Legal · Õiguslik
Privacy policy · Privaatsuspoliitika
How Nola (‘we’, ‘us’) processes personal data as a data processor for providers, and as a data controller for provider account holders. In effect from 14 September 2026.
1. Who this applies to · Kellele kehtib
Providers (businesses that publish services on Nola) are data controllers for their own customers' data. Nola is their data processor — see our Data Processing Agreement. Nola is the data controller for provider account and billing data, and for end customers where Nola itself determines the purpose of processing (e.g. platform security, this website).
ET: Teenusepakkujad on oma klientide andmete vastutavad töötlejad. Nola on nende volitatud töötleja (vt andmetöötluslepingut). Nola on vastutav töötleja teenusepakkuja konto- ja arveldusandmete osas.
2. What we collect · Mida kogume
- Account identity: name, email, phone, authentication identifiers (via Clerk).
- Bookings, quotes, messages, and payment status tied to a provider's services.
- Consent records (marketing, cookies, terms/privacy acceptance) and data-request history (export/delete) — kept as evidence of compliance.
- Payment metadata via Stripe/Montonio (card and bank-link details are held by the payment processor, not by Nola).
- Technical logs (IP address, user agent) for security and abuse prevention, and — only with consent — anonymised analytics (Vercel Analytics).
3. Legal basis · Õiguslik alus
Contract performance (running your booking or the provider's business), legitimate interest (fraud prevention, product security), consent (marketing, analytics cookies), and legal obligation (accounting records retained per Estonian law, typically 7 years for invoices).
4. Your rights · Teie õigused
Under GDPR you may access, correct, export, or delete your personal data, and withdraw consent at any time. Signed-in users can do this directly from Account settings ("Download my data" / "Delete my account"). Where a provider is the controller for your data, we forward requests to them within the timelines the DPA requires.
5. Retention · Säilitamine
We keep account and booking data for as long as the account is active, plus any retention period a provider configures (Provider → Privacy & GDPR → Retention). Financial records (invoices, transactions) are retained 7 years per Estonian accounting law even after account deletion, in anonymised form where possible.
6. Sub-processors · Alltöötlejad
The infrastructure providers we use to run Nola are listed, with their purpose and location, on our DPA page.
7. Cookies · Küpsised
We use strictly necessary cookies for sign-in and, only after you accept the cookie banner, an anonymised analytics cookie. You can change your choice at any time via Cookie settings in the site footer (or Account settings when signed in).
8. Contact · Kontakt
For privacy requests or questions, contact us via Contact. We respond within 30 days as required by GDPR Article 12.