Privacy notice

How Motravax OÜ handles personal data under Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Estonian Personal Data Protection Act.

Last updated: 9 August 2026

1. Who is responsible for your data

The controller of the personal data described in this notice is:

Motravax OÜ
Registry code 17460792
Harju maakond, Tallinn, Kesklinna linnaosa, Tartu mnt 82, 10112, Estonia
Email: motravax@inbox.eu
Telephone: +44 7476 690352

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Data protection questions should be sent to the email address above.

2. What we collect and why

2.1 Enquiries and correspondence

When you use the enquiry form or write to us directly, we process the details you provide: your name, email address and, if you supply them, your company, telephone number, delivery country, the equipment category you are interested in and the content of your message — including any floor-plan summary you choose to attach.

  • Purpose: to answer your enquiry and to prepare an offer.
  • Legal basis: Article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract; and, for general correspondence that is not pre-contractual, Article 6(1)(f) — our legitimate interest in responding to people who contact us.
  • Consequence of not providing it: without at least a name, an email address and a message we cannot reply to you.

2.2 Orders and business records

If an enquiry becomes an order, we process the contact and delivery details needed to fulfil it, together with the resulting invoicing and accounting records.

  • Legal basis: Article 6(1)(b) GDPR for performance of the contract, and Article 6(1)(c) for compliance with accounting and tax obligations that apply to us in Estonia.

2.3 Website operation

Our hosting provider processes technical connection data — such as your IP address, the requested URL, the time of the request, the referring page and your browser's user-agent string — in server logs, which are necessary to deliver the site and to protect it against abuse.

  • Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating a functioning and secure website.

2.4 Cookies and local storage

The site stores your theme preference and your cookie choice in your browser's local storage. These are strictly necessary to provide the functions you have asked for and are not used to track you. Optional measurement storage is used only if you have accepted it. Full details are in the cookie notice.

2.5 The floor planner

The floor planner runs entirely in your browser. Room dimensions and layouts are not transmitted to us and are not stored on our servers. A layout reaches us only if you choose to insert it into the enquiry form and submit that form, at which point it is processed as part of your enquiry under section 2.1.

3. What we do not do

  • We do not sell or rent personal data.
  • We do not use your details for marketing without a separate, specific opt-in that you can withdraw at any time.
  • We do not carry out automated decision-making or profiling that produces legal or similarly significant effects for you (Article 22 GDPR).

4. Who else processes your data

We share personal data only where it is necessary, and only with parties acting on our instructions as processors or under their own legal obligations:

Recipient categoryPurposeBasis for the transfer
Website hosting and content delivery providerServing the site, delivering form submissions, security loggingProcessor under Article 28 GDPR
Email service providerReceiving and sending correspondenceProcessor under Article 28 GDPR
Suppliers and carriersFulfilling and delivering a confirmed orderNecessary for performance of the contract
Accountants, auditors, banksInvoicing, bookkeeping and statutory reportingLegal obligation / legitimate interest
Public authoritiesWhere we are legally required to discloseLegal obligation

5. Transfers outside the EEA

Our service providers may process data on infrastructure located outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision of the European Commission or by appropriate safeguards under Article 46 GDPR, such as the Commission's Standard Contractual Clauses. You may request information about the safeguards applied to a specific transfer at the contact address above.

6. How long we keep it

  • Enquiries that do not lead to an order: kept while the enquiry is live and then deleted, unless a longer period is needed to defend a legal claim.
  • Contract and order records: kept for the duration of the contract and afterwards for as long as claims may be brought under the applicable limitation periods.
  • Accounting documents: kept for seven years, as required by the Estonian Accounting Act.
  • Server logs: kept for the short period our hosting provider retains them for security and diagnostics.
  • Cookie choice: stored in your browser until you clear it or change your choice.

7. Your rights

Under the GDPR you have the right to:

  • request access to the personal data we hold about you (Article 15);
  • have inaccurate data corrected (Article 16);
  • have data erased where one of the grounds in Article 17 applies;
  • request restriction of processing (Article 18);
  • receive data you provided in a portable format (Article 20);
  • object to processing based on our legitimate interests (Article 21);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).

To exercise any of these, write to motravax@inbox.eu. We respond within one month of receiving a request, as required by Article 12(3); if a request is complex, we may extend that period and will tell you why. We may need to verify your identity before acting.

8. Complaints

If you believe we have handled your data unlawfully, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — www.aki.ee — or with the supervisory authority of your country of residence.

9. Security

The site is served over HTTPS and we apply technical and organisational measures appropriate to the risk, including limiting access to correspondence to the people who need it. No transmission over the internet can be guaranteed to be completely secure; please do not send us payment card details or identity documents by email.

10. Children

This site is aimed at businesses and adults. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this notice

We may update this notice to reflect changes in how we operate or in the law. The date at the top shows when it was last revised. Material changes affecting your rights will be highlighted on this page.