Hiring policy

UP Catalyst OÜ (“Up Catalyst,” “we” “us” or “Company;” for contact details see the end of this privacy policy) considers protecting and respecting your privacy and safeguarding your personal data as critically important aspects of its business. This policy details and regulates how we collect, store, process, transfer, share and use your personal data, for example when you visit our website for informational purposes, when you contact us via our website (https://upcatalyst.com/) and e-mail or when you enter into contractual negotiations with us. You will also find information on the protective measures we have taken concerning your personal data, transferring of your personal data, information on your rights, and our contact details.

If you have any questions about our privacy policy or how we use your personal information, please contact us via e-mail at info@upcatalyst.com.

Who is Responsible for Processing Your Data

We are the data controller with regard to the personal data processed when you visit, use our website, contact us or purchase our services or products. This means that we determine and are responsible for how your personal data is processed. Our full contact details can be found at the end of this privacy policy.

Our website may contain links to other websites. Please be aware that once you leave our site and navigate to a third-party website, their privacy policy will apply to any information you provide or is collected through that site. We encourage you to review the privacy policy of any site you visit to understand their data practices.

Types of Data Processed and the Purpose for Processing

To achieve the purposes set out in this privacy policy, we process some or all of the following personal data. The exact composition of the personal data processed varies in each case, but we always follow the principle of processing as little personal data as necessary to achieve the purpose:

  • Personal data disclosed to us during communication with clients and potential clients (including the names, personal identification numbers, email addresses, phone numbers, and postal addresses of individuals and individuals related to legal entities, such as representatives, contact persons, certain employees, etc.) are primarily processed for the purpose of establishing and maintaining client relationships. We have a legitimate interest in responding to inquiries, ensuring client satisfaction, and offering our services or products. Additionally, we process such data for fulfilling our contractual obligations and protecting our rights.

  • For the above purposes, we may process your personal data if you have disclosed it to us via the contact form on our website or through email communication. For example, if you have asked us for information about a specific product/service or a quote, we process your data to send you the requested information, offer, etc., and to prepare, conclude, and fulfill the contract during contractual negotiations, and to protect our rights if necessary.

  • In contracts, we process the names, personal identification numbers, email addresses, phone numbers, bank account numbers, and, if necessary, financial and other information needed for preparing, concluding, and fulfilling (and also protecting rights under) the contract, related to individuals and individuals associated with legal entities with whom we have business relationships (e.g., representatives, contact persons, certain employees, etc.). Until the contract is concluded, we process this information for the purpose of concluding the contract (establishing a client relationship) and protecting rights. From the conclusion of the contract, we process the data for fulfilling the contract and protecting our rights. We process personal data for as long as necessary for these purposes.

  • In case you have subscribed to our marketing communications, we will process your personal data based on your consent which you may at all times withdraw by an unsubscribe link provided in the marketing communication. 

    We may also process your personal data to fulfill obligations set out in legal acts, such as ensuring the protection of personal data, retaining personal data for any period necessary to comply with legal obligations (e.g., for accounting purposes), and fulfilling other obligations arising from applicable legal acts.
  • When you visit our website, we may process personal data that we gather ourselves (or by using third-party services) regarding how, when and for what periods you access and use our website, and information about the device you use to access our website. For further information, please see our cookie policy.

We always ask for your prior explicit consent to process personal data if we use it for purposes not listed in the privacy policy. You can withdraw such consent at any time.

In addition to ensuring the processing of personal data in accordance with applicable laws as a data controller, we keep all data that becomes known to us through the use of the website or in the course of contractual relationships confidential (subject to any applicable exceptions) and secure.

Data Retention

We retain the personal data you provide to us with your requests etc. for a period of up to three years to enable us to better manage the relationship between us and cater to any of your follow-up requests and queries.

Customer data shall be retained for the duration of the relevant customer contract and for a period of up to three years thereafter. Customer data which is related to accounting, billing and taxes shall be retained for a period of ten years or until required by applicable legislation. We may be required to store customer data for longer periods when this is necessary for resolving disputes, protecting our lawful and legitimate interests, or required by applicable laws.

We may be required to store your personal data for periods which are longer than the periods above when this is necessary for resolving disputes, protecting our lawful and legitimate interests, or required by applicable laws.

Storing and Transferring Your Personal Data

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, change or damage. All data we collect will be stored on the secure servers of our reputable cloud service providers.

If you wish to enquire further about the safeguards we use, please contact us using the details set out at the end of this privacy policy.

Any transfers of personal data outside the EU/EEA shall be done under a lawful basis, including to a recipient which is in a country which provides an adequate level of protection for personal data; or under appropriate safeguards which cover the EU/EEA requirements for the transfer of personal data outside the EU/EEA.

Recipients

Your personal data may be shared with third party service providers that perform services for us or on our behalf. Such services may include accounting, legal or IT services, such as e-mail, cloud services and analytics services, such as such as SA, EAS Estonia, ProIT, EIT Manufacturing, Pipedrive, Hubspot, Factorial HR, calendly, Deel. This list is not exclusive and is subject to change over time based on provider availability, service agreements, and Company policy updates.

Your personal data may also be shared with external recipients if we are legally obliged to do so. This may include court orders and judgements, and data protection supervisory authority requests. In honouring such orders, judgements, and requests, we shall make sure that a lawful basis exists under which we share the information.

We may share your personal data in connection with legitimate exercise or protection of our or our customers’ rights, or in investigating contract breaches or illegal activity. In such cases the recipients of your personal data may be professional advisors or law enforcement agencies.
Your personal data may be disclosed to third parties if we are involved in a merger, sale of all or part of our assets or shares, reorganisation, or financing.

Your Rights

In accordance with and subject to exceptions prescribed by applicable law, you as a data subject have the following rights against us to the extent we act as a data controller, which you may exercise by submitting a relevant request to us which we shall process in accordance with applicable legal acts:

  • Right of access (the “subject access request”). This will provide you information on your personal data processed by us (including a copy thereof, if requested), including the lawful bases and purposes thereto.

  • Data portability right. You can request a copy of your personal data in a structured, commonly used and machine-readable format or to transfer this data to another party.

  • Rectification right. You may request for us to correct your personal data held by us if it is inaccurate or incomplete.

    Right to restrict processing. You may request for us to restrict processing of your personal data if you have contested the accuracy of the personal data, if the data processing is unlawful, if there is no purpose for the controller to process the data but you need the data for making a legal claim, or if you have objected to processing.

  • Right to object. Under bases provide by applicable legal acts, you may object to the processing of your personal data by us. In such case we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing, which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defense of legal claims.

  • Erasure right. Unless prohibited by statutory provisions or overridden by our legitimate interests, you may demand the deletion of your personal data held by us.

  • Right to withdraw consent. If we process your data based on consent, you may revoke it at any time, following which we will no longer process your data based on such consent. This does not affect the lawfulness of prior processing activities based on consent.

  • You have the right to lodge a complaint to your local data protection authority.

Amendments to the Privacy Policy

This privacy policy may be amended by us from time to time. We suggest for you to periodically review this page. In amending the privacy policy, the “last modified” date at the top of this privacy policy shall be updated. The privacy policy currently published on our website is regarded as valid and effective.

Contacting Us

Please contact us if you have any questions, comments, or requests regarding this privacy policy. Our contacts are as follows:


UP Catalyst OÜ

Estonian commercial register code: 14798378
Registered address: Akadeemia tee 23, Tallinn 12618, Estonia
e-mail address: info@upcatalyst.com

Our supervisory authority is the Estonian Data Protection Inspectorate (www.aki.ee)