GDPR — Personal Data Protection Notice
Ritapos GDPR / personal data protection notice: how we collect, use, store and protect personal data, and your rights under GDPR.
Personal Data Protection Notice (GDPR)
Since day one, Ritapos has aimed to help businesses serve their customers better with easy, fast and reliable systems. The privacy and security of your personal data are among our highest priorities. This notice explains how Ritapos OÜ (“Ritapos”, “we”) processes personal data in connection with ritapos.com and related services, in line with the EU General Data Protection Regulation (GDPR) and other applicable laws.
1. Who is the data controller?
Ritapos OÜ, registered in Estonia (Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145), is the data controller for personal data processed through our website, applications and customer communications. You can reach us at [email protected] or +90 850 308 29 89.
2. What personal data do we process?
Depending on how you interact with us, we may process: identity data (name, surname); contact data (email, phone, billing address); billing and support records (including chat or call content where applicable); security and technical data (device/MAC identifiers, hashed passwords, tokens, cookies); and audio recordings if you contact our call centre.
3. Purposes and legal bases
We process personal data to perform and manage contracts (including account setup, purchases and billing); to run finance and accounting processes; to operate and improve our products and business; to verify identity for online or in-app purchases; for marketing and advertising where you have given consent; and to meet legal obligations. Where GDPR applies, our legal bases include performance of a contract, legitimate interests, legal obligation and consent.
4. How we collect data
Data is collected directly from you (forms, registration, purchases, support) and automatically via our website or mobile apps (for example cookies and security logs), as described in our Privacy Policy.
5. Recipients and transfers
We may share data with service providers that help us host infrastructure, process payments, deliver communications or provide support, under appropriate contracts. Where data is transferred outside the EEA, we use GDPR-compliant safeguards such as adequacy decisions or standard contractual clauses.
6. Retention
We keep personal data only as long as needed for the purposes above, and as required by tax, accounting and other legal retention rules. When retention ends, data is deleted or anonymised.
7. Your rights
Subject to applicable law, you may have the right to access, rectify, erase or restrict processing of your personal data; to object to processing; to data portability; and to withdraw consent where processing is based on consent. You may also lodge a complaint with a supervisory authority. To exercise your rights, contact [email protected].
8. Security
We use technical and organisational measures appropriate to the risk, including encryption and access controls, to protect personal data against unauthorised access, loss or alteration.
9. Updates
We may update this notice from time to time. The current version is always published on this page. For more detail on cookies and website privacy practices, see our Privacy Policy.
Sign Up Now
Don't wait for a demo. Sign up and try it free for 14 days.
No credit card required — cancel anytime.