Privacy policy
How 25dbr OÜ processes personal data under Regulation (EU) 2016/679 (GDPR). Last updated 14 August 2026.
1. Who is responsible for your data
The data controller is 25dbr OÜ, a private limited company registered in Estonia under registry code 16618245, EU VAT EE102794803, registered office Sepapaja tn 6, 15551 Tallinn, Lasnamäe linnaosa, Harju maakond, Estonia.
Data protection contact: privacy@25dbr.com. We have not appointed a Data Protection Officer, as we do not meet the criteria in Article 37 GDPR.
2. What we collect and why
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Contact form: name, email, subject, message | Answering your message | Art. 6(1)(b) pre-contractual steps; Art. 6(1)(f) legitimate interest in business correspondence | 24 months from last contact |
| Consultation enquiry — required fields: company, contact person, email, service type, project description, scope selections | Preparing a technical response and, if it proceeds, a proposal | Art. 6(1)(b) pre-contractual steps taken at your request | 24 months from last contact |
| Consultation enquiry — optional fields: phone, budget band | Replying through the channel you offered, and judging what kind of response is proportionate | Art. 6(1)(f) legitimate interest — an optional field cannot be necessary for a contract, so Art. 6(1)(b) does not cover it | 24 months from last contact |
| Server logs: truncated IP address, timestamp, request path, user agent | Operating the service, diagnosing faults, rate limiting and abuse prevention | Art. 6(1)(f) legitimate interest in a working, non-abused service | 30 days |
| Rate-limit counters: a salted hash of your IP address | Limiting how often a single source can submit forms | Art. 6(1)(f) legitimate interest in preventing automated abuse | 24 hours |
We do not use tracking pixels, advertising cookies, analytics scripts, session recording, or automated decision-making including profiling. Nothing on this site profiles you.
Why the enquiry form has two rows. Article 6(1)(b) only covers processing that is necessary for steps taken at your request. A field the form itself tells you is optional cannot be necessary, so the optional ones — phone and budget band — are listed separately under Article 6(1)(f), with the interest we pursue stated. It is a small distinction that a lot of privacy policies get wrong, and getting it wrong means the published basis does not describe what the form actually does.
We do not ask you to consent
Neither form on this site has an “I agree” checkbox, and that is deliberate. The lawful bases above are Article 6(1)(b) and 6(1)(f) — steps taken at your request, and our legitimate interest in business correspondence. None of this processing relies on consent under Article 6(1)(a).
A checkbox you must tick before the form will submit is not freely given consent, and presenting it as consent would describe our processing as something it is not. Each form instead carries a neutral acknowledgement immediately above its submit button — that by submitting it you acknowledge we will process what you send in order to reply — together with that form's lawful basis and retention period and a link to this policy.
The interface, this policy and the API agree: there is no agreement checkbox, no consent field in the request, and no consent flag stored against your enquiry. Because we do not rely on consent, there is no consent to withdraw — but you can object to processing based on legitimate interest, and ask us to erase your data, at any time (section 4).
3. Processors, and where your data is
In your browser, nothing third-party runs. This website makes no third-party requests at all: web fonts are self-hosted, icons are inline SVG, and there are no embedded maps, videos, social widgets, analytics or content delivery networks. You can confirm this in your browser's network panel — every request goes to 25dbr.com.
On the server, there is exactly one processor. The site and its database run on a virtual server operated by Hostinger International Limited. That server is located in the United Kingdom. Everything submitted through this site — enquiries, messages, application logs and rate-limit counters — is stored on that one machine. We use no separate analytics, monitoring, backup, ticketing or CRM service, and no data is copied to one.
Transfer outside the EEA
The United Kingdom is not part of the European Economic Area, so hosting there is a transfer of personal data to a third country under Chapter V of the GDPR. That transfer takes place under the European Commission's adequacy decision for the United Kingdom, which permits transfers to the UK without additional safeguards, supported by the data processing terms we hold with the hosting company under Article 28.
We state this plainly rather than claiming EEA-only processing, because the claim would not be true and you are entitled to know which country your data sits in. If you would rather not have your data processed in the UK, write to us before submitting a form and we will take your enquiry another way.
Email. Outbound email notification is currently switched off, so no email provider receives anything you submit here — enquiries are written to the database on the server above and read there. When we reply to you, that reply travels through our email provider in the ordinary way, as any business correspondence does.
We do not sell, rent or share personal data with anyone for their own purposes, and we do not use it for advertising or profiling.
4. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have your data erased (Art. 17)
- restrict processing (Art. 18)
- receive your data in a portable format (Art. 20)
- object to processing based on legitimate interest (Art. 21)
Write to privacy@25dbr.com and we will respond within one month. If you believe we have handled your data unlawfully you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, www.aki.ee, or with the supervisory authority in your own EU country of residence.
5. Security
The site is served over TLS. Form submissions are validated and rate-limited server-side, database access uses prepared statements, and application logs deliberately exclude message bodies and form contents. Access to stored enquiries is limited to the people who need it to answer you.
Our internal controls are modelled on ISO/IEC 27001 Annex A. 25dbr OÜ is not certified to ISO/IEC 27001 and makes no claim to be.
6. Changes
If this policy changes materially we will update the date at the top of the page. This version is dated 14 August 2026.