Privacy policy
1. Introduction
Welcome to the Meiekinnisvara.ee portal!
Your privacy and security are a top priority for us. We follow security best practices, including the OWASP (Open Web Application Security Project) guidelines, to protect your personal data.
2. Bases for data processing
We process your data:
- To perform the contract (managing your user account)
- To fulfil a legal obligation (tax records)
- On the basis of our legitimate interest (security measures, web analytics without personal data)
3. Sessions and cookies
We use secure server-side sessions with HTTPS-only cookies to manage the session ID. Cookies are used only:
- To ensure login security and the functioning of the website
- To detect malicious traffic (Cloudflare)
You can control and change the use of cookies in your browser settings, but removing them may affect the functioning of the portal.
4. Password encryption and security
All user passwords are securely encrypted with Argon2id technology, which provides the highest level of security. This ensures protection even if passwords were to leak.
Our security measures include:
- Password strength checks and requirements.
- Regular system and database security updates.
- Protection against unauthorised access.
5. Security measures and OWASP standards
We follow OWASP security standards that protect both us and you:
- Secure HTTPS connections: All traffic is encrypted with the TLS 1.2 and TLS 1.3 protocols.
- User input validation: All data inputs are sanitised and filtered to prevent XSS and SQL attacks.
- Rate limiting: Important forms have a limit to prevent attacks.
- File upload protection: Only selected image formats are allowed.
- Encrypted data: All your data is encrypted in our systems. This ensures protection of all data even in case of leaks (for example messages, personal data, etc.).
- Audits: We regularly conduct independent security audits and penetration tests.
- Rapid response: In case of a data security incident, we notify users and relevant authorities within 72 hours.
6. Third parties
We use third-party services that follow security standards:
- Stripe: All payments are processed through Stripe; our system does not store bank information.
- Cloudflare: Protects the website against DDoS attacks and malicious traffic. Cloudflare also improves page speed and thereby your user experience.
- Data transfers outside the European Union: For data transfers we use only providers certified under the EU-US Data Privacy Framework (EU-US DPF).
Data is shared with third parties only when necessary to comply with laws or to provide the service (e.g. payment processing), and these partners are contractually obliged to follow strict security standards.
7. Data retention
Personal data is retained:
- For an active account - until a deletion request
- Tax records - 7 years to fulfil a legal obligation
- Backups - up to 30 days after deletion
8. Your rights
On the Meiekinnisvara.ee portal you have the following rights:
- Data deletion (GDPR Article 17): You have the right to delete your account along with all data stored in our website system. When a user is deleted, all data related to you is deleted immediately. Deleted user data is removed from our backups within 30 days.
- Deleting messages: You have the right to delete messages you have sent yourself. Received messages remain with the recipient and are not deleted at the other party's request. For a deleted account, the username in conversations is replaced with the text "Deleted user".
- Data modification/restriction (GDPR Articles 16 and 18): You have the right to request correction of data or restriction of its use.
- Data portability (GDPR Article 20): You can request a copy of your data in a readable form.
9. Questions and contact
If you have questions about data processing or security, contact us:
Email: info@meiekinnisvara.ee
Phone: +372 5457 3643
Registry code: 16900545