Privacy Policy
Version 1.1 · Last updated: 26 June 2026
1. Controller
The controller responsible for processing personal data on this website is:
plusRS OÜ (a HM Ventures OÜ company)
Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551
Registry code: 17182790 · VAT ID: EE103002866
Email: privacy@plusrs.com
We are not required to appoint, and have not appointed, a Data Protection Officer. For any data-protection matter, please contact privacy@plusrs.com.
This policy covers personal data processed via the plusrs.com website only. The opexONE product and the customer data processed within it are governed by separate terms (our Data Processing Agreement and Sub-processors list).
2. No Tracking, No Tracking Cookies
This website uses no analytics, advertising, or tracking technologies, and sets no tracking cookies. Fonts are served from our own infrastructure — no requests are made to third-party font or tracking services when you browse this site. Any strictly-necessary cookies required for security or form submission are exempt from consent under the ePrivacy Directive; we do not use a cookie banner because we set no consent-requiring cookies.
3. What We Process, and Why
a) Server logs
When you visit this website, our hosting provider (Amazon Web Services / AWS Amplify) automatically processes technical data — IP address, date and time of access, requested page, browser type — in server logs. This is necessary to deliver the website securely and to detect abuse. Legal basis: our legitimate interest in site security, IT integrity, and abuse detection (Art. 6(1)(f) GDPR, Recital 49). Logs are retained for no longer than 30 days and then deleted, and are not merged with other data.
To protect our forms against spam and abuse we use a hidden honeypot field and IP-based rate-limiting, which briefly process the submitting IP address. Legal basis: our legitimate interest in IT security and abuse prevention (Art. 6(1)(f) GDPR, Recital 49).
b) Contact form and email enquiries
If you contact us via the contact form or by email, we process the data you provide (name, email address, company, message content) solely to handle your enquiry. Legal basis: pre-contractual measures and legitimate interest (Art. 6(1)(b) and (f) GDPR). Messages are sent via Amazon SES and received and stored in our Microsoft 365 mailbox; they are retained for as long as needed to handle the enquiry and any follow-up, after which they are deleted. Providing this data is voluntary, but without it we cannot respond to your enquiry.
c) Job applications
If you send an application to careers@plusrs.com, we process your application data (CV, contact details, correspondence) to evaluate your application. Legal basis: steps prior to entering an employment contract, taken at your request (Art. 6(1)(b) GDPR), and our legitimate interest in assessing your suitability (Art. 6(1)(f) GDPR). Estonian law (the Personal Data Protection Act and the Employment Contracts Act) governs, and the Estonian Data Protection Inspectorate supervises. Providing this data is voluntary, but without it we cannot evaluate your application. Application data is deleted no later than six months after the conclusion of the application process, unless you expressly consent (Art. 6(1)(a) GDPR) to longer retention in our talent pool.
d) No automated decision-making
We carry out no automated decision-making or profiling within the meaning of Art. 22 GDPR. IP-based rate-limiting is a purely technical abuse-prevention measure with no legal or similarly significant effect on you.
4. Recipients and Transfers
We rely on the following processors: Amazon Web Services (website hosting via AWS Amplify and outbound email delivery via Amazon SES) and Microsoft 365 — provided by Microsoft Ireland Operations Limited, with Microsoft Corporation as the underlying entity — for receiving and storing our email correspondence in Exchange Online, OneDrive and SharePoint. Where personal data is processed outside the EEA, it is safeguarded by the EU–US Data Privacy Framework — under which Amazon Web Services is covered by the Amazon.com, Inc. certification and Microsoft Corporation is certified — with EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a fallback. We use no analytics, advertising, or tracking providers, and we do not sell personal data.
5. Your Rights
Under the GDPR, you have the right to:
- access the personal data we hold about you (Art. 15)
- rectification of inaccurate data (Art. 16)
- erasure (Art. 17) and restriction of processing (Art. 18)
- data portability (Art. 20)
- object to processing based on legitimate interest (Art. 21)
To exercise any of these rights, contact privacy@plusrs.com. You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, +372 627 4135, info@aki.ee, aki.ee. You may also complain to the supervisory authority in your country of residence or work.
6. Data Security
This website is served exclusively over TLS-encrypted connections. We apply appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access.
7. Changes to This Policy
We may update this privacy policy when the website or legal requirements change. The current version is always available on this page.
See also our imprint.