Privacy Policy

Version 1.0 · In force from

This website sets no cookies, runs no analytics, embeds nothing from anyone else, and serves its fonts from its own domain. There is no form to submit and no account to create.

If you only read this site, the only personal data involved is what any web server unavoidably records in its logs. If you email us, we process your email.

This policy covers gobird.io only. Each of our products publishes its own privacy policy on its own site.

Controller

The controller of your personal data under the General Data Protection Regulation (EU) 2016/679 is:

Company
GoBird OÜ
Registry code
17311365
Address
Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Harju maakond, Estonia
Privacy contact
privacy@gobird.io

We have not appointed a Data Protection Officer, and are not required to under Article 37 GDPR. Privacy questions go to the address above and are answered by us directly.

Server logs

Every request to a web server leaves a record. Our hosting provider writes a log entry for each request to gobird.io.

What is recorded

  • IP address of the requesting device
  • Date and time of the request
  • The page or file requested, and the HTTP status returned
  • Amount of data transferred
  • Referring page, where the browser sends one
  • Browser and operating system, as reported in the user-agent string

Why

To keep the site available and secure, to diagnose faults, and to recognise and stop abuse such as automated attacks.

Legal basis

Article 6(1)(f) GDPR — our legitimate interest in operating a functioning, secure website. We do not use these logs to build profiles, and we do not try to identify individual visitors from them.

How long

Log entries are deleted after retention period, unless a specific entry is needed to investigate a security incident, in which case it is kept until that is closed.

If you write to us

When you send us an email, we process your address, whatever name you sign with, and the content of the message.

Why

To read your message, answer it, and keep a record of the correspondence.

Legal basis

Article 6(1)(f) GDPR — our legitimate interest in responding to people who contact us. Where your message concerns a contract or steps taken before entering one, Article 6(1)(b) GDPR.

How long

We keep correspondence for as long as the matter is open and for a reasonable period afterwards, in case it comes up again. Where a message forms part of an accounting record or documents a contractual obligation, we keep it for as long as Estonian bookkeeping and limitation rules require. Otherwise we delete it once it no longer serves a purpose.

What we do not do

  • We set no cookies on this site and use no local storage.
  • We run no analytics, no tracking pixels, and no session recording.
  • We show no advertising and use no advertising networks.
  • We load no fonts, scripts, styles, images or embedded media from third-party servers — everything on the page comes from our own domain.
  • We carry out no profiling and no automated decision-making within the meaning of Article 22 GDPR.
  • We do not sell, rent or trade personal data, and we never will.
  • We do not combine data from this website with data from any of our products.

Because we set no cookies and no non-essential trackers, there is no consent banner. There is nothing to consent to.

Who else sees it

We share personal data only with service providers who process it on our behalf, under a written processor agreement satisfying Article 28 GDPR:

Hosting
provider name — runs the server that delivers this site and writes the logs described above.
Email
provider name — delivers and stores mail sent to our addresses.

Beyond that, we disclose personal data only where the law requires it — for example to a court or a competent authority acting within its powers.

Transfers outside the EEA

We prefer processors operating inside the European Economic Area. Where a processor stores or accesses data outside the EEA, the transfer is covered either by a European Commission adequacy decision or by the Commission’s Standard Contractual Clauses together with any additional measures the transfer requires. You can ask us which applies at any time.

Your rights

Under the GDPR you have the right to:

  • Access — ask whether we hold personal data about you and receive a copy.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have data deleted where one of the grounds in Article 17 applies.
  • Restriction — have processing limited while a dispute about it is resolved.
  • Portability — receive data you provided in a structured, machine-readable format.
  • Object — object at any time to processing based on legitimate interest, on grounds relating to your situation.

Write to privacy@gobird.io. We answer within one month, as Article 12(3) requires; if a request is genuinely complex we may extend that and will tell you why. Exercising these rights costs nothing.

Complaints

If you think we have handled your data wrongly, tell us first — we would rather fix it. You can also complain to a supervisory authority at any time. Ours is:

Authority
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Address
Tatari 39, 10134 Tallinn, Estonia
Website
www.aki.ee

If you live in another EU or EEA country, you may complain to the supervisory authority there instead.

Children

This website is not directed at children and we do not knowingly collect their personal data. If you believe a child has sent us personal data, write to privacy@gobird.io and we will delete it.

Changes

If how we handle personal data changes, we update this page and change the date at the top. We do not make changes retroactively, and we do not quietly widen what we collect.