~/veonio/legal/privacy-policy.mdin effect
The small print, made big*
// changelog
- v2026.09Rewritten from scratch in plain English. The company is VEONIO OÜ (Estonia). Added retention times, ready-made emails for your rights and the TL;DR for every section. Terms rewritten for how our agency actually works.
- v2019.06Original policy and terms, issued by VEO Capital Ltd. (Malta).
What we collect, why we collect it and what you can do about it. Every section boots with a plain-English summary. The full legal text sits right underneath.
* and 100% legal (pinky promise). No magnifying glass required.
This policy explains how VEONIO OÜ handles personal data when you visit veonio.com, contact or apply to us, use the Digital Readiness Scorecard or sign up for our emails. It follows the EU General Data Protection Regulation (GDPR) and Estonian data protection law.
Who is responsible
In plain English: We are VEONIO OÜ, a company in Tallinn, Estonia. We decide what happens to your data, so we are the ones responsible for it.
The controller of your personal data under the GDPR is VEONIO OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia (registry code 16255914) (“VEONIO”, “we”, “us”). We have not appointed a data protection officer because we are not legally required to. For anything related to privacy, write to privacy@veonio.com.
Visiting the website
In plain English: Our host Cloudflare sees the technical data every website visit sends, like your IP address. We count visits without cookies and without identifying you.
Hosting and delivery
The website is hosted and delivered by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) through Cloudflare Pages and its global network. When you open a page, your browser necessarily transmits technical data: IP address, date and time, the page requested, referrer, browser and operating system. Cloudflare processes this data to deliver the page, protect the site against attacks and keep it available. These logs are kept only briefly and are not combined with other data. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a secure, fast and reliable website.
Web analytics
We use Cloudflare Web Analytics to count page views and see which pages are popular. It works without cookies and without identifying individual visitors; we only see aggregated figures such as visits per page, referring websites and countries. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in understanding which content is useful.
Our fonts are served from our own domain. No data is sent to Google Fonts or similar services.
Cookies and browser storage
In plain English: None. Our website sets no cookies and stores nothing in your browser, so there is no cookie banner to click away.
| What | Provider | Purpose | Cookies |
|---|---|---|---|
| veonio.com itself | VEONIO | The website | None |
| Web Analytics | Cloudflare | Aggregated visit counts | None |
| Turnstile (form pages only) | Cloudflare | Telling humans from bots | See Cloudflare’s Turnstile privacy addendum |
Features such as TL;DR mode on this page work only for the current visit and are not saved.
Contact, application and careers forms
In plain English: When you fill in a form, we use what you type to answer you. Nothing more.
When you use the application form, the contact or careers form, or email us, we process the details you give us: for example name, email address, company, website, phone number, your answers about goals, company size, budget and timing, and your message. We use them to review your request, prepare a conversation and answer you.
- Form submissions are stored in a database operated by Cloudflare (Cloudflare D1) and forwarded to our mailbox by our email provider Resend.
- You receive a copy of your application by email.
- Our mailboxes are hosted by Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
Legal basis: Art. 6(1)(b) GDPR where your request relates to a contract or steps before one, otherwise Art. 6(1)(f) GDPR, our legitimate interest in answering messages sent to us. For job applications also Art. 6(1)(b) GDPR (steps before an employment or service contract).
How we assess fit
The application form shows a “fit score” based on your own answers about budget, size and timing, and a link to book a call if it matches the projects we take on (currently from €10,000, starting within 12 months). This simple rule has no legal or similarly significant effect on you. A person reads every application, and you can always contact us directly instead.
Digital Readiness Scorecard
In plain English: Your answers create your personal report, which we also email to you. We use them to prepare a conversation if you’d like one.
The scorecard asks ten questions about how your company works, four questions about your company and plans, and your contact details. We use this data to create your report and show it immediately, to email you a copy, to notify Markus Behmann so any follow-up is relevant, and to decide whether we offer a strategy call (the same simple rule as above). Submissions are stored in our Cloudflare D1 database.
Legal basis: Art. 6(1)(b) GDPR for creating and sending the report you asked for; Art. 6(1)(f) GDPR for preparing a follow-up.
Emails you asked for
In plain English: Our monthly brief and the scorecard playbooks only arrive if you say yes. One click unsubscribes you.
