Last updated 5 September 2026
Privacy Policy
How 3S holding OÜ handles personal data on this website. Written to be read, not to be survived: if anything here is unclear, write to us and we will explain it.
1. Who is responsible for your data
The controller is 3S holding OÜ, a private limited company registered in Estonia under registry code 16417831, EU VAT EE102621015, with its registered office at Purpuri tn 12-2, 51011 Tartu, Tartu maakond, Estonia.
For any question about this policy, or to exercise any of the rights described in section 8, write to info@3sholding.net. We are not required to appoint a Data Protection Officer and have not appointed one; enquiries go to the management board at that address.
2. What this policy covers
This policy covers the website at 3sholding.net. It does not cover systems we build or operate for clients — in those, our client is the controller and their own policy applies, with us acting as a processor under a written data-processing agreement.
3. What we collect, and why
We collect as little as we can. In practice there are three categories.
3.1 What you type into a form
If you send a proposal request or a message, we receive: your name, your work e-mail address, your message, and — on the proposal form — your organisation’s name, the project-scope option you selected, and, if you chose to give it, an indicative budget band.
- Purpose: to read your enquiry, work out whether we can help, and reply.
- Legal basis for the required fields (name, e-mail, message, and on the proposal form the organisation and scope): Article 6(1)(b) GDPR — steps taken at your request before entering into a contract. Without them we cannot answer you.
- Legal basis for the optional budget field: Article 6(1)(f) GDPR — our legitimate interest in judging whether a scope is realistic before spending time on it. You can leave it blank, and you may object to this processing at any time under Article 21.
- We do not ask for consent for these forms, because consent is not the correct basis for processing that is necessary to answer your own request — and a consent box that you cannot meaningfully refuse while still using the form would not be freely given.
3.2 What the server records automatically
Our web server keeps standard access logs: IP address, date and time, the page requested, the HTTP status, and the browser’s user-agent string.
- Purpose: keeping the site available, diagnosing faults, and detecting abuse such as automated form submissions or intrusion attempts.
- Legal basis: Article 6(1)(f) — our legitimate interest in operating a secure, working website.
- Retention: 14 days, then automatically deleted. We do not build profiles from logs and do not combine them with form submissions.
3.3 Measurement, only if you allow it
If — and only if — you switch on the analytics option in the consent banner, we load Microsoft Advertising’s UET tag, which tells us whether an advertisement led to an enquiry. Until you do that, no measurement or advertising script is loaded at all, and the tag’s consent signals are set to denied before anything else runs.
- Legal basis: your consent — Article 6(1)(a) GDPR, and § 1031 of the Estonian Electronic Communications Act implementing the ePrivacy Directive.
- Withdrawal: and switch it off. Withdrawal takes effect immediately and is as easy as granting.
- Recipient: Microsoft Ireland Operations Limited and Microsoft Corporation, as an independent controller for its own purposes under its own privacy statement.
- Status today: no advertising tag identifier is configured on this site yet, so at the time of writing the tag would not load even with consent given. This section describes what happens once one is configured.
We do not use Google Analytics, Meta pixels, session recording, heat-mapping, A/B testing tools or any advertising network other than the one described above.
4. Cookies and browser storage
This site sets no cookies of its own. Your consent decision is kept in your browser’s local storage under the key 3sh.consent.v1, which records what you chose and when. It never leaves your browser and we cannot read it from our server. Clearing your site data removes it and you will be asked again.
The full inventory, including what the optional Microsoft tag would set, is in the Cookie Policy.
5. Who else sees your data
Your enquiry is read by our own staff. Beyond that, the only third parties involved are the infrastructure providers that make the site work:
- Namecheap, Inc. (AS22612) — our web hosting provider, in the United States. Acting as a processor. Your message is stored on that server.
- Microsoft — only if you consented to measurement, as described in section 3.3.
We do not sell personal data, we do not share it for anyone else’s marketing, and we do not use it for automated decision-making or profiling producing legal or similarly significant effects.
6. International transfers — please read this one
We host this website with Namecheap, Inc. (AS22612) in the United States, which is outside the European Economic Area. Personal data you submit through this site is therefore transferred to a third country.
That transfer is made under Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the safeguard permitted by Article 46(2)(c) GDPR, together with the technical measures described in section 7. You are entitled to ask us for a copy of the safeguards; write to the address in section 1.
We are telling you this plainly because a European visitor is entitled to know where their data goes, and because we verified the hosting location by measurement rather than assuming it. We did not want to claim EU hosting that we could not stand behind. Measured from inside the production host: RDAP for 104.207.82.198 returns the ARIN allocation NET-104-207-64-0-1 held by Namecheap, Inc.; round-trip time is 22 ms to Cloudflare's anycast resolver and 25-41 ms to United States civic hosts, against 53 ms to Germany and 168 ms to Lithuania - a European location is excluded by the latency alone.
7. How we protect it
- The whole site is served over HTTPS; plain HTTP requests are redirected.
- Database credentials are held in a file readable only by the application account, outside the web root, and are never present in the source repository.
- The application account has only the database rights it needs, and no shell access.
- A firewall limits reachable ports; repeated failed access attempts are blocked automatically.
- Submitted data is written using parameterised queries and is never interpolated into SQL.
- Security headers restrict what the page may load and prevent the site being framed.
No system is perfectly secure. If you believe you have found a vulnerability in this site, please tell us at info@3sholding.net and give us a reasonable opportunity to fix it before disclosing it.
8. How long we keep it
- Enquiries and proposal requests: 24 months from our last contact with you, then deleted. If the enquiry becomes an engagement, the relevant records move to the contract file and follow its own retention period, which is driven by Estonian accounting and limitation rules.
- Server access logs: 14 days.
- Your consent record: in your own browser until you clear it.
9. Your rights
Under the GDPR you may:
- ask what we hold about you and get a copy (Article 15);
- have inaccurate data corrected (Article 16);
- have data erased where the conditions are met (Article 17);
- have processing restricted while a dispute is resolved (Article 18);
- receive data you gave us in a portable format (Article 20);
- object to processing based on legitimate interests, including the optional budget field (Article 21);
- withdraw consent to measurement at any time, without affecting what happened before.
Write to info@3sholding.net. We answer within one month, and we do not charge for it. We may need to check who you are before releasing data — that check is itself a protection for you.
If you are unhappy with how we have handled your data, you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, www.aki.ee, or to the supervisory authority where you live or work.
10. Children
This is a business-to-business site and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us data, tell us and we will delete it.
11. Changes to this policy
If we change how we handle data, we update this page and the date at the top. Where a change materially affects you — a new recipient, a new purpose, a different hosting location — we will say so prominently rather than relying on you noticing a changed date. Earlier versions are available on request.