Protection of personal data

Bestnet personal data processing notice

Bestnet AS (registration code: 10261109) and its subsidiaries (” Bestnet” or “Our”) are companies belonging to the AVH group of companies, which are active in the metal industry, e.g. providing surface coatings, manufacturing and selling trailers, providing trailer rental services.

The protection of your personal data is very important to Bestnet. Bestnet’s Privacy Notice (hereinafter  Notice) explains how we process your personal data (e.g. how we collect, use and protect it) and what your rights are in relation to the processing of your personal data.

When processing your personal data, we comply with Estonian and European Union law, including Regulation (EU) No 2016/679 of the European Parliament and of the Council (hereinafter the General Regulation).

According to the notice, the data controller is Bestnet, alone or in several persons.

In addition, in certain cases, the controller of personal data may be the AVH Group or others.

AVH group companies, but only if this is in accordance with the applicable legislation.

Bestnet processes your personal data only for the purposes for which we collected the data from you and to the extent necessary for the fulfilment of those purposes. If the purpose for which we process your personal data has been fulfilled and there is no other basis or obligation to process your personal data, we will delete your personal data. The notice provides information, for example, when you use Bestnet’s products, services, applications, e-environments (e.g., online shop on the Internet that allows customers to make transactions) or visit Bestnet’s websites.

The notice does not reflect the processing of data by other companies’ products, services, applications, websites, etc., even if it is possible to use them through our services or to access other websites or e-environments through Bestnet’s websites or e-environments.

Bestnet allows you to access the Notice at any time through Bestnet’s websites and at Bestnet’s office at Rae 4, Paldiski 76805 Lääne-Harju parish.

We will refer to, including allow access to, the Privacy Notice, for example, when entering into a contract, when offering and selling a service or product, or when providing an e-service (including an online shop). The notice is an informative document and does not form part of any contract with you.

Subject to your best efforts to keep the Notice up to date and available to you in the ways set out above. We will notify you of changes to the Notice through Bestnet’s websites or other reasonable means.

The Alexela Group’s personal data processing policy and the list of companies belonging to the Alexela Group can be found here.

Personal data and what personal data Bestnet processes

Personal data is information about an individual, i.e. a natural person (before and after Your or Data Subject) through which a natural person is or can be identified, directly or indirectly. For the sake of clarity, we have divided your personal data into the following categories:

  • Examples of personally identifiable information include: first and last name, personal identification number, date of birth, language of communication, identity document number (e.g. passport, ID card, driving licence), etc;
  • Examples of contact details are: e-mail address, address, telephone number, etc;
  • Examples of data relating to the offer or provision of a service and the offer or purchase of a product are: data relating to the performance of a contract, data relating to the consumption of a service, data relating to the purchase of a product, applications, enquiries, complaints, payment information, etc;
  • Examples of financial data are: credit or debts or transactions, etc;
  • Examples of communication data include: customer communications with Bestnet by telephone, data collected via email, data collected via social media, data transmitted via messaging, etc;
  • Special categories of personal data include: racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, ethical data, biometric data used to uniquely identify a natural person, health data or data concerning a natural person’s sex life or sexual orientation.

Bestnet does not aim to collect sensitive personal data, but it may become known to Bestnet inadvertently, e.g. if you send your sensitive personal data to Bestnet by e-mail and/or via the online shop.

Collection of personal data

Bestnet collects your personal information from various sources. The type of personal data collected will depend on, for example, what products you want to buy, services or e-environments you want to use (e.g. ordering from an online shop), what personal data is necessary to provide them. Of course, the extent to which you consider it necessary to transfer personal data to Bestnet and the consents you give to Bestnet to process your personal data are also important.

We base our collection of personal data on the principles set out in the General Regulation (e.g. the principles of minimisation and purpose limitation).

For example, we collect your personal information in the following ways:

  • When offering and/or buying a product (e.g. from an online shop);
  • When using the Service;
  • When subscribing to newsletters;
  • Making requests for information (e.g. price enquiries), complaints, etc;
  • We may also obtain your personal data from other sources, as necessary, should this prove necessary for the conclusion, performance, performance or enforcement of a contract or to comply with legal obligations.

Grounds for and purposes of the processing of personal data

The processing of personal data must be justified and in accordance with the principles governing the processing of personal data. There are several legal grounds for processing personal data under the General Regulation, but in this case Bestnet processes personal data on the following grounds: for the performance of legal obligations, for the conclusion and performance of a contract, on the basis of Bestnet’s legitimate interest and with the data subject’s consent.

We therefore process your personal data on four different legal bases. Please note that there are different retention periods for the processing of your personal data and you have different rights to influence the processing of your personal data. More information on this can be found in the text below.

Compliance with a legal or regulatory obligation

Compliance with a legal obligation is the processing of personal data in a way that is required by applicable law and Bestnet is obliged to do so to the extent that Bestnet is required to do so by law. This processing is not at Bestnet’s or your discretion, as it is a legal obligation that must be complied with.

For example, the following objectives fall under this heading:

  • Accounting data;
  • Responding to queries and reporting infringements to public authorities, including supervisory authorities;
  • Notifying individuals of a breach.

