Who is responsible for your data
The controller of personal data is Kidnes OÜ, registry code 12575875, A. H. Tammsaare tee 47, 11316 Tallinn, Estonia. For any questions about your data, write to info@kidnes.ee.
This policy applies to the website kidnes.ee and its forms. Data processing under an accounting services agreement is governed by the agreement and the law.
What data we collect and why
Contact form
Name, company, e-mail, phone and the text of your message. Legal basis — steps taken at your request prior to entering into an agreement. Used only to reply.
Agreement request
Registry code, company name, representative's name, service start date, e-mail, phone, the selected package and services. Basis — preparation of an agreement at your initiative. Using the registry code we pre-fill public details from the Estonian Business Register (name, address, VAT number, beneficial owners) so you do not have to type them. The lookup runs against our local copy of the register's open data — your code is not passed to third parties.
KYC/AML questionnaire
Details of the company, its activities, owners and beneficial owners, representative, countries, banks and volumes, politically exposed person status and sanctions screening. Basis — the legal obligation of Kidnes OÜ as an obliged entity under the Money Laundering and Terrorist Financing Prevention Act. Without this data we cannot start providing services.
Booking a consultation
Bookings run through SimplyBook.it. Data you enter in the booking window is processed by SimplyBook under its own privacy policy; we receive your name, contact details and the chosen time.
Technical data
When any form is submitted we process the IP address and the result of the bot check — solely to block automated submissions. This data is kept for no longer than one hour.
Where the data goes and how long it is kept
Form data goes to our request-processing service, which generates the documents and sends them to Kidnes OÜ's e-mail address and to yours. The service is a conduit, not an archive: an agreement request is kept there until the questionnaire is completed, but no longer than 30 days; after the documents are sent, copies are deleted after 7 days. Contact-form messages are not stored in the service.
Further storage is handled by Kidnes OÜ in its own systems. Identification documents and KYC/AML questionnaires are kept for at least five years after the end of the business relationship — a period set by law. Correspondence and documents relating to the agreement are kept for the term of the agreement and seven years after its end, in accordance with the Accounting Act.
Copies of identity documents are not collected through the website. If they are required, you provide them directly to Kidnes OÜ.
Who we share data with
- Hosting of the website and the request-processing service — a server in the European Union.
- The Kidnes OÜ e-mail service (Elkdata OÜ, Estonia) — delivery of e-mails and documents.
- SimplyBook.it — consultation bookings.
- Google (Google Tag Manager, Google Analytics) and Meta (Meta Pixel) — visitor statistics and advertising, see the cookies section.
- Public authorities — where required by law, including the Financial Intelligence Unit on request.
We do not sell data and do not use it for third-party marketing.
Cookies and statistics
The website uses Google Tag Manager, Google Analytics 4 and Meta Pixel. They set cookies and collect anonymised visitor statistics; Google and Meta may process data outside the EU on the basis of standard contractual clauses. You can disable cookies in your browser settings — the website and forms will keep working. We do not use our own cookies for the forms.
Your rights
You may request access to your data, its correction, erasure, restriction of processing and portability, and you may object to processing. To do so, write to info@kidnes.ee — we reply within 30 days. The right to erasure does not extend to data we are required by law to keep (KYC/AML questionnaires, accounting records).
If you believe we are infringing your rights, you may contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).
Security
Data is transmitted only over an encrypted connection. Server access is by key only; data access is limited to the responsible staff of Kidnes OÜ. We do not keep more on the website than is needed to deliver the documents.
Changes
The current version is always on this page. Material changes will be announced on the website.
Version dated 28 August 2026.