Privacy policy
What Oleks Tech OÜ does with the personal data it controls: your dealership account, your billing, your correspondence with us, and this website.
On this page
- 1. What this policy covers
- 2. Two roles, kept separate
- 3. What we collect
- 4. Why we process it, and on what legal basis
- 5. Cookies and this website
- 6. Who else sees it
- 7. Transfers outside the EEA
- 8. How long we keep it
- 9. How we protect it
- 10. Your rights
- 11. Automated decisions and profiling
- 12. Children
- 13. Changes to this policy
1. What this policy covers
This policy describes personal data for which Oleks Tech OÜ is the controller — meaning we decide why and how it is processed. That is: the people who run a dealership using miraride, the people who write to us, and the visitors to this website.
It does not describe what a dealership does with its own customers' data inside miraride. We do not decide that; the dealership does. See the next section.
2. Two roles, kept separate
We are the controller for your dealership's account, your billing records, and your correspondence with us. We decide why we hold those and we answer for them.
We are a processor for everything you store about your own customers — their names, contact details, driving licence details, rental agreements, and documents. There you are the controller, we act only on your instructions, and the data processing agreement sets out the terms in the form Article 28 of the GDPR requires.
If you are a car buyer or renter who dealt with a dealership that uses miraride, the dealership is your point of contact. Write to us anyway if that is easier — we will tell you who the controller is and pass your request to them rather than leave it unanswered.
3. What we collect
As controller, we hold:
- Account data: name, email address, the language you work in, your role in the dealership, and a cryptographic hash of your password — never the password itself.
- Dealership data: business name, legal identity, address, contact details, and the domain you connect.
- Billing data: the invoices we issue you, what they were for, and whether they were paid.
- Correspondence: the emails you send us and our replies, including any security or data protection request.
- Technical data: server logs holding an IP address, a request identifier, a timestamp, and a user agent, kept for security and fault diagnosis.
- Demo data: the business name and personal name a visitor types to create a demonstration dealership, and nothing else about that visitor.
- Workspace discovery: the email address you submit is used only to look up eligible real dealerships and, when there is a match, send a one-hour read-only link. We store only a digest of that link, not the link itself; unknown addresses are not retained.
- Security and signup data: MFA status and recovery-code digests, server-owned acceptance timestamps, signup offer state, and Cloudflare Turnstile results used to protect public forms.
- Content notices: the reported on-platform URL, explanation, optional legal basis, identity and contact details where supplied, receipt, human review, decision, reasons, notifications, and redress record.
4. Why we process it, and on what legal basis
Every purpose below is tied to a lawful basis under Article 6 of the GDPR.
- To provide the service and administer your account — performance of a contract with you (Article 6(1)(b)).
- To invoice you and keep accounting records — legal obligation under Estonian accounting and tax law (Article 6(1)(c)).
- To keep the service secure, investigate abuse, and diagnose faults — our legitimate interest in a service that stays available and is not attacked (Article 6(1)(f)).
- To answer your messages and tell you about changes that affect your use of the service — performance of the contract, and our legitimate interest in communicating with business customers (Articles 6(1)(b) and 6(1)(f)).
- To create and clean up demonstration dealerships — our legitimate interest in letting a prospective customer evaluate the product without an account (Article 6(1)(f)).
- To receive, assess, decide, and communicate illegal-content notices — compliance with our Digital Services Act duties (Article 6(1)(c)).
7. Transfers outside the EEA
The application, the database, and background processing run on servers in Germany. Personal data is stored in the European Union.
Some providers are established in or can process from the United States. Where a transfer of personal data outside the European Economic Area occurs, it relies on the European Commission's Standard Contractual Clauses together with the supplementary measures described in our security documentation, and on an adequacy decision where one applies. The provider page states the mechanism and role for each one.
8. How long we keep it
We do not keep personal data longer than the purpose requires.
- Operational account and dealership data: for the agreement term, then a thirty-day recovery and export window with active tenant data erased at its end unless a specific legal duty requires longer retention.
- Completed or expired signup requests and closed invitations: thirty days. Used or expired password-reset and session-handoff tokens: twenty-four hours.
- Immutable legal acceptance evidence: three years after termination. It contains the accepted versions, bundle hash, locale, time, actor and encrypted organization identity snapshot, but no IP address.
- Accounting records, including issued invoices: seven years, as required by the Estonian Accounting Act.
- Correspondence: three years from the last message in the thread.
- Illegal-content notices and decision records: while the notice is being handled and for three years after the final decision, so we can demonstrate compliance and address redress or legal claims.
- Application and security logs: no more than ninety days. Scrubbed Sentry error events: no more than thirty days.
- Demonstration dealerships and sessions: deleted automatically when the demonstration period expires and always within twenty-four hours.
- Encrypted backups: removed as the backup retention window rotates, rather than erased record by record.
9. How we protect it
Personal data is encrypted at rest with authenticated encryption under a key derived for each individual value. Each dealership's records are isolated and every query is scoped to the dealership resolved from the request. Sessions are host-only, contact details never reach a log, and access to production systems is limited to the people who operate them.
Our security documentation describes the technical and organisational controls used to protect account and customer data.
10. Your rights
Under the GDPR you may ask us to give you a copy of your personal data, correct it, erase it, restrict how we use it, or provide it in a portable format. You may object to processing we base on our legitimate interests, and where we ever rely on consent you may withdraw it at any time without affecting what came before.
Write to us at the address at the foot of this page. We answer within one month, and we will tell you if we need longer because a request is complex. We do not charge for this, and we will not make it harder than sending an email.
If you think we have handled your data badly, please tell us first — but you have the right to go straight to a supervisory authority. Ours is the Estonian Data Protection Inspectorate, and you may also complain to the authority in the country where you live or work.
11. Automated decisions and profiling
We make no decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you. The software computes rental prices and settlement figures from rules the dealership configured; that is arithmetic on a contract, not a decision about a person.
Optional AI features are user-initiated suggestions that remain invisible until reviewed and accepted by a person. They cannot issue documents, publish listings, save output automatically, or decide a person's rights or access.
12. Children
miraride is a service for businesses. It is not directed at children, and we do not knowingly collect personal data from them. If you believe a child's data has reached us, write to us and we will remove it.
13. Changes to this policy
When this policy changes, the version and date at the top of the page change with it. If a change materially affects how we handle your personal data, we will email you before it takes effect. Previous versions are available on request.