Privacy Notice

1. Introduction

1.1. This privacy notice (hereinafter “Notice”) provides an overview of how Frankenburg Technologies OÜ, registry code 16901751, address Sepise 7, 11415, Estonia (hereinafter “we”) processes as a controller the personal data of the following categories of data subjects:

(i) our website frankenburg.tech (hereinafter “Website”) visitors;

(ii) visitors of our social media platforms, including LinkedIn and X;

(iii) representatives of legal entity clients, suppliers and cooperation partners;

(iv) visitors of our premises;

(v) other persons whose personal data we process in the course of ordinary business activities, including when contacting us (e.g. through the Website, telephone, e-mail or other channels).

1.2. The processing of your personal data is carried out in accordance with applicable data protection legislation, including the General Data Protection Regulation of the European Union (EU) 2016/679 (“GDPR”) and other data protection legislation.

1.3. If you have questions about the processing of your personal data, please contact our data protection officer by e-mail at privacy@frankenburg.tech.

2. Categories and sources of personal data

2.1. Personal data is any information that can be used to directly or indirectly uniquely identify you as a private individual. We process the following categories of personal data, including its collection, use, storage, and transmission:

2.1.1. General identification data: this includes given name and surname, e-mail address, (mobile) phone number (“General Identification Data”).

Data sources: we collect your personal data when (i) you contact us; or (ii) the legal entity you represent provides it to us.

2.1.2. Commercial Data: data related to the conclusion and performance of a contract, including General Identification Data of the contracting party’s representative, job title, name and address of the organisation, customer status, business relationship details such as date of conclusion of the contract, the contract document and its contents, invoices, payments, current account details, communication and transaction history (“Commercial Data”).

Data sources: we collect your personal data directly from you, from the organisation you represent or work for, and, where relevant, from other parties involved in the business relationship or from publicly available sources, including commercial registers, company websites and professional networking platforms. We may collect such data before the contract is concluded, at the time of conclusion and throughout the commercial relationship.

2.1.3. Visitor Data: General Identification Data, personal identification code or date of birth, name of the organisation you represent or work for, the date of your visit and the location visited (“Visitor Data”).

Data sources: we collect personal data from you when you visit our premises, including through access control and registration systems.

2.1.4. Communication Data: General Identification Data, the date and time of the message, and the subject and content of the message (“Communication Data“).

Data sources: we collect personal data from you when you contact us via the Website, by telephone, by e-mail or by other means.

2.1.5. Social Media Data: information which may include General Identification Data, social media user IDs, profile picture, gender, username, age, country, list of friends or followers, and other information that you have made public on your social media platform or that you have consented to share (“Social Media Data“).

Data sources: we collect personal data from you when you visit, follow or interact with our social media channels, or have any other contact with us via our social media channels. We may also collect your personal data from social media platforms (e.g. via LinkedIn Page Insights), where we act as joint controllers for that processing. Further information about that processing is available here for LinkedIn.

2.1.6. Website usage data: data that is automatically generated when you visit and use our Website and which may include your IP address, device information (browser type and version, device type and operating system), date and time of visit, pages or resources requested on the Website (“Website Usage Data“).

Data sources: we collect personal data automatically when you visit our Website.

3. Legitimate interest

3.1. We process your personal data for the following purposes and on the following legal grounds:

3.1.1. Consent

Your consent is required for the processing of personal data for the purposes outlined below. You have the right to withdraw your consent at any time by contacting the data protection officer using the contact details provided in Section 1.3 of this Notice.

Processing purposeCategories of personal data
Development and improvement of Website services, including collecting information about your recent Website visits for analytical purposes so that we can improve the Website functionality and make it more user-friendlyWebsite Usage Data

3.1.2. Compliance with a legal obligation

We process your personal data in order to comply with a legal obligation, where such an obligation arises from a law or other legal act.

Processing purposeCategories of personal data
Organization of accounting, including retention of accounting documentsCommercial Data
Compliance with requirements and obligations arising from legislation and responding to inquiries from public sector and other law enforcement authoritiesAll data categories

3.1.3. Legitimate interest

For these purposes, we process your personal data based on legitimate interests. You have the right to request an explanation regarding the processing of your personal data based on legitimate interests by sending a request using the contact details provided in Section 1.3 of this Notice. You also have the right to object if you believe that the processing of your personal data for the purposes outlined below affects your rights.

