Contact us

Privacy policy

Last updated: January 2026

1. Data Controller

TuneUp OÜ
Registry code: 14664287
Address: Pärnu mnt. 139B, 11317 Tallinn, Estonia
Email: info@tuneup.ee

TuneUp OÜ (operating onlineaccounting.ee) is the data controller responsible for processing your personal data collected through this website.


2. What Personal Data We Collect and Why

Contact and Service Request Forms

When you submit a form on our website (such as contact inquiries, company registration requests, legal address service requests, or annual report requests), we collect the information you provide, including:

  • Name
  • Email address
  • Phone number (if provided)
  • Company details
  • Message content and any additional details you supply

  • Purpose: To evaluate your request, communicate with you, fulfill requested services, and manage pre-contractual or contractual relationships.

  • Legal Basis: Performance of a contract or taking pre-contractual steps at your request (GDPR Art. 6(1)(b)), and our legitimate interest in responding to incoming customer inquiries (GDPR Art. 6(1)(f)).

Email & Direct Communication

If you contact us via email, we process your email address, contact information, and the metadata/content of your communication.

  • Purpose: Customer support and business administration.
  • Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) or contract performance (GDPR Art. 6(1)(b)).

3. Web Analytics (Matomo Analytics)

We use Matomo Analytics, a self-hosted web analytics platform installed directly on our own secure servers within the European Union, to aggregate basic usage statistics and improve our website performance.

Matomo is intentionally configured in a privacy-first, cookieless mode:

  • No Cookies or Local Storage: Matomo does not set or read any cookies or browser storage on your device.
  • IP Anonymization: Your IP address is automatically masked by 2 bytes (e.g., 192.168.xxx.xxx) at the immediate point of ingestion, preventing direct identification.
  • No Cross-Site Tracking: We do not track visitors across other websites or create user profiles.
  • Browser Signals: Matomo automatically respects “Do Not Track” (DNT) and Global Privacy Control (GPC) headers set by your web browser.

  • Purpose: Statistical analysis of website usage, technical optimization, and performance monitoring.

  • Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)). Because processing is entirely cookieless and anonymized, consent is not required under EU ePrivacy regulations or Estonian law.

4. Security & Bot Protection (Cloudflare Turnstile)

To protect our contact forms and website against automated spam, bot attacks, and abuse, we use Cloudflare Turnstile.

Turnstile checks non-identifying technical signals from your browser (such as device characteristics and non-personal header data) to verify that a human is submitting the form.

  • Turnstile operates without setting persistent user tracking cookies or processing personal advertising IDs.
  • Purpose: Protecting site functionality, form security, and system integrity.
  • Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) to secure our infrastructure against malicious traffic, categorized as strictly necessary technical processing.

This website does not use cookies for analytics, advertising, remarketing, or user profiling.

Only strictly necessary, temporary technical session state indicators (such as standard web server state or security indicators) may be utilized to ensure core website delivery and navigation. Because no non-essential cookies are set, no cookie consent banner is displayed or required.


6. How Long We Retain Your Data

We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected:

  • General inquiries: Retained for up to 2 years following the resolution of your request, unless a contractual relationship is established.
  • Contractual & Service Data: Retained for the duration of the contract plus applicable legal limitation periods (typically 3–10 years under Estonian civil law).
  • Accounting & Transaction Data: Retained for 7 years to comply with statutory accounting requirements under the Estonian Accounting Act (Raamatupidamise seadus).

Data is safely deleted or anonymized once retention periods expire.


7. Data Processors and Transfers

We do not sell, rent, or trade your personal data. We share personal data only with trusted third-party service providers (data processors) strictly necessary for operating our business, such as:

  • Secure EU-based web hosting and server infrastructure providers
  • Business email and communication infrastructure

All data processors are bound by strict Data Processing Agreements (DPAs) in compliance with GDPR Article 28. If processing involves infrastructure services provided by non-EEA companies (such as Cloudflare for security routing), transfers are protected using EU Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework.


8. Your Data Protection Rights

Under the GDPR, you hold the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of personal data where legal grounds allow.
  • Right to Restrict Processing: Request restricted processing under specific statutory circumstances.
  • Right to Object: Object to data processing carried out under the legal basis of legitimate interest.
  • Right to Data Portability: Receive your data in a structured, commonly used machine-readable format.

To exercise any of these rights, please contact us at info@tuneup.ee.

Right to Lodge a Complaint

If you believe our processing of your personal data infringes on your privacy rights under the GDPR, you have the right to lodge a formal complaint with a supervisory authority:

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee
Website: www.aki.ee

If you reside in another EU/EEA member state, you may also contact your local data protection authority.


9. Data Security

We implement appropriate technical and organizational measures (including HTTPS encryption, access restrictions, and secure server hosting) to safeguard personal data against unauthorized access, loss, alteration, or disclosure.


10. Updates to This Policy

We may periodically update this Privacy Policy to reflect technical or legal changes. The latest version will always be published on this page with an updated date.


11. Contact Us

For any questions regarding this Privacy Policy or your personal data, please contact:

TuneUp OÜ
Email: info@tuneup.ee
Address: Pärnu mnt. 139B, 11317 Tallinn, Estonia

Request an annual report quote