Monthly brief (“Send me the magic”). When you enter your email address, we first send a confirmation email. Only after you confirm do we add you to the list (double opt-in). We store your email address, language and the time of sign-up and confirmation as proof of your consent.
Scorecard playbooks. If you tick the box in the scorecard, we send a short series of emails with practical guidance for your focus areas (about five emails over two weeks). For this we store your name, email address, company, language and your score summary.
Both are sent through Resend. Every email contains an unsubscribe link; you can also withdraw your consent at any time by writing to us. We do not track whether you open our emails or which links you click. After you unsubscribe, we keep your address on a suppression list so that you receive no further emails. Legal basis: Art. 6(1)(a) GDPR (consent).
Spam protection
In plain English: Our forms are guarded by Cloudflare Turnstile instead of annoying CAPTCHAs. It checks you’re human, usually invisibly.
When a page with a form loads, Cloudflare Turnstile runs a short, usually invisible check in your browser and transmits technical information (such as your IP address and browser characteristics) to Cloudflare to tell humans from bots. The data is used only for this purpose. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in protecting our forms against abuse. Details: Cloudflare Turnstile privacy addendum.
Booking a call
In plain English: If you book a strategy session, our scheduling tool Motion handles the booking and puts it in our calendar.
If you book a call, you are taken to our scheduling provider (currently Motion, usemotion.com), where you choose a time and enter your name and email address. The provider passes the booking to our calendar. The video call itself takes place in the tool named in the invitation. Legal basis: Art. 6(1)(b) GDPR, steps before a contract at your request.
Links to social networks
In plain English: We link to LinkedIn and Facebook. Nothing is sent to them unless you click.
Our pages link to our profiles on LinkedIn and Facebook, and articles offer a “Share on LinkedIn” link. These are ordinary links: no data is sent to these networks unless you click them. After clicking, the privacy policy of the respective network applies.
How long we keep it
In plain English: Only as long as we need it: server logs for days, enquiries for up to two years, emails until you unsubscribe, accounting records for 7 years because the law says so.
// retention, drawn to scale (0 to 7 years)
- Server logs: only as long as Cloudflare needs them for delivery and security, generally a few days.
- Enquiries and applications: until your request has been dealt with; if no business relationship follows, we delete them after 24 months at the latest.
- Scorecard submissions: 24 months after your last contact with us, unless a business relationship follows.
- Email subscribers: until you unsubscribe or withdraw consent, then only on the suppression list.
- Accounting records: 7 years, as required by the Estonian Accounting Act.
Your rights
In plain English: It’s your data, so you’re the boss. Pick a right below and copy a ready-made email to use it. We reply within one month.
You have the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to withdraw consent at any time with effect for the future (Art. 7(3)). Right to object (Art. 21 GDPR): where we process data on the basis of our legitimate interests, you can object at any time for reasons arising from your particular situation; you can object to direct marketing at any time without giving reasons. We answer requests free of charge within one month and may ask you to confirm your identity first.
Access
Get a copy of the personal data we hold about you.
Correction
Fix data that is wrong or incomplete.
Deletion
Ask us to delete your data when we no longer need it.
Restriction
Ask us to pause using your data while an issue is checked.
Portability
Get your data in a machine-readable file to take elsewhere.
Objection
Object to use based on our legitimate interest, or to direct marketing.
Withdraw consent
Stop emails you agreed to earlier.
Send the email to privacy@veonio.com. You can also simply write to us in your own words.
How we protect it
In plain English: Encryption, access controls and two-factor authentication. Only people who need your data can see it.
All connections to this website are encrypted (HTTPS/TLS). Access to stored data is limited to the people who need it and protected by two-factor authentication. If a data breach is likely to put your rights at risk, we will inform you and the supervisory authority as the law requires.
Changes to this policy
In plain English: If we change something important, the date at the top changes too. Subscribers hear about significant changes by email.
We update this policy when the website, our services or the law change. The date at the top shows the current version.
Contact and complaints
In plain English: Questions? Email us. Still unhappy? You can complain to the Estonian Data Protection Inspectorate or your local authority.
If you are not satisfied with our answer, you have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
// company
VEONIO OÜ
Sepapaja tn 6, 15551 Tallinn
Estonia · Reg. code 16255914
privacy@veonio.com
// supervisory authority
Andmekaitse Inspektsioon
Tatari 39, 10134 Tallinn, Estonia
aki.ee · info@aki.ee
// EOF. You made it to the end. Respect.
