Privacy Policy

1. Who We Are and Our Responsibilities

The data controller for the processing of personal data on this website is:
PARALLEL IDEAS OÜ
Address: Harju maakond, Jõelähtme vald, Kostivere alevik, Jõe tn 4-8, 74204, Estonia.
Phone: +372-610-42-52
Email: info@rollupmaster.ee
The controller determines the purposes and methods of processing personal data and is responsible for ensuring compliance with data protection requirements.
Requests regarding data subject rights should be sent to the email address above. Responses will be provided without undue delay and within one month from receipt of the request.
No separate Data Protection Officer has been appointed; for all data protection inquiries, please use info@rollupmaster.ee.

2. How We Collect Your Data and What Data We Process

2.1. Data Provided by You
Your data is collected when you provide it to us personally. This may include:

  • Data you enter in the contact form on the website;
  • Data you provide when sending us an email;
  • Data you provide over the phone;
  • Data you provide by selecting checkboxes in forms (e.g., when subscribing to a newsletter or consenting to personal data processing);
  • Data you enter when placing an order, including name, delivery address, contact details, and payment information;
  • Any other data you voluntarily provide during the purchase or use of related services.

 2.2. Data Collected Automatically
Other data is collected automatically or with your consent when you visit the website by our IT systems. This may include:

  • Technical data of your browser and device, browser version, operating system, device type, screen resolution, system language, IP address, access time, session duration;
  • Data on behavior on the website (viewed products, added to cart, clicks, navigation sequence, interaction time);
  • Location data based on IP address;
  • Data on referral source, referrer, search query, or advertising campaign;
  • Data on downloads, errors, and technical issues during order processing.

3. Purposes of Using Your Data

  • Performance of contractual obligations — concluding and fulfilling sales contracts, processing orders, organizing delivery, returns, and warranties.
  • Customer communication — correspondence, order status information, handling inquiries and complaints, consultations.
  • Website and service improvement — analyzing website usage to improve usability and service quality.
  • Marketing — only with your consent (e.g., newsletters, special offers, cart reminders).
  • Legal compliance — compliance with tax, accounting, and other legislation.
  • Security — protecting IT systems and preventing abuse.

If we intend to use your data for other purposes, we will notify you in advance in clear language and specify the legal basis.

4. Legal Bases for Processing Personal Data

We process data only when there is a lawful basis:

  • Consent.
    If you provide voluntary, specific, informed, and unambiguous consent, we process data strictly within its scope (e.g., newsletter subscription, non-essential cookies, feedback outside a contract).
    Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Performance of a contract and pre-contractual measures.
    Processing of data necessary for fulfilling a contract and actions prior to its conclusion (e.g., order processing and delivery, status notifications, responses prior to purchase).
  • Legal obligations.
    Processing necessary to fulfill legal obligations (e.g., storing accounting documents, responding to government authorities).
  • Legitimate interests.
    Processing based on our legitimate interests: ensuring website security and stability, fraud prevention, logging technical events, basic visit statistics, protecting legal claims, communication with existing clients.
    Before such processing, we conduct a balancing test. You have the right to object to such processing at any time.

5. Categories of Personal Data Processed

We collect and process the following categories of data:

  • Contact information: first name, last name, email, phone;
  • Data provided in contact forms and applications;
  • Company information (if applicable);
  • Delivery and billing address;
  • Payment information for applicable payment methods;
  • IP address and location data;
  • Technical data of browser and device;
  • Cookie and similar technology data (see §8);
  • Order history and interactions with the website and emails.

All data is processed only to the extent necessary for the stated purposes.

6. Data Processing for Order Fulfillment and Recipients

6.1. Delivery Providers
For delivery, we use Cargobus, DPD, and our courier service.
Recipient name and delivery address are shared.
Email and phone are shared only with your explicit consent (for delivery or notifications). Consent can be withdrawn at any time.

