NodeOps Security Infrastructure · Assurance
Privacy

Privacy policy

How NodeOps Security OÜ handles personal data collected through this website, under the EU General Data Protection Regulation (GDPR).

Last updated: 16 September 2026

The short version. This website sets no cookies, runs no analytics, loads no fonts or scripts from third parties, and does not track you. The only personal data we receive is what you deliberately send us through the contact form or by email, plus standard server logs kept by our hosting provider.

1. Controller

The controller for the processing described here is NodeOps Security OÜ, an Estonian private limited company. Postal and registration details are on our legal notice. For any question about this policy or your data, write to info@nodeops-sec.tech.

Given our size we are not required to appoint a Data Protection Officer. Data protection questions are handled directly by the management board.

2. What we collect

2.1 Enquiries you send us

When you use the contact form we receive the name, company, email address, country, enquiry category and message you enter, together with the fact and time of submission. If you email us directly we receive whatever your message and mail headers contain.

2.2 Server log data

Our hosting provider records standard web server logs for every request: IP address, date and time, the resource requested, HTTP status, referring page and browser user agent. These logs are generated by the web server itself and are necessary to operate the site securely and diagnose faults.

2.3 What we do not collect

  • No cookies of any kind are set by this website.
  • No analytics, tag managers, heatmaps or advertising pixels.
  • No fonts, scripts, stylesheets or images loaded from third-party servers or CDNs.
  • No social media embeds, share widgets or tracking parameters.
  • No profiling and no automated decision-making.

Because nothing is stored on your device and no third party receives data, this site does not require a cookie consent banner.

3. Why we process it, and on what legal basis

  • Responding to your enquiry - Article 6(1)(b) GDPR, steps taken at your request prior to entering into a contract; and your consent under Article 6(1)(a) GDPR, given via the checkbox on the form. You may withdraw consent at any time, which does not affect processing already carried out.
  • Operating and securing the website - Article 6(1)(f) GDPR, our legitimate interest in providing a stable, secure service and preventing abuse. We have assessed this as low impact: log data is not combined with other sources and is not used to identify individuals.
  • Preventing form spam - Article 6(1)(f) GDPR. We use a hidden honeypot field and a timing check. No third-party CAPTCHA service is involved, so no data leaves our server for this purpose.
  • Meeting statutory obligations - Article 6(1)(c) GDPR, where accounting or commercial law requires records to be kept.

4. How long we keep it

  • Enquiries that do not lead to an engagement: deleted within 12 months.
  • Enquiries that lead to an engagement: kept for the life of the relationship and then for the statutory retention period under Estonian accounting law.
  • Server logs: retained by our hosting provider according to their standard policy, typically a matter of weeks.

5. Who else sees it

We do not sell personal data, and we do not share it for marketing. Data is disclosed only to:

  • our hosting provider, which stores the website and processes server logs and form submissions on our behalf under a data processing agreement;
  • our email provider, which transmits and stores our correspondence;
  • professional advisers or authorities, where we are legally required to disclose.

[ COMPLETE BEFORE LAUNCH ] Name your hosting and email providers here once chosen, and confirm a data processing agreement is in place with each.

6. Transfers outside the EEA

We aim to keep processing within the European Economic Area. Where a provider processes data outside the EEA, we rely on an adequacy decision of the European Commission or on Standard Contractual Clauses together with appropriate supplementary measures.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased where no overriding obligation applies;
  • restrict processing while a dispute is resolved;
  • receive your data in a portable, machine-readable format;
  • object to processing based on our legitimate interests;
  • withdraw consent at any time, with future effect.

Write to info@nodeops-sec.tech to exercise any of these. We respond within one month. You also have the right to complain to a supervisory authority - in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) - or to the authority in your own country of residence.

8. How we protect it

The site is served exclusively over HTTPS with HTTP Strict Transport Security. Form submissions are validated and length-limited server-side, and the response headers restrict which content the browser will load. Access to the mailbox receiving enquiries is limited to the people who need it and protected by multi-factor authentication.

Please do not send passwords, private keys, configuration files or client data through the contact form or by ordinary email. If an enquiry requires sensitive material, ask us and we will arrange an appropriate channel.

9. Changes to this policy

We may update this policy as our services or providers change. The current version is always published here with its revision date. Material changes affecting existing clients will be communicated directly.