and to diagnose technical faults.
Legal basis
Our legitimate interests in operating a secure and functioning website (Article 6(1)(f) GDPR). Some of this processing is also strictly necessary to provide the service you have requested.

3.3 Analytics data

We use two separate measurement tools, on two different legal bases.

Google Analytics (optional, consent-based). Subject to your consent, we use Google Analytics — loaded through Google Tag Manager — to understand how visitors use the Website, for example which pages are viewed and how visitors arrive. It sets cookies on your device. Nothing is loaded and no analytics cookie is set unless and until you accept.

Cloudflare Web Analytics (always on, no cookies). We also use Cloudflare Web Analytics, which produces aggregate visitor counts and page-view statistics. It sets no cookies, stores nothing on your device, and does not track you across sites or sessions. Because it does not store or access information on your device, it does not require consent, and it runs whether or not you accept analytics cookies.

Why we use them
To measure and improve the Website’s content and performance.
Legal basis — Google Analytics
Your consent (Article 6(1)(a) GDPR), which you give through our cookie banner and may withdraw at any time. See Section 4.
Legal basis — Cloudflare Web Analytics
Our legitimate interests in understanding how the Website is used and in improving it (Article 6(1)(f) GDPR). You may object to this processing on grounds relating to your particular situation — see Section 9.

3.4 Data we do not collect

We do not operate user accounts, a client portal, or an online shop, and we do not take payments through the Website. We do not advertise vacancies or collect CVs through the Website. We do not buy personal data from third parties, and we do not sell or rent your personal data to anyone.

We do not use your personal data to make decisions about you by automated means that produce legal effects or similarly significantly affect you (Article 22 GDPR).

4. Cookies and similar technologies

A cookie is a small file placed on your device when you visit a website. Some cookies are necessary for the site to work; others are optional.

We place optional cookies only after you have given consent through our cookie banner. Strictly necessary cookies are set without consent, as permitted by law, because the Website cannot function securely without them.

Cookie / technology Set by Purpose Type Retention
__cf_bm Cloudflare Distinguishes human visitors from automated traffic; protects the Website against abuse Strictly necessary 30 minutes
cf_clearance Cloudflare Records that a security check has been passed Strictly necessary 12 months
lnoks_consent LNOKS (first-party) Records your cookie preferences Strictly necessary 12 months
_ga Google Analytics Distinguishes visitors for statistical purposes Analytics (optional) 2 years
_ga_[container-id] Google Analytics Maintains the analytics session state Analytics (optional) 2 years

Google Tag Manager is used to manage how the above analytics tags are loaded. It does not itself set cookies for tracking purposes.

Other storage on your device

Besides cookies, the Website uses your browser’s session storage for one purpose:

Item Set by Purpose Retention
lnoks:cta LNOKS (first-party) Records which page you were on and which button you clicked when you navigate to our contact form, so that an enquiry can be attributed to the part of the Website that prompted it Deleted when you close the browser tab, or when the enquiry is sent

This item is first-party, is never read by anyone else, contains no identifier for you, and never leaves your browser unless you go on to submit the form — in which case its contents are sent with your enquiry and stored with it (Section 3.1).

Cloudflare Web Analytics (Section 3.3) stores nothing on your device at all.

Managing your choices
You can accept or reject optional cookies when you first visit the Website, and you can change your decision at any time via the “Cookie settings” link in the Website footer. You can also delete or block cookies through your browser settings, though this may affect how the Website works.

We do not use cookies for advertising, retargeting, or cross-site tracking, and we do not use Google Ads, Google Signals, or Google’s advertising features in our analytics configuration.

5. Who we share your personal data with

We share personal data only with service providers who process it on our instructions under a written data processing agreement, and with the recipients set out below. We do not disclose it for any other purpose except where the law requires it.