Processing purposeCategories of personal data
Taking steps prior to entering into a contract with a business customer or cooperation partner to initiate cooperation, including pre-contractual negotiations and conclusion of a contractCommercial Data, Communication Data, General Identification Data
Performance and administration of the contract with a business customer or cooperation partnerCommercial Data, General Identification Data
Termination of the contract with a business customer or cooperation partner and management of the termination processCommercial Data, General Identification Data
Receiving and responding to inquiries, including feedbackCommunication Data, General Identification Data
Managing visitor access to our premises, including registration and verification of visitors for security purposesVisitor Data
Ensuring the operation of and access to the Website, implementing data security measures to protect data, and diagnosing and eliminating Website malfunctions for uninterrupted operationWebsite Usage Data
Managing social media and communicating through them, including responding to user comments or messages and ensuring platform-based visibilitySocial Media Data
Backing up documents and data to prevent data loss, including storing information containing personal data in backup systemsAll data categories
Disclosure of data to service providers and professional advisors to ensure daily operationsAll data categories
Disclosure of data to legal successors and/or potential acquirersAll data categories
Disclosure of data to public sector, law enforcement and supervisory authorities in compliance with applicable lawsAll data categories
Data analysis when it is necessary for establishing, exercising or defending legal claims in judicial, administrative or out-of-court proceedingsAll data categories
Establishing, exercising or defending legal claims, whether in judicial proceedings or in administrative or out-of-court proceduresAll data categories
Arranging the sale, merger or other corporate restructuring involving Frankenburg Technologies OÜ and providing information for the purposes of conducting legal, financial or other audits (including related data exchange), where necessaryAll data categories

4. Recipients and transfer of personal data

4.1. In certain cases, in order to comply with applicable legal or contractual obligations or, where applicable, to pursue legitimate interests, we may transfer your personal data to the following categories of recipients, who process such personal data as independent controllers.

CategoryPurpose and legal basis of disclosure
Public authorities and law enforcement agenciesWhere required by applicable law, court orders or legally binding requests, we may disclose your personal data to public authorities, supervisory authorities or law enforcement agencies in order to comply with legal obligations or to establish, exercise or defend legal claims.
Other companies within our groupWhere necessary, we may disclose your personal data to other companies within the Frankenburg group, including its direct and indirect subsidiaries and other affiliated entities, in order to enable the use of shared technical infrastructure, provide centralised support functions or perform internal administrative tasks, based on legitimate interests and subject to appropriate safeguards.
Service providers and cooperation partnersWhere necessary, we may disclose your personal data to service providers, such as banks, payment service providers, insurance companies or postal service providers.
Professional advisorsWhere necessary, we may disclose your personal data to professional advisers, such as auditors, accountants, legal advisers or other consultants, for the purposes of obtaining professional advice, ensuring compliance with legal obligations or the proper conduct of business operations.
Successors and/or potential acquirers of the Frankenburg Technologies OÜWhere necessary for the purposes of a transfer, merger, acquisition or other corporate restructuring involving Frankenburg Technologies OÜ, your personal data may be disclosed to potential acquirers or successors and their professional advisers, based on legitimate interests and subject to confidentiality obligations.

4.2. We may engage and use processors in the processing of personal data who have access to your personal data solely for the purpose of performing the contract concluded with us and who apply adequate safeguards in the processing of personal data. Such processors process personal data solely on our documented instructions and only for the purposes of performing services under the applicable contract. The engaged processors belong to the following categories:

Category of recipientsPurpose of disclosure
IT and security service providersWe may engage IT and security service providers (such as data hosting, backup, storage, system maintenance, support and security service providers) who process personal data on our behalf for the purposes of operating, maintaining and securing our systems, technical infrastructure and administrative systems.
Accounting service providersWe may engage accounting service providers who process personal data on our behalf for the purposes of accounting, financial reporting and compliance with statutory obligations.
Communication service providersWe may engage communication service providers (such as e-mail and messaging platforms and social media management tools) who process personal data on our behalf for the purposes of internal and external communication and promoting business activities through social media and other channels.
Other companies within our groupWe may engage other companies within the Frankenburg group who process personal data on our behalf for the purposes of providing shared IT infrastructure, technical support, administrative or other centralised support services, solely to the extent necessary to provide such services.

4.3. Some recipients involved in our data processing, including processors, may be located outside the EU/EEA, and we may therefore transfer your personal data outside the EU/EEA when disclosing it to them.

4.4. Where personal data is transferred outside the EU/EEA, we ensure that appropriate safeguards are in place in accordance with applicable data protection legislation, such as standard contractual clauses approved by the European Commission or other legally recognised transfer mechanisms, to ensure a level of protection essentially equivalent to that applicable in the EU/EEA. You may obtain further information about the applicable safeguards by contacting the data protection officer using the contact details provided in Section 1.3 of this Notice.