Conclusion and performance of the contract, including enforcement.

In this case, the processing of personal data is mainly because we offer and/or sell you products or services, and in order for Bestnet to be able to do so, it is necessary to process your personal data. As in other cases, we will keep the processing of your personal data to a minimum, i.e. we will process your personal data minimally in order to achieve the purpose for which we are processing it.

For example, in this case we process your personal data for the following purposes:

  • Pre-contractual relations, e.g. making an offer;
  • Identification of the person or data subject, including the identification of the data subject’s representative;
  • Order management;
  • Serving the person or data subject, e.g. sending reminders;
  • Fulfilment of a contractual obligation, e.g. delivery of a product;
  • Managing documentation related to contracts;
  • Ensuring contractual quality;
  • Billing, e.g. preparing invoices.

Processing of personal data based on consent

With your consent, we will process your personal data only to the extent and for the purposes for which you have given your consent.

For example, we ask for consent to process personal data for the following purposes:

  • Marketing offers and notifications (SMS, MMS, e-mails, etc.)
  • Transfer personal data to other companies in the AVH group and to processors for marketing purposes.

The consent given by the data subject is freely, freely and unambiguously given. Consent may be withdrawn by the data subject at any time in writing or in a format that can be reproduced in writing (e.g. by sending an e-mail withdrawal of consent form and complying with legal requirements). Consent remains valid until it is withdrawn or until new consent is given. Withdrawal of consent does not have retroactive effect. Depending on the manner in which the consent is given and withdrawn, it may apply for a certain period of time. There may be a longer delay if you give or withdraw consent on paper, in which case Bestnet will not be able to change it quickly in the database.

Legitimate interest

Legitimate interest means Bestnet’s interest in processing personal data in connection with Bestnet’s business activities in order to provide you with better services and products and thereby to improve them. In such a case, we can provide you with the services, products, support, etc. that you expect from Bestnet. We will process your personal data on the basis of legitimate interest where the processing is necessary and compatible with your rights and interests.

For example, we process your personal data on the basis of legitimate interest for the following purposes:

  • Organising campaigns;
  • For data exchange within the AVH group, if necessary;
  • To maintain a customer relationship, e.g. a conversation with Bestnet;
  • Bestnet for the protection of property, e.g. video surveillance.

We consider it necessary to point out that the purposes for which we process personal data under the above legal bases are not exhaustive, but we will always process your personal data in accordance with the law. If you have any questions about the processing of your personal data, we are always happy to answer them. Our contact details can be found in the section at the end of this Privacy Notice, Contact Bestnet.

Recipients of personal data

Personal data may be processed by companies of the AVH group if this is necessary for the management and administrative decisions of the Bestnet company and is in accordance with applicable law.

Bestnet’s partners are companies that process your personal data on Bestnet’s behalf. Under the General Data Protection Regulation, these are Bestnet’s processors. Processors do not use your personal data for any purpose other than to carry out an activity agreed with Bestnet, such as selling or supplying you with a product.

Authorised processors are companies located in Estonia, in the European Union, in the European Economic Area, but in individual cases they may also be located outside this area. In all cases, we have put in place measures to ensure the security of the processing of your personal data in these countries.

If a situation arises in which Bestnet’s cooperation partner is to be regarded as a co-responsible processor under the law, which means that in this case (e.g. when a product is sold) both we and the cooperation partner are responsible for your personal data, then in addition to Bestnet’s terms and conditions, the cooperation partner’s terms and conditions for the protection of personal data also apply.

For a list of Bestnet’s partners and AVH Group companies, click here.

Bestnet may also disclose your personal data to competent public authorities (e.g. the courts, the police) if required to do so by law. We will therefore only transfer personal data in accordance with the law. We may transfer your personal data to whistleblowers if we only do so in accordance with the law.

Anonymous data is not personal data as it does not allow the identification of a natural person. We may process such data for other purposes and for other persons. Also, where such data are subject to additional obligations under the law, we will comply with them.

Retention of personal data

We will retain your personal data for as long as it is necessary to achieve the purpose for which the personal data is processed or for as long as required by applicable law.

In certain cases, we will keep your personal data for longer than the period referred to in the list below, e.g. we will not automatically apply an expiry date in the event of a debt or a dispute.

We think it is important to point out to you that the following list is not exhaustive, but for example, we keep your personal data as follows:

Video surveillance recordings (to be deleted after 1 month at the latest, unless otherwise provided by law); Quotation information, who does not enter into a contract (to be deleted after 2 years at the latest, unless otherwise provided by law);

Events relating to the data subject, e.g. counselling (to be deleted after 2 years at the latest, unless otherwise required by law);

Contractual performance information (e.g. in Estonia for the duration of the contract and for at least 3 years after expiry of the contract);

Accounting data (e.g. in Estonia, we delete after 7 years from the end of the financial year).

Security of processing of personal data

Bestnet uses the necessary IT and organisational security measures to ensure the security of the processing of personal data. Such measures include, for example, the protection of employees, office buildings, technical equipment. Bestnet’s employees are subject to data (including personal data) confidentiality requirements. In addition, training on the protection of personal data is provided.

