Privacy Policy
Last updated: July 31, 2026
This Privacy Policy describes how brixline (brixline Osaühing) collects, uses, and protects your personal information when you use our website and services related to brixline cycling and ferry excursions on Saaremaa and Muhu islands. We are committed to protecting your privacy and handling your data responsibly in accordance with applicable data protection regulations.
Who We Are (Data Controller)
We operate the website and provide brixline cycling day trip and ferry crossing excursion packages. As the data controller, we are responsible for ensuring that your personal information is processed lawfully and securely. We collect and process your data to provide our services, respond to your inquiries, and improve your experience with us. Our commitment to transparency means we inform you clearly about what data we collect and how we use it.
Information We Collect
We collect information in several ways. When you book an excursion or contact us, you provide personal details such as your name, email address, phone number, and payment information. We also collect data automatically through cookies and similar technologies, including your IP address, browser type, pages visited, and time spent on our site. Usage data helps us understand how visitors interact with our website and allows us to optimize our services accordingly.
Legal Basis for Processing
We process your personal information based on several legal grounds. Your explicit consent is obtained when you book a tour or subscribe to our newsletter. We also rely on legitimate interests to improve our services and prevent fraud. Processing is necessary to fulfill contracts with you, such as confirming your booking and providing customer support. Additionally, we comply with legal obligations imposed by law, including tax and accounting requirements.
How We Use Your Information
We use your data to process and confirm your bookings, manage payments, and provide customer support for your brixline cycling and ferry excursion packages. We send you confirmations, updates, and important information about your tours. Your information helps us personalize your experience and tailor our services to your preferences. We also use aggregated, anonymized data for analytics and marketing purposes to improve our website and understand customer behavior patterns.
Data Retention
We retain your personal information for specific periods depending on the type of data:
- Booking and transaction data: Retained for 7 years to comply with accounting and tax requirements
- Contact form inquiries: Retained for up to 24 months after the last interaction or tour completion
- Newsletter subscription data: Retained until you unsubscribe
- Website analytics and cookies: Retained for up to 14 months from collection
- Server logs and technical data: Retained for up to 12 months for security and troubleshooting purposes
After the retention period expires, we securely delete or anonymize your information unless we are required by law to retain it longer.
Your Rights
You have several rights regarding your personal information. You can request access to the data we hold about you and receive a copy in a portable format. You have the right to correct inaccurate or incomplete information. You may request deletion of your data, subject to legal obligations. You can object to certain types of processing and withdraw your consent at any time without affecting the lawfulness of previous processing. If you believe we have violated your rights, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate.
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your browsing experience and gather analytics about site usage. Essential cookies are necessary for the website to function properly, such as maintaining your session. Performance cookies help us understand how visitors use our site and identify areas for improvement. Marketing cookies may be used to display targeted content based on your interests. You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect your ability to use some features of our website.
Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. We use encryption for sensitive data such as payment information and maintain secure server infrastructure. Our team members are trained in data protection best practices. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security. We encourage you to use strong passwords and report any security concerns to us immediately.
Third-Party Services
We may share your information with trusted third parties who assist us in providing our services, such as payment processors, email service providers, and analytics platforms. These service providers are bound by confidentiality agreements and are only authorized to use your information for the purposes we specify. We do not sell your personal information to third parties. If you have concerns about third-party processing, we are happy to provide more details about our partners and their data handling practices.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by posting the updated policy on our website with a new "last updated" date. Your continued use of our services after changes have been posted constitutes your acceptance of the revised Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.
Contact Us
If you have questions about this Privacy Policy, your rights, or our data handling practices, please contact us:
Email: [email protected]
Phone: +372 58 427 891
Address: Pikk Street 28, Tallinn, 10133, Estonia