Privacy Policy
Home Privacy Policy
Last updated: May 2026
Trustif Solutions OÜ - Privacy Policy (DPA-aligned)
1. Controller and Contact
Trustif Solutions OÜ (registry code 17079460) processes personal data as described below.
Contact: Trustif Solutions OÜ, registry code 17079460, Valukoja tn 8/2, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia. Email and phone: info@trustif.ee, +372 5624 6020.
2. Role Allocation
For customer whistleblowing platform operations, the Customer is generally the Controller and Trustif is the Processor.
Trustif is Controller for its own business operations such as billing, security telemetry, and support case administration.
3. Data Categories
Service-operation personal data includes primary user contact data and technical logs (for example name, email, phone, IP address, sign-in and change logs).
Whistleblower report content is technically hosted and transmitted for service operation on Customer instruction.
4. Processing Purposes
service delivery and technical administration
security monitoring and incident handling
customer support and contractual communication
billing, accounting, and legal compliance
5. Legal Bases
contract performance and pre-contract steps
legal obligations
legitimate interests for security and service reliability
6. Subprocessors
Render - hosting and runtime infrastructure
Resend - transactional email delivery
Cloudflare Turnstile - anti-spam validation for public forms
Subprocessors are bound by written terms requiring equivalent data-protection safeguards.
7. Data Location and Transfers
Primary storage and processing are intended within EU/EEA infrastructure.
Trustif does not plan non-EU/EEA transfers in normal operation. If one becomes necessary, legal transfer safeguards must be implemented first.
8. Security
Trustif applies appropriate technical and organizational measures, including access restrictions, transport encryption, security logging, and operational controls.
9. Data Subject Rights
Data subjects can request access, rectification, erasure, restriction, objection, and portability where applicable under GDPR.
If data is processed by Trustif on behalf of a Customer, requests should normally be directed to that Customer as Controller.
10. Retention and End of Service
Data is retained only as needed for service and legal obligations. At end of service, Customer data is returned or deleted unless retention is legally required.
11. Changes and Complaints
This policy may be updated. Material updates are published on trustif.ee.
Supervisory authority in Estonia: Andmekaitse Inspektsioon.
See also our Terms and Conditions.

