GDPR Compliance
Updated: 10 June 2026
AtalayaSoft OÜ, a company established in Estonia (European Union), complies with the General Data Protection Regulation (Regulation (EU) 2016/679) in all its processing activities. This page summarises our approach; the full detail is in our Privacy Policy and our Cookie Policy.
Principles we apply
- Minimisation: we only collect the data needed to respond to your enquiry or provide the service.
- Genuine consent: non-essential cookies are only set if you accept them, and you can withdraw your consent in one click via "Cookie settings".
- Transparency: purposes, legal bases and retention periods documented and public.
- Safeguarded transfers: EU-US Data Privacy Framework and Standard Contractual Clauses whenever a provider processes data outside the EEA.
- Security: technical and organisational measures in accordance with Art. 32 GDPR.
For our B2B clients
When AtalayaSoft works embedded in a client's team and accesses personal data under the client's responsibility, we act as a data processor and sign the corresponding data processing agreement (DPA) in accordance with Art. 28 GDPR. We routinely work with the compliance requirements of regulated sectors (banking, insurance, healthcare).
Supervisory authorities
Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Data subjects residing in Spain may also contact the Spanish Data Protection Agency (AEPD).
Contact
For any data protection matter or to request our DPA: legal@atalayasoft.com.