We use cookies to enhance your experience. By continuing to visit this site, you agree to our use of cookies. Learn more

    Privacy Policy

    Effective Date: February 3, 2026
    Website: www.fsa.ee

    This Privacy Policy describes how FSA.ee ("we", "us", or "the Platform") processes personal data in accordance with the EU General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws.

    By using FSA.ee, you acknowledge that you have read and understood this Privacy Policy.

    1. Data Controller

    For the purposes of the GDPR, FSA.ee is the data controller responsible for the processing of personal data.

    Contact details for data protection matters are available on www.fsa.ee.

    2. Personal Data We Collect

    We may process the following categories of personal data:

    a) Data You Provide

    • Email address and account credentials
    • Subscription or billing-related information (processed by Stripe; we do not store your full payment card details)
    • Communications with us (e.g., support requests)

    b) Automatically Collected Data

    • IP address
    • Device, browser, and operating system information
    • Usage and interaction data
    • Cookies and similar technologies

    We do not intentionally process special categories of personal data as defined under Article 9 of the GDPR.

    3. Purposes & Legal Bases for Processing (Article 6 GDPR)

    We process personal data for the following purposes and legal bases:

    PurposeLegal Basis
    Provide and operate the PlatformArticle 6(1)(b) – Contract
    Account authentication and securityArticle 6(1)(f) – Legitimate interest
    Platform improvement and analyticsArticle 6(1)(f) – Legitimate interest
    Service communicationsArticle 6(1)(b) – Contract
    Legal and regulatory complianceArticle 6(1)(c) – Legal obligation
    Optional communicationsArticle 6(1)(a) – Consent

    4. Cookies & Tracking Technologies (ePrivacy)

    FSA.ee uses cookies and similar technologies in accordance with applicable EU ePrivacy rules.

    Where required, non-essential cookies are used only after obtaining your consent. You may manage cookie preferences through your browser settings or any cookie management tools provided on the Platform.

    5. Data Recipients & Third Parties

    Personal data may be shared with trusted third parties only where necessary, including:

    • Hosting and infrastructure providers
    • Analytics and monitoring services
    • Payment processors (Stripe, Inc.) – payment data is processed directly by Stripe under their own privacy policy
    • Legal or regulatory authorities where required

    All third parties act as data processors under GDPR and are contractually obligated to protect personal data.

    6. International Data Transfers (Chapter V GDPR)

    Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards are applied in accordance with GDPR, including Standard Contractual Clauses (SCCs) or equivalent legal mechanisms.

    7. Data Retention (Article 5(1)(e) GDPR)

    Personal data is retained only for as long as necessary for the purposes for which it is processed, including legal, accounting, and regulatory requirements. Data no longer required is securely deleted or anonymized.

    8. Data Security (Article 32 GDPR)

    We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including protection against unauthorized access, loss, alteration, or disclosure.

    9. Data Subject Rights (Articles 12–22 GDPR)

    You have the right to:

    • Access your personal data (Article 15)
    • Rectify inaccurate data (Article 16)
    • Request erasure ("right to be forgotten") (Article 17)
    • Restrict processing (Article 18)
    • Data portability (Article 20)
    • Object to processing (Article 21)
    • Withdraw consent at any time (Article 7(3))

    Requests may be submitted using the contact information available on the Platform.

    10. Right to Lodge a Complaint (Article 77 GDPR)

    You have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work, or place of alleged infringement.

    11. Children's Data

    FSA.ee is not intended for individuals under the age of 18, and we do not knowingly process personal data of minors.

    12. Changes to This Policy

    We may update this Privacy Policy from time to time. Any changes become effective upon publication on the Platform. Continued use of FSA.ee constitutes acceptance of the updated policy.

    13. Contact

    For questions regarding this Privacy Policy or personal data processing, please contact us via the information provided on www.fsa.ee.