Bestnet’s cooperation partners, i.e. processors and companies of the Alexela Group, are obliged to ensure up-to-date security measures when processing your personal data.

Processing of personal data for marketing purposes

You can give Bestnet your consent to use your data for direct marketing purposes. If you have given your consent, you will be able to receive marketing offers and notifications from us and our partners via an e-mail channel (e.g. SMS, e-mail).

Consents to process data for direct marketing purposes will be taken separately from other terms and conditions of the contract, for example by ticking the box that you wish to receive offers. If you only wish to be subscribed to Bestnet marketing offers or communications, some Bestnet websites allow you to do so. To do this, you simply need to enter your e-mail address on the website and then confirm in an e-mail sent to the same e-mail address that you agree to receive future marketing offers and notifications. You will then receive general Bestnet and partner offers.

This consent can be withdrawn at any time by using the opt-out link at the end of the marketing offer or by sending an email to loobu@tiki.ee or by any other means provided by us.

Your rights regarding your personal data

You, or your representative where you have given him or her the appropriate rights, have the following rights in relation to your personal data:

  • The right to access your personal data (e.g. the sources and purposes of their use) in accordance with the applicable law and to the extent provided for in the applicable legislation;
  • The right to request the modification and/or rectification of your personal data in accordance with the procedure and to the extent provided for by applicable law;
  • The right to request the restriction or erasure of the processing of your personal data in accordance with the procedure and to the extent provided for by applicable law;
  • The right to object to the processing of your personal data where we process your personal data on the basis of a legitimate interest.
  • The right to request the transfer of data in accordance with the procedure and to the extent provided for in the applicable legislation. Please note that this right is limited under the legislation in several ways;
  • The right to apply to Bestnet, the supervisory authority or the courts. If you wish to receive more information about the processing of your personal data, you can always contact us via the contact details published on Bestnet’s website(https://www.bestnetgroup.com/).

If you feel that the information you have received was not sufficient or you believe that the terms and conditions for processing your personal data have been breached, you can contact Alexela’s Data Protection Specialist (andmekaitse@tiki.ee). You also always have the right to seek the protection of your personal data from the Data Protection Inspectorate or the courts. The Data Protection Inspectorate is the national supervisory authority to which you can turn for advice or assistance on personal data.

These rights are not necessarily absolute and are governed by existing European Union and national legislation.

Use of cookies

Cookies are small text files that are downloaded to the user’s computer when using a website, and as a result, the browser is able to transmit cookie information each time the website is used. Cookies are designed to improve and simplify the visitor’s experience on a website.

You can choose to disable cookies from your browser devices. However, in some cases, this may, for example, slow down the browsing of a web page, or reduce the functionality of a particular web page. At the moment, Bestnet websites contain links to third-party websites and services and social media extensions (e.g. Facebook). These extensions are mainly designed for statistical or marketing purposes. Third-party extensions on Bestnet’s websites are subject to the third-party privacy policy. Therefore, we recommend that you familiarise yourself with their privacy practices.

For more information on how to use and manage cookies in the most common browsers, see:

Internet Explorer: http://support.microsoft.com/kb/278835

Chrome: https://support.google.com/chrome/answer/95647?hl=en

Firefox: http://support.mozilla.org/en-US/kb/Clear%20Recent%20History

Opera: https://help.opera.com/en/latest/web-preferences/

Safari: http://support.apple.com/kb/PH5042

Bestnet AS authorised processors or cooperation partners

Bestnet AS’s partners process Employees’ personal data (hereinafter also referred to as the Data) on behalf of Bestnet AS and the partners do not use the Data for any purpose other than to carry out the activity or activities agreed with the controller, i.e. Besnet AS. For example, such activities may include the provision of services, the sale of products, the storage of contracts and many other activities that involve the processing of personal data.

Not all Bestnet AS’s partners always process all personal data, but process those data whose processing is necessary for the purpose.

Bestnet AS partners are the following companies:

LHV Bank AS
Business registration code: 10539549
Address: Tartu mnt 2, 10145 Tallinn, Estonia
E-mail: info@lhv.ee

ESTO AS
Business registration code: 14180709
Address: Tornimäe tn 2, 15010 Tallinn, Estonia
E-mail: info@esto.ee

Epicor Software Estonia OÜ
Business registration code: 10539549
Address: Tartu mnt 2, 10145 Tallinn, Estonia
E-mail: tteder@epicor.com

Synerto OÜ (Synergy)
Business registration code: 11557740
Address: Peetri tee 20c, Peetri alevik, 75312 Rae vald, Harjumaa
E-mail: info@synerto.eu

Taavi Tarkvara OÜ (Taavi)
Business registration code: 10265337
Address: 5-17 Turu plats, 11611 Tallinn, Estonia
E-mail: info@taavi.ee

Sector Digital OÜ
Business registration code: 14091408
Address: Liivalaia 20a, 10118 Tallinn, Estonia
E-mail: info@sektordigital.com

Notification last modified 01.09.2020.AVH