We do not track your movements
No account is required, no advertising profile is created, and your location history is not stored.
- registration and sign-in are not required;
- we do not use advertising trackers or third-party web analytics;
- we do not sell or rent personal data;
- we do not build visitor profiles or location histories;
- emailing us is voluntary.
1. Controller
The controller for TallinnSecrets.ee is MINUFIRMANIMI OÜ. For data protection questions, contact [email protected].
2. What data may arise?
Technical server logs
When a website is opened, the browser necessarily sends the server an IP address, request time, requested address, response status, and general browser and device information. The hosting provider may process these data to deliver the service, maintain security and diagnose faults. We do not use server logs to track people's movements or for marketing.
The legal basis is our legitimate interest in keeping the service operational and secure. Ordinary logs under the operator's control are generally kept for no more than 30 days unless a security incident or legal obligation requires longer retention. The hosting provider may act as a separate controller for its own system logs.
Location permission
If you use the map's “my location” feature, your browser asks for separate permission. The location is used on your device to centre the map. TallinnSecrets.ee does not link it to an account, create a location history, or store your precise location in its database. You can withdraw permission at any time in your browser settings.
Loading the map
Map layers and data may be loaded from the external provider identified on the map. That provider technically receives your IP address and information about the requested map area. Where OpenStreetMap infrastructure is used, the relevant request is also subject to the OpenStreetMap Foundation Privacy Policy. Attribution displayed on the map identifies the current data or map provider.
Emails
If you email us, we process your email address, name (if supplied), message and technical email metadata in order to respond and manage the enquiry. The basis is our legitimate interest in answering communications or taking steps at your request before entering into a contract. Routine correspondence is deleted after its purpose ends, generally within 12 months. Information may be kept longer where required for a dispute, accounting obligation or another legal need.
3. Who can access the data?
Access may be available to authorised persons of the operator and, as necessary, to hosting, email and map service providers. We do not disclose data to data brokers or advertising networks. We may disclose data to a competent authority where legally required.
4. Transfers outside the European Economic Area
We do not plan separate international transfers of personal data. A request may pass outside the EEA when an external technical service or global map cache is used. The relevant provider is responsible for its processing and applicable safeguards; further information is available in that provider's privacy terms.
5. Your rights
Depending on the circumstances, you may have the right to request access, correction or erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. We do not use automated decision-making or profiling.
Send requests to [email protected]. We may request proportionate additional information to verify the applicant's identity. You also have the right to complain to the Estonian Data Protection Inspectorate.
6. Security and changes
We apply technical and organisational safeguards appropriate to the nature of the data. If the service functions or processing change, we will update this notice before the new processing begins and change the update date shown on this page.
Last updated: 18 September 2026