6.2. Payment Services
Montonio Finance OÜ, Harju County, Kesklinna District, Rotermanni St. 8, 10111, Tallinn — for payment processing.
Transfer is limited to necessary payment and order data. Providers may perform automated credit risk assessments; you may object to the provider.

6.3. Web Hosting and Infrastructure
Zone Media OÜ, Harju County, Lasnamäe District, Lõõtsa St. 5, 11415, Tallinn.
Processes IP address, access date and time, time zone, HTTP status, data volume, browser type and version, OS, referring site, and visited pages.
Data is stored in log files for website stability and security.

6.4. Cookie Banner
CookieYes Limited, 3 Warren Yard Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom.
Used to manage user consent for cookies. The banner stores a cookie with your choice and maintains a consent log.
You can change or withdraw consent at any time via the “Cookie Settings” link at the bottom of the site.
For detailed rules on the use of cookies, their categories, and retention periods, see §8.

6.5. Analytics
Google Analytics, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Used only with your consent for statistical cookies. IP anonymization is enabled; data may be processed outside the EU under Standard Contractual Clauses.
Google Analytics operates only with your consent; settings and withdrawal can be found in §8.

6.6. Form Protection
Divi’s Basic Captcha, Elegant Themes, 977 West Napa Street #1002, Sonoma, CA 95476, USA.
Operates locally, does not use external APIs, and does not transmit personal data to third parties. Verification is performed in your browser.

6.7. Newsletters
MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland.
Used to send newsletters with your consent. Processes email, name (if provided), IP address, and interaction with emails.
Unsubscribe via the link in the email footer.

6.8. Third-Party Platforms via Links
Instagram (Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA).
Facebook (Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA).
Pinterest (Pinterest Inc., 651 Brannan St., San Francisco, CA 94107, USA).
The site uses standard links and icons. Data begins to be processed by the platform only after clicking and leaving the site.
We do not control further processing by these providers. Please review their privacy policies before using these functions.

 

7. Cross-Border Data Transfer

The main processing of data occurs in the EU.
Some services may process data in countries with different levels of protection, including the USA.
We apply the European Commission Standard Contractual Clauses and additional technical and organizational measures.
If a provider participates in a recognized adequacy scheme, we rely on it. Information on applied safeguards is available upon request.

 

8. Cookies and Server Log Files

When first visiting the website, you see the CookieYes banner and may:

  • consent to the use of cookies;
  • refuse;
  • select only necessary cookies.

You can change your choice later via the “Cookie Settings” link at the bottom of the site.

8.1. Categories of Cookies and Purposes

  • Necessary cookies — ensure basic website functions.
  • Functional cookies — improve usability and remember settings.
  • Statistical cookies — used for analytics (only with consent).
  • Marketing cookies — used only with your consent.

8.2. Consent Management
The CookieYes banner saves your choice, date, and version. Consent can be changed or withdrawn at any time.
The consent log is retained to prove compliance with legal requirements.

8.3. Individual Settings and Refusal
You can allow all cookies, refuse all except necessary, or select specific categories.
Disabling cookies may limit website functionality.

8.4. Cookie Table and Retention Periods
The list of cookies with names, providers, purposes, and retention periods is available on the “More about cookies” screen in the banner.
Persistent cookies are kept until deleted by the user or automatically by the browser.

8.5. Do Not Track and Global Privacy Control Signals
If your browser sends a DNT or GPC signal, we take it into account where possible.
In case of conflict, your choice in the cookie banner prevails.

8.6. Local Storage and Similar Technologies
We may use browser local storage to save technical interface settings.
This data is not shared with third parties and can be deleted in browser settings.

8.7. Server Log Files
The website provider automatically collects and stores information in server log files: browser type and version, OS, referrer, host name, request time, IP address.
Data is not combined with other sources.
Collection is necessary for technically error-free presentation and optimization of the website.