Recipient Role What they process Location of processing
Cloudflare, Inc. Processor — website hosting, content delivery, DNS, security, and cookieless analytics IP address and technical request data; everything you send to or receive from the Website Global edge network, including servers outside the EEA
Sanity AS Processor — content platform behind the Website Website content and cookie-consent records. No contact-form data. Belgium — Google Cloud europe-west1 (St. Ghislain), inside the EU
DigitalOcean, LLC Processor — infrastructure hosting for our own CRM system Enquiry records and the files attached to them Frankfurt, Germany (FRA1)
Google Ireland Limited / Google LLC Processor — website analytics (Google Analytics and Google Tag Manager) Analytics data (subject to consent) EEA, with possible access from the United States
Our CRM is not a third party
Enquiries — and any file you attach to one — are delivered from the Website into a customer relationship management system that we built and operate ourselves, under the same legal entity named in Section 1. Moving your enquiry into it is not a disclosure to anyone else; it is us moving your data between our own systems, for the purposes set out in Section 3.1. No one outside LNOKS has access to it. The only external party involved is DigitalOcean, which rents us the servers it runs on, and which is listed above.
Attachments
Files you attach are uploaded directly to our own server in Frankfurt. They are stored outside the public area of that server, are not reachable by a public web address, and open only for a signed-in member of our staff who is working on your enquiry. An upload that is never sent with a completed form is deleted within 24 hours.

We may also disclose personal data to our professional advisers (such as lawyers and auditors) where necessary, to public authorities where we are legally obliged to do so, and to a purchaser or successor entity in connection with a merger, acquisition or reorganisation of our business.

6. International transfers

The Website itself runs on Cloudflare’s global edge network, which means pages are served to you from whichever of Cloudflare’s locations is nearest — inside or outside the European Economic Area. Everything you send us through the contact form — your enquiry and any attachment — is stored in the European Union (Frankfurt, Germany), on our own CRM.

Cloudflare and Google are established outside the European Economic Area or may access data from outside it. Sanity stores our content on Google Cloud Platform in the europe-west1 region (St. Ghislain, Belgium), inside the European Union — and it holds no contact-form data in any case. Where personal data is transferred to a country that has not been recognised by the European Commission as providing an adequate level of protection, we rely on appropriate safeguards under Chapter V GDPR — principally the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional technical and organisational measures identified through a transfer risk assessment. Where a recipient is certified under the EU–U.S. Data Privacy Framework, we may also rely on the European Commission’s adequacy decision for that framework.

You may request a copy of the relevant safeguards by contacting us at office@lnoks.com.

7. How long we keep your personal data

Data Retention period
Enquiries that do not lead to an engagement 24 months from our last communication with you, then deleted
Enquiries that lead to an engagement Retained under the contract concluded with you, and thereafter for the periods required by Estonian accounting and limitation-period rules
Server and security logs 12 months
Analytics data 14 months (Google Analytics data retention setting)
Cookie consent records 12 months from the date consent was given or last refreshed

Your enquiry, and any file attached to it, are held in a single system — our CRM — so the periods above apply to one copy rather than to several scattered across different services. A request to access, correct or delete your data is acted on there, and on any backup of it in the ordinary course.

Where we are subject to a statutory retention obligation — for example under the Estonian Accounting Act (raamatupidamise seadus) — we keep the relevant records for as long as that obligation requires, and no longer.

Backups may retain deleted data for a short additional period before being overwritten in the ordinary course.

8. How we protect your personal data

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS), access controls limiting access to staff who need it, multi-factor authentication on business-critical systems, network and application-level protection against malicious traffic, and regular review of our providers’ security practices.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the Estonian Data Protection Inspectorate in accordance with Articles 33 and 34 GDPR.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy of it;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”) in the circumstances set out in Article 17;
  • restrict our processing in the circumstances set out in Article 18;
  • data portability — receive data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means;
  • object to processing based on our legitimate interests, on grounds relating to your particular situation; and
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, write to office@lnoks.com. We will respond within one month of receiving your request, extendable by a further two months for complex requests, in which case we will tell you. We may ask for information to verify your identity before we act. Exercising these rights is free of charge, unless a request is manifestly unfounded or excessive.

You may also complain to the supervisory authority in your EU country of residence or place of work, and you have the right to an effective judicial remedy.

10. Children

The Website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from children, and we do not market to them. If you believe a child has provided us with personal data, please contact us at office@lnoks.com and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or in the law. The current version is always available on the Website, and the effective date at the top shows when it was last revised. Where a change materially affects how we use your personal data, we will take reasonable steps to bring it to your attention.

12. Contact us

Questions about this Policy or about how we handle personal data:

LNOKS Tech OÜ Harju maakond, Tallinn, Kesklinna linnaosa, Kaupmehe tn 7-120, 10114, Estonia
office@lnoks.com