5. Personal data retention periods

5.1. We retain your personal data for as long as necessary to fulfil the purposes described in this Notice and in accordance with applicable statutory retention periods. Retention periods are determined by us acting as a controller, unless a specific retention period is required by applicable law. In determining appropriate retention periods, we take into account the nature, scope and sensitivity of the personal data, the purposes of the processing, the potential risks associated with unauthorised use or disclosure, and applicable legal or regulatory requirements.

5.2. For example, accounting documents (including invoices and payment records) are retained for 7 years after the end of the relevant financial year, in accordance with the Estonian Accounting Act. Website Usage Data collected through cookies is retained for the period specified in Section 7 of this Notice.

5.3. If you would like further information about applicable retention periods or the retention of a specific category of personal data, you may contact the data protection officer using the contact details provided in Section 1.3 of this Notice.

5.4. Upon expiry of the applicable retention period, or where we no longer need the personal data for the purposes for which it was collected, the personal data will be deleted or anonymised, unless further retention is required or permitted by applicable law, including for the establishment, exercise or defence of legal claims.

6. Rights of the data subject

6.1. Where your personal data is processed by us, you have the right to contact the data protection officer using the contact details provided in Section 1.3 of this Notice in order to exercise the following rights in accordance with applicable data protection legislation, including the GDPR:

6.1.1. The right to access your personal data, including the right to obtain a copy of your data and information about how it is being processed.

6.1.2. The right to request the rectification of inaccurate or incomplete personal data that we process.

6.1.3. Right to erasure of personal data (“right to be forgotten”), for example, if the data is no longer necessary for the purpose for which it was collected, you withdraw your consent and no other legal basis for processing exists, or if the processing is unlawful.

6.1.4. The right to request the restriction of the processing of your personal data, for example, if you contest its accuracy, the processing is unlawful, or we no longer need the data for processing purposes, but you require the personal data to establish, exercise or defend legal claims.

6.1.5. The right to data portability, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have it transmitted to another controller, where technically feasible, if the processing is carried out by automated means and is based on your consent or a mutual contractual relationship.

6.1.6. The right to object to the processing of your personal data, for example, where the processing is based on legitimate interests.

6.1.7. The right to withdraw your consent at any time. The withdrawal of your consent does not affect the lawfulness of the processing of personal data prior to the withdrawal.

6.1.8. The right to contact the supervisory authority, to submit your claim to the data protection authority. In Estonia, the competent authority is the Estonian Data Protection Inspectorate (www.aki.ee, info@aki.ee).

7. No automated decisions

7.1. We do not envisage that you will be subject to decisions or profiling that will have a significant impact on you based solely on automated decision-making.

8. Use of cookies and similar technologies

8.1. The following sections apply to the use of cookies and similar technologies on the website careers.frankenburg.tech. Cookies used on other websites operated by Frankenburg Technologies OÜ, if any, are not covered by this section.

8.2. We use all cookies, except for strictly necessary (technical) cookies, only with your prior consent. You have the right to withdraw your consent at any time by changing your preferences through the website careers.frankenburg.tech.

8.3. We use first-party cookies (cookies set by our own domain).

8.4. The cookies we use are classified as either session cookies or persistent cookies. Session cookies are valid only during your browsing session on the website and are automatically deleted when you close your web browser. Persistent cookies, however, are stored on your device for a specified period of time, which may be set by us or by a third party, and expire either on a fixed date or after a defined period.

8.5. For convenience, we have categorised the cookies used on our website according to their purpose as follows:

Strictly necessary cookiesThese cookies ensure the functioning of the core features of the website. Strictly necessary cookies cannot be disabled, as the website cannot function properly without them. In accordance with applicable legislation, your consent is not required for the use of these cookies.
Analytics cookiesThese cookies help collect statistics about the use of the website. For example, they allow us to identify which pages are visited and how long is spent on them on average. We use such cookies only with your prior consent.

Below we have listed all cookies used on our website careers.frankenburg.tech. You will find information about their purpose, retention period and whether they are first-party or third-party cookies.

CategoryNamePurposeExpiryFirst-party or third-party cookie
Strictly necessary_tt_sessionThis cookie is used to keep the context of a visitor (e.g. to keep you logged in on the site).2 daysFirst-party
Strictly necessary_ttCookiePermissionsThis cookie is used to hide the cookie banner once you have interacted with it.6 monthsFirst-party
AnalyticsreferrerThis cookie is used to identify the web link used to direct visitors to the site.After sessionFirst-party
Analytics_ttAnalyticsThis cookie is used to gather insights about how visitors use the site.6 monthsFirst-party

9. Changes to this notice

This Notice may be updated from time to time to reflect changes in applicable law or in the way we process personal data. Where material changes are made, the updated version of the Notice will be made available to you through appropriate means.

Version: September 23, 2026