Skip to main content
Privacy

Privacy Policy

Effective date: 5 August 2026

This policy explains how Digital License OÜ, trading as IT Solution Plus, collects and uses personal data when you visit itsolutionplus.net, contact us, buy a standard package or engage us for a custom IT project.

1. Controller and contact details

Data controller: Digital License OÜ
Registry code: 17098998
VAT number: EE102801246
Address: Harju maakond, Tallinn, Kristiine linnaosa, Kotkapoja tn 2a-10, 10615, Estonia
Privacy contact: info@itsolutionplus.net
Telephone: +372 5551 1792

2. Personal data we collect

  • Identity and contact data: name, organisation, billing address, email address and telephone number.
  • Order and billing data: products or services ordered, quotation and invoice details, VAT information, payment status, transaction reference and refund history. Payment providers generally process full card or account credentials directly.
  • Project and support data: requirements, technical environment, files, correspondence, call notes, service history, authorized system-access information and work outputs.
  • Website and device data: IP address, browser and device information, timestamps, security logs, pages viewed, referrer information and cookie choices.
  • Preference data: language, communication choices and any marketing consent.

Do not send secrets through ordinary forms or email. Please do not send passwords, private keys, full payment-card details or special-category personal data unless we specifically request a suitable, secure method and the information is necessary for the project.

3. Purposes and legal bases

PurposeTypical legal basis
Respond to enquiries, assess requirements and prepare a quotationSteps requested before entering a contract; legitimate interests for business contacts
Process orders, take payment, deliver services and provide supportPerformance of a contract
Issue invoices, maintain accounts and comply with tax or regulatory dutiesLegal obligation
Protect our website, systems, customers and legal rights; prevent fraud and misuseLegitimate interests and, where relevant, legal obligation
Improve service operation and understand website useLegitimate interests for strictly necessary or privacy-preserving activity; consent where non-essential cookies or similar technology require it
Send optional marketing communicationsConsent, or another lawful basis where expressly permitted

Where we rely on legitimate interests, we assess whether those interests are overridden by your rights and reasonable expectations. You may ask for information about that assessment.

4. When data is required

Some information is needed to prepare a quotation, form a contract, verify authorization, issue an invoice or deliver the service. If required data is not provided, we may be unable to accept or complete the request. Optional fields will be identified where practical.

5. Sources of data

We usually receive data directly from you, your organisation or the person placing an order. We may also receive transaction confirmation from a payment provider, necessary account information from a platform you authorize us to access, or business contact details from lawful public sources.

6. Service providers and other recipients

We disclose personal data only where reasonably necessary to:

  • website hosting, email, support, cloud storage, security and e-commerce providers;
  • payment providers and financial institutions handling a transaction or refund;
  • accounting, tax, legal, insurance and professional advisers;
  • technical subcontractors approved or appropriately engaged for an agreed project; and
  • public authorities, courts or regulators where disclosure is legally required or necessary to protect legal rights.

Providers acting for us are required to protect data and process it only under appropriate instructions. Providers acting as independent controllers apply their own privacy notices.

7. International transfers

Some service providers may process data outside Estonia or the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we use an applicable safeguard, such as the European Commission’s standard contractual clauses, and supplementary measures where appropriate. You may contact us for information about the relevant safeguard.

8. Retention

We keep data only for as long as needed for the purpose collected, including contractual, security, accounting and legal requirements. Typical criteria are:

  • unsuccessful enquiries: generally up to 24 months after the last meaningful contact;
  • order, project and support records: for the engagement and the period needed to establish, exercise or defend legal claims;
  • invoices and accounting records: for the period required by Estonian accounting and tax law;
  • security and server logs: for a limited operational period, normally no longer than 12 months unless an incident requires longer retention; and
  • consent records: while the consent is active and for a reasonable period afterward to demonstrate compliance.

A different period may apply where law requires it, a dispute is ongoing, or data is needed to investigate security or fraud. Data is then deleted, anonymised or securely archived.

9. Security and project access

We use reasonable technical and organisational measures appropriate to the nature and risk of the data. These may include access controls, least-privilege accounts, secure transfer methods, backups and provider due diligence. No internet transmission or storage system is completely risk-free.

If a service requires access to a customer system, we use the access only for the authorized scope. Customers should create temporary credentials where possible and revoke access when the work is complete.

10. Your data protection rights

Subject to the conditions and exceptions in applicable law, you may:

  • request access to your personal data and a copy of it;
  • ask us to correct inaccurate or incomplete data;
  • request erasure or restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • lodge a complaint with a data protection authority.

To exercise a right, email info@itsolutionplus.net. We may request proportionate information to verify identity. We normally respond within one month, subject to any lawful extension for a complex or numerous request.

11. Cookies and similar technologies

Strictly necessary technologies may operate without consent where permitted. We ask for consent before using non-essential analytics, advertising or similar technologies where consent is required. You can change or withdraw your choice through the site’s cookie controls. See our Cookie Policy.

12. Marketing, automated decisions and children

We do not send optional electronic marketing without the required legal basis, and every marketing message will provide a way to opt out. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects. Our services are intended for adults and organisations and are not directed to children.

13. Complaints and supervisory authority

Please contact us first so we can investigate a privacy concern. You also have the right to complain to the Estonian Data Protection Inspectorate or the competent authority in your country of residence or work.

14. Changes to this policy

We may update this policy when our processing, providers or legal duties change. The current version and effective date will be published on this page. Material changes will be highlighted where appropriate.

Privacy questions: info@itsolutionplus.net · +372 5551 1792