HEXEST MATERIALS AS – PRIVACY POLICY

Valid from: 01.01.2026

This Privacy Policy describes how Hexest Materials AS (“Hexest”, “we”) processes personal information on our website, in recruitment, communications, partnering and other business activities. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Estonian law.

1. THE CONTROLLER

Hexest Materials AS

Registration number: 17268480

Address: Suur-Ameerika 1, 10122 Tallinn, Estonia

E-mail: info@hexestmaterials.ee

Media contact: meedia@hexestmaterials.ee

KMKR: EE102878839

2. THE PERSONAL DATA PROCESSED, THE PURPOSES, THE LEGAL BASIS AND THE RETENTION PERIODS.

ProcessingProcessable dataLegal basis (including reference to the law, if applicable)Retention period
Website logs and securityIP address, device info, logs, cookie dataGDPR Art 6(1)(f) – Legitimate interest (ensuring IT security and performance).1 year
Enquiries and communicationName, email, phone, content of the requestGDPR Art 6(1)(b) – pre-contractual act or Art 6(1)(f) – legitimate interest.2 years since last contact
Customer contracts and customer relationsContact details, communication, contracts, billing informationGDPR Art 6(1)(b) – performance of the contract3 years after the end of the contract; original documents according to RPS 7 a
AccountingInvoices, payment documents, customer name and contact detailsGDPR art 6(1)(c) – legal obligation (Accounting Act § 12, § 7(1))7 years (RPS)
Documents relating to tax obligationsTax documents, data relating to declarationsGDPR Art 6(1)(c) – legal obligation (Tax Administration Act)As provided by law (generally until the statute of limitations expires).
Marketing and newslettersName, e-mailGDPR art 6(1)(a) – consent (opt-out possible at any time)Pending withdrawal of consent
Details of job applicantsCV, cover letter, work and education details, references, recruitment communication.GDPR Art 6(1)(b) – pre-contractual act; additional data with consent (Art 6(1)(a)).1 year after the end of the recruitment process (longer only with agreement).
Staff dataEmployment contract, work organisation, timesheets, holidays, payroll, training, etc.GDPR Art 6(1)(b) – performance of contract; Art 6(1)(c) – legal obligation (Employment Contracts Act; Working Environment Act).In accordance with the law and internal storage arrangements (generally 5-10 years).
Suppliers and partnersContact details, contracts, communicationGDPR Art 6(1)(b) – performance of the contract or Art 6(1)(f) – legitimate interest.3 years after the end of the cooperation; original documents RPS 7 a
Proving legal claims and disputesRelevant documents, correspondenceGDPR Art 6(1)(f) – Legitimate interest (protection of rights and proof of claims).Until claims expire (usually 3 years)

3. SOURCES OF PERSONAL DATA

We process data: (i) directly from the data subject (enquiries, contracts, applications), (ii) automatically when the website is used (logs, cookies), (iii) when recruiting from job portals and public sources, (iv) from contract partners when necessary for the performance of the contract.

4. DATA TRANSFERS AND PROCESSORS

Personal data will only be transferred on a needs basis and in accordance with the law. We use server and IT service providers, accounting service providers, recruitment platforms and employment agencies, and, where necessary, legal advisers or auditors as processors. Data will not be transferred outside the EEA unless GDPR safeguards are in place.

5. DATA SUBJECT RIGHTS

The individual has the right of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent. Complaints can be submitted to the Data Protection Inspectorate (aki.ee). Please send enquiries to info@hexestmaterials.ee.

6. CONSERVATION PRINCIPLES

We will retain personal information only for as long as necessary to fulfill the purposes described in this policy or as required by law. We will implement periodic review and deletion in accordance with retention periods.

7. SECURITY INFORMATION

We implement technical and organisational security measures: role-based access, encrypted data, secure accommodation, logging and monitoring, access auditing and regular staff training.

8. MISSIONS

We use the necessary cookies and, if the user gives consent, analytics cookies. The details (types, purposes, retention periods) are described in a separate cookie policy. Hexest Materials AS cookie policy can be found at the following link: cookie policy.

9. APPLICATION AND RECRUITMENT PROCESS

When recruiting, we process the candidate’s data to assess their suitability for the job, including background checks where necessary, within the limits of the law. The data will be kept for 1 year after the end of the recruitment process, unless the candidate agrees to a longer retention period.

10. UPDATING POLICIES

Hexest Materials AS reserves the right to update this Privacy Policy. The current version will be published on the website and will enter into force on publication unless otherwise stated.
E-mail: info@hexestmaterials.ee