Privacy Policy
What is personal data?
Personal data is data that allows identifying you. Personal data does not include anonymous or aggregated data, such as aggregate statistics of users, i.e. data that cannot be unambiguously linked to you. Personal data includes, for example, your first and last name, personal code, gender, language, place of residence, date of birth, phone number, contact details on social media, e-mail address, network identifiers, such as your MAC address and IP address, and cookies.
Data controller
The data controller of the personal data on Liikluslab mobile app, the site liikluslab.ee and all its subdomains, including e.liikluslab.ee (hereinafter: Services) is Liikluslab group of companies, consisting of Liikluslab Baltic OÜ (registry code 14812701) and Liikluslab Tervis OÜ (registry code 12190856), located at Rotermanni 18/1-301, Tallinn, e-mail info@liikluslab.ee.
Using Services
When you use our Services, we automatically collect and store technical information sent by your browser, including the following: your IP address, the website you used to reach the current site, the versions of your browser and operating system, HTTP query parameters, the user’s session identifier, the unique identifier of the device, and the CSRF token. Some of this data is collected using cookies. When visiting the liikluslab.ee site or Liikluslab mobile app for the first time you see a warning that cookies are used. If you continue to use the liikluslab.ee site or Liikluslab mobile app, you agree with the usage of the required cookies. Learn more about cookie files in Cookie policy.
We process your personal data, which is part of this technical data, to ensure the stable and safe use of the Services, protect personal data from loss, damage, theft, or unauthorised access, and, if necessary, to identify a device which has been used to carry out illegal or malicious operations when using the Services. The legal basis for processing is your consent and the legitimate interest of Liikluslab group of companies.
In addition, we process this data to identify breaches of the terms and conditions of use of the online environment of Liikluslab (hereinafter: terms of use) and, if necessary, to identify the user responsible for the breach and/or the device used to carry out such operations. The legal basis for processing is the legitimate interest of Liikluslab group of companies.
We retain and process the collected technical information until the achievement of the objectives stated above – generally, for three years. After that, the data is deleted automatically.
Registration and login
When registering and logging in depending on the login method we may request the Facebook identifier, name, surname and e-mail address of the Facebook user.
Mobile app doesn't support logging in via Facebook.
We process this personal data to personalise the Services, ensure the efficient operation of support services, ask for your feedback, remind you of important events (e.g. the expiry of the term of your plan), and send you payment documents. The legal basis for processing is compliance with the terms of use and the legitimate interest of Liikluslab group of companies. To achieve these goals, we retain and process the personal data listed above until your account is closed. You can send a request for closing your account to the e-mail address info@liikluslab.ee.
We also process this personal data to ensure compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. For this purpose, your Facebook user ID and name will be added as a watermark to all images of the learning materials. The legal basis for processing is the legitimate interest of Liikluslab group of companies to control the compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. Considering the legitimate purpose of data processing, the fact that the terms of use are available to you and are reasonable, and the fact that only your identifier and full name are processed, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests. For this purpose, we retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account.
If you have granted your consent, your e-mail address will be processed for sending messages for direct marketing purposes. Your consent is the legal basis for the processing. You have the right to revoke your consent at any time. You can do so under your user profile (the button ‘I want to keep up to date with Liikluslab news’), by clicking the respective link in the footer of the e-mail or by contacting our customer service (info@liikluslab.ee).
Devices
We control from which devices you use the online environment as you may use it only from 3 different devices. The legal basis for processing is the legitimate interest of Liikluslab group of companies to ensure compliance with the terms of use. If you use more than three devices, then Liikluslab may require two-factor authentication when logging in. Considering the legitimate purpose of data processing, the fact that the number of devices limitation is described in the