 

9. Retention Period

Unless a specific period is stated, data is stored while the processing purpose is relevant, then deleted or anonymized.

After contract completion, retention periods according to tax and commercial law apply:

  • Business and accounting documents — up to 7 years;
  • Business correspondence — up to 6 years;
  • Order and delivery data — up to 7 years;
  • Newsletter account data — until unsubscription;
  • CookieYes data — as long as required to record consent or until withdrawal;
  • Statistical cookies and analytics events — according to the validity period of specific cookies or until withdrawal of consent;
  • Server logs — limited period sufficient for security and incident investigation.

If you withdraw consent or request deletion, data will be erased unless there is another legal basis.

 

10. Obligation to Provide Data and Consequences of Refusal

Contact and address data, as well as payment and delivery information, are mandatory for order processing and fulfillment. Without them, the order cannot be processed.
Data for newsletters and marketing is provided voluntarily.

 

11. Your Rights Regarding Data

You have the right to:

  • obtain confirmation of processing and access to your data;
  • know the purposes, categories, recipients, and retention periods;
  • request correction of inaccurate or incomplete data;
  • request deletion if data is no longer necessary or processing is unlawful;
  • request restriction of processing in certain cases;
  • receive your data in a machine-readable format and transfer it to another operator if such processing is provided;
  • object to processing based on legitimate interests, including profiling;
  • opt out of direct marketing;
  • withdraw consent at any time;
  • lodge a complaint with the supervisory authority: Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, e-mail:info@aki.ee.

Right to a Copy of Data.
Upon request, we will provide a copy of the processed personal data.
Additional copies may incur a reasonable fee covering administrative costs.
When providing a copy, we take into account the rights and freedoms of others.

Information on Safeguards for Cross-Border Transfer
If your data is transferred outside the EU, you have the right to receive information on the safeguards applied.

How to Exercise Your Rights
Send a request to info@rollupmaster.ee.
We will respond within one month; if the request is complex, the period may be extended.

12. Data Security

We apply technical and organizational measures:

  • HTTPS encryption;
  • Regular CMS and plugin updates;
  • Access restriction and monitoring of user actions;
  • Backup and storage of copies in a secure environment;
  • Firewall and security monitoring;
  • Processing agreements with providers and staff training.

In the event of a security incident, we act promptly.
If there is a risk to your rights and freedoms, we will notify you without delay.

 

13. Special Provisions for Children and Minors

The website is intended for adults.
Minors may place orders with parental or legal guardian consent.
We do not intentionally collect data of children under 16 for marketing purposes.
If we become aware of collecting data of a child without legal basis, it will be deleted.

 

14. Automated Decisions and Profiling

We do not make decisions based solely on automated processing that create legal effects for you.
Some payment providers may perform automated credit risk assessments — to prevent fraud and losses.
You have the right to object to such processing with the provider, but this may limit available payment methods.

15. Collection of Data Not from the Data Subject

We may receive personal data not directly from you, but from third parties — payment providers, carriers, technical operators.
In such cases, we will inform you of:

  • who the controller is and contacts;
  • purposes and legal bases;
  • categories of data received;
  • categories of recipients;
  • information on cross-border transfers and safeguards;
  • retention periods or criteria for their determination;
  • our legitimate interests (if applicable);
  • your rights, including objection and complaint;
  • source of data (including if from publicly available sources).

Information is provided within a reasonable period after receiving the data, no later than one month.
If data is used to contact you — at first contact.
If disclosure to third parties is planned — before disclosure.
If notification is impossible or requires disproportionate effort, we take measures to protect your rights, including publishing information in this policy.

16. Updates to This Policy

We reserve the right to amend or adapt these terms to comply with applicable legal requirements or changes in our services.
The current version is always available on our website.

 

 

Last Updated: 05.02.2026
Effective as of publication on www.rollupmaster.ee.

 

Delivery all over Estonia & EU is available
Delivery all over Estonia & EU is available