Privacy Policy
What is personal data?
Personal data is data that allows identifying you. Personal data does not include anonymous or aggregated data, such as aggregate statistics of users, i.e. data that cannot be unambiguously linked to you. Personal data includes, for example, your first and last name, personal code, gender, language, place of residence, date of birth, phone number, contact details on social media, e-mail address, network identifiers, such as your MAC address and IP address, and cookies.
Data controller
The data controller of the personal data on Liikluslab mobile app, the site liikluslab.ee and all its subdomains, including e.liikluslab.ee (hereinafter: Services) is Liikluslab group of companies, consisting of Liikluslab Baltic OÜ (registry code 14812701) and Liikluslab Eesti OÜ (registry code 12190856), located at Rotermanni 18/1-301, Tallinn, e-mail [email protected].
Using Services
When you use our Services, we automatically collect and store technical information sent by your browser, including the following: your IP address, the website you used to reach the current site, the versions of your browser and operating system, HTTP query parameters, the user’s session identifier, the unique identifier of the device, and the CSRF token. Some of this data is collected using cookies. When visiting the liikluslab.ee site or Liikluslab mobile app for the first time you see a warning that cookies are used. If you continue to use the liikluslab.ee site or Liikluslab mobile app, you agree with the usage of the required cookies. Learn more about cookie files in Cookie policy.
We process your personal data, which is part of this technical data, to ensure the stable and safe use of the Services, protect personal data from loss, damage, theft, or unauthorised access, and, if necessary, to identify a device which has been used to carry out illegal or malicious operations when using the Services. The legal basis for processing is your consent and the legitimate interest of Liikluslab group of companies.
In addition, we process this data to identify breaches of the terms and conditions of use of the online environment of Liikluslab (hereinafter: terms of use) and, if necessary, to identify the user responsible for the breach and/or the device used to carry out such operations. The legal basis for processing is the legitimate interest of Liikluslab group of companies.
We retain and process the collected technical information until the achievement of the objectives stated above – generally, for three years. After that, the data is deleted automatically.
Registration and login
When registering and logging in depending on the login method we may request the Facebook identifier, name, surname and e-mail address of the Facebook user.
Mobile app doesn't support logging in via Facebook.
We process this personal data to personalise the Services, ensure the efficient operation of support services, ask for your feedback, remind you of important events (e.g. the expiry of the term of your plan), and send you payment documents. The legal basis for processing is compliance with the terms of use and the legitimate interest of Liikluslab group of companies. To achieve these goals, we retain and process the personal data listed above until your account is closed. You can send a request for closing your account to the e-mail address [email protected].
We also process this personal data to ensure compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. For this purpose, your Facebook user ID and name will be added as a watermark to all images of the learning materials. The legal basis for processing is the legitimate interest of Liikluslab group of companies to control the compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. Considering the legitimate purpose of data processing, the fact that the terms of use are available to you and are reasonable, and the fact that only your identifier and full name are processed, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests. For this purpose, we retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account.
If you have granted your consent, your e-mail address will be processed for sending messages for direct marketing purposes. Your consent is the legal basis for the processing. You have the right to revoke your consent at any time. You can do so under your user profile (the button ‘I want to keep up to date with Liikluslab news’), by clicking the respective link in the footer of the e-mail or by contacting our customer service ([email protected]).
Devices
We control from which devices you use the online environment as you may use it only from 3 different devices. The legal basis for processing is the legitimate interest of Liikluslab group of companies to ensure compliance with the terms of use. If you use more than three devices, then Liikluslab may require two-factor authentication when logging in. Considering the legitimate purpose of data processing, the fact that the number of devices limitation is described in the terms of use, which are available to you and are reasonable, and the fact that only data required to identify the device is processed, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests. For this purpose, we retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account.
Published data
We monitor public websites, social networks and other sources to identify breaches of the terms of use (e.g. publishing screenshots from study materials, providing access to the account to third parties or a corresponding offer, etc.) The legal basis for processing is the legitimate interest of Liikluslab group of companies to ensure compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. Considering the legitimate purpose of data processing, the fact that Liikluslab group of companies very often has problems with breaching the listed terms of use, the fact that the terms of use are available to you and are reasonable, and the fact that those sources are public, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests. For this purpose, we retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account.
Choosing a driving school
When registering you are asked to select your driving school. This is an option, not an obligation. When the driving school is selected, your theory teacher is able to see your full name, e-mail address, if registering with Facebook - name in Facebook, online environment usage statistics. We offer the option to upload a profile picture, if desired, so that the driving school can provide a better user experience and customer service during client engagement. Uploading a profile picture is optional, not mandatory, and can be deleted by the user at any time. We process this personal data to simplify and personalise the learning process and to allow giving driving theory tests online. The legal basis for processing is the legitimate interest of Liikluslab group of companies. To reach these goals, we retain and process personal data while your driving school is selected. You can cancel your choice of a driving school at any time by selecting "I will choose later / the school is not in the list" under the "School" inscription in the "My profile" section of the online environment.
Registration for driving school courses
On the liikluslab.ee website you can choose a driving school and register for training courses. This is an option, but not an obligation. When registering for a training course, you will need to fill in the information requested on the registration form, including your personal and contact details, which are required to register you for the course and to send you invoices. After registration, your data will be sent to the driving school via the Liikluslab admin panel; your name, contact details and training preferences will be sent to the driving school by email. This data will be processed by a person appointed by the driving school for the purpose of registering you for training, including billing you for training and clarifying your training preferences.
We keep and process your data for as long as it is necessary to register you for training and enable you to take advantage of the bonuses provided by Liikluslab, generally 1 year, after which the data is automatically deleted.
Paying for our services
Mobile app doesn't support paying for our services.
The payment system requests and processes the personal data required for making the payment. The payment system services are provided by Maksekeskus AS (registry code: 12268475, address: Niine 11, Tallinn 10414, Estonia) and Montonio Finance OÜ (registry code: 14557628, address: Kai 1, Tallinn 10111, Eesti). We do not retain or process the client data, with the exception of the name of the payer, which is forwarded to us by Maksekeskus AS and Montonio Finance OÜ.
In order to, if necessary, identify the persons responsible for breaches, the name of the payer will be added as a watermark to all images of the learning materials. We retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account. The legal basis for processing is the legitimate interest of Liikluslab group of companies to ensure compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. Considering the legitimate purpose of data processing, the fact that your card obviously will not be used to pay for the services used by a stranger, the fact that the terms of use are available to you and are reasonable, and the fact that only your name is used, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests.
We retain and process your name, e-mail address, and the payer name in accordance with the provisions of the Accounting Act and the relevant taxation legislation. We retain this data for seven years as an accounting source document. The legal basis for processing is compliance with legal obligations.
Health Check Service
The group of Liikluslab companies offers the opportunity to undergo a health check for motor vehicle drivers at its partner clinics. The service's Terms of Use are available here.
When you register for a health check, we will ask for your name, personal identification number, e-mail address, telephone number, communication language and the group of health certificate you are applying for. We process this personal data to enable you to complete the health check and to provide you with information about the service. The legal basis for the processing is the legitimate interest of the Liikluslabi group of companies to ensure compliance with the terms and conditions of the service referred to above and to enable health checks to be carried out by partner clinics. In view of the legitimate purpose of the processing, the fact that the conditions of the service referred to above are available to you and reasonable, we consider that your interests or the fundamental rights and freedoms for the protection of personal data do not outweigh our interest. To this end, we will retain and process the personal data until the purposes set out above have been fulfilled, normally for a period of six months after the health check.
The health check is carried out by a partner clinic of Liikluslab. Liikluslab does not have access to your health-related data and we do not collect or process it.
At your request and with your consent, we will forward the group and the date of issue of the health certificate (hereinafter: health certificate information) to the driving school, which is a partner of Liikluslab, so that the driving school can meet requirements of MKM Regulation No. 60 § 29 and you can start learning more quickly. In order to transmit the information, the occupational health professional enters the health certificate information in the Liikluslab information system and Liikluslab forwards the information to the driving school of your choice. Your consent to share your health certificate information with Liikluslab and with the driving school of your choice will be asked twice - when you register for the health check on the website liikluslab.ee and during the health check. When you give your consent, we ask you to choose the driving school (or schools) to which you want to transmit the information. If at the time of the health check you do not know which driving school you will go to, you can give your consent for the health certificate information to be transmitted to Liikluslab, and you can choose the driving school to which the information will be transmitted later. You can withdraw your consent to the transmission of health certificate information by telling the occupational health professional at the time of the health check or by clicking on the corresponding link in the confirmation e-mail you receive. The legal basis for the processing of the data is your consent. We will retain and process personal data until the above purposes are fulfilled.
If you are referred for a re-check during the health check, the Liikluslab group of companies will be able to offer you a discount on a re-check. In order to receive the discounted rate, the occupational health professional must, with your consent, note in the Liikluslab information system that you have been assigned a re-check (the reason for the re-check and the health-related information are not noted). This is an option, not an obligation. If you do not wish to receive a discount, or do not wish to provide information about the re-check, you do not have to give your consent. You can withdraw your consent by clicking on the link in the e-mail we will send you after the health check. The legal basis for the processing of the data is your consent. We will retain and process personal data until the purposes set out above have been fulfilled, normally for a period of six months.
Recipients of personal data
Personal data is forwarded to the employees of Liikluslab group of companies who need to process it due to their working duties.
Personal data is forwarded to data processors authorized by Liikluslab group of companies (e.g. data storage service provider, accountant or IT service provider) on the basis of contracts concluded between Liikluslab group of companies and the data processors. The data processors are obligated to ensure relevant protective measures in the processing of personal data.
Personal data is stored in the servers of DigitalOcean LLC, which are located in the territories of EU Member States or members of the EEA.
Data may also be forwarded to third parties if this is required by the current legislation (for example, data protection organizations) or if it is necessary in the legitimate interests of Liikluslab group of companies to protect its rights (legal consultant, collection).
Security and access to data
Liikluslab group of companies implements physical, organisational, and information technological security measures to protect personal data from accidental or illegal destruction, loss, alteration, or unauthorised disclosure or access.
Your rights in the processing of personal data
You have the following rights:
- to receive information about the processing of personal data;
- to access your personal data that Liikluslab group of companies processes;
- to request the rectification of your personal data if the personal data processed by Liikluslab group of companies is incorrect;
- to request the erasure of your personal data if, in your opinion, there is no legal basis for the processing or if the erasure is required in accordance with valid legislation;
- to object to the processing of personal data on the basis of legitimate interest. If the objection is declared valid, your personal data will be erased and will no longer be processed;
- to request the transmission of the personal data which you have submitted to us and the legal basis for the processing of which is your consent or compliance with the terms of use;
- to revoke your consent to procedures of personal data processing.
Please contact the customer service ([email protected]) to exercise these rights. You will receive a reply within one month. Some personal data may be retained as backup copies after its erasure for a reasonable amount of time.
Settling disputes
Disputes regarding the processing of personal data are settled via the customer service ([email protected]). The supervising authority is the Estonian Data Protection Inspectorate ([email protected]).