Data Controller
The controller responsible for processing your personal data is:
Data We Collect
We collect personal data only where there is a legitimate purpose for doing so. The categories of data we collect depend on how you interact with us.
- Full name and company name
- Email address and phone number
- Shipment details (route, vehicle type, quantity, preferred dates)
- Any additional information you include in your message
- Origin and destination country and city
- Vehicle specifications and quantity
- Contact details provided at the estimate stage
- IP address and browser type (collected automatically)
- Pages visited, time spent, and navigation path
- Referral source and device type
- Cookie data (see Section 9)
We do not collect special category data (as defined in GDPR Article 9) and we do not knowingly collect data from persons under 16 years of age.
How We Use Your Data
| Purpose | Description |
|---|---|
| Responding to enquiries | Processing your quote request or contact form submission and providing a service proposal. |
| Service delivery | Coordinating and executing vehicle transport and logistics operations once you become a client. |
| Contract performance | Managing transport agreements, issuing invoices, and fulfilling obligations under the CMR Convention and our ISO 9001 quality standards. |
| Legal compliance | Meeting our obligations under Estonian and EU law, including accounting, tax, and customs requirements. |
| Website analytics | Understanding how visitors interact with our website in order to improve its performance and content. |
| Service communications | Sending operational updates or responses to your requests. We do not send marketing emails without your explicit prior consent. |
Legal Basis for Processing
All processing of personal data by Hert-Transport AS is grounded in one or more of the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): processing is necessary to respond to your enquiry, provide a quote, or carry out a transport contract to which you are party.
- Legal obligation (Art. 6(1)(c)): processing is required for compliance with accounting, tax, customs, or other legal obligations applicable in Estonia and the EU.
- Legitimate interests (Art. 6(1)(f)): processing for website analytics and service improvement, provided our interests do not override your rights and freedoms.
- Consent (Art. 6(1)(a)): where you have given explicit consent, for example to receive marketing communications or to accept non-essential cookies. You may withdraw consent at any time.
Retention Periods
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by applicable law. The following periods apply:
| Data type | Retention period | Legal basis |
|---|---|---|
| Enquiries where no contract is formed | 12 months | Legitimate interest, follow-up and service improvement |
| Client contracts and transport records | 7 years | Estonian Accounting Act (§12) |
| CMR waybills and shipping documents | 7 years | Legal and customs requirements |
| Invoices and financial records | 7 years | Estonian Accounting Act |
| Website analytics data | Up to 26 months | Legitimate interest, website improvement |
| Cookie consent records | 12 months | Legal obligation, consent management |
At the end of each applicable retention period, data is securely deleted or irreversibly anonymised.
Who We Share Data With
We do not sell, rent, or exchange your personal data. We share data with third parties only where operationally necessary or legally required:
- Logistics network partners: where your shipment involves routes or handling coordinated through our partner network, relevant shipment data is shared with network members under data processing agreements that comply with GDPR.
- Fleet tracking and operations providers: service providers that support shipment visibility and fleet management. Each provider's own privacy policy applies to data they process on their systems.
- IT and hosting service providers: for website hosting, email delivery, and business system operations. All providers operate under data processing agreements and are bound by GDPR requirements.
- Legal and regulatory authorities: where required by Estonian or EU law, court order, or to protect our legal rights.
- Professional advisors: accountants, auditors, and legal counsel, where required to fulfil our financial and legal obligations.
All third parties with whom we share personal data are contractually bound to process it securely and solely for specified purposes. We do not permit third parties to use your data for their own marketing activities.
International Data Transfers
Our primary operations and data storage are within the European Economic Area (EEA). Hert-Transport AS operates logistics routes across 17+ European countries, and some data processing may involve partners or tools located outside the EEA. In all such cases, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission for the relevant country
- Other legally recognised transfer mechanisms under GDPR Chapter V
You may request details of the safeguards applied to any specific international transfer by contacting us at hert@hert.ee.
Your Rights
Under the GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, submit a written request to hert@hert.ee. We may need to verify your identity before processing the request.
- Right of access (Art. 15): request a copy of the personal data we hold about you and information about how we use it.
- Right to rectification (Art. 16): request correction of personal data that is inaccurate or incomplete.
- Right to erasure (Art. 17): request deletion of your data where there is no legitimate reason to continue processing it, subject to our legal retention obligations.
- Right to restriction (Art. 18): request that we suspend processing of your data in certain circumstances.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format where processing is based on consent or contract and carried out by automated means.
- Right to object (Art. 21): object to processing based on legitimate interests, including any profiling based on such interests.
- Right to withdraw consent: where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.
We will respond to all verified requests within 30 calendar days. For complex or multiple requests, we may extend this period by a further 60 days and will notify you. There is no fee for exercising your rights in ordinary circumstances. If you believe your rights have not been respected, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee), or with the supervisory authority in your country of residence.
Cookies
We use cookies and similar tracking technologies on our website. Cookies are small text files placed on your device that help us operate the site and understand how it is used. You will be asked for your consent to non-essential cookies when you first visit the site.
| Cookie type | Purpose | Duration | Consent required |
|---|---|---|---|
| Essential (session) | Form functionality, security tokens, navigation state | Session | No |
| Cookie consent record | Stores your cookie preferences | 12 months | No |
| Language preference | Remembers your ET/EN language selection | 12 months | No |
| Analytics | Aggregate website usage statistics, pages visited, session duration, traffic sources. Processed by a third-party analytics provider. | Up to 26 months | Yes |
You can withdraw or change your cookie consent at any time through our cookie preference centre or by adjusting your browser settings. Note that disabling essential cookies may affect website functionality.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. Measures in place include:
- Encrypted connections (HTTPS) for all data transmitted to and from our website
- Access controls limiting data access to authorised personnel only
- Periodic review of our data processing procedures and systems
- Data processing agreements with all third-party service providers
In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, we will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of the breach. Where required by law, we will also notify affected individuals without undue delay.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable legal requirements. When we do, we will revise the "Last updated" date at the top of this page. For material changes that significantly affect how we process your personal data, we will provide a more prominent notice, either by email (if we hold your contact details) or by a notice on our website.
We encourage you to review this policy periodically to stay informed about how we protect your data.
Contact Us
For questions about this Privacy Policy, to submit a data subject request, or to raise a concern about how we handle your personal data, please reach us through any of the following channels:
Ilmatsalu põik 3a
50407 Tartu, Estonia
www.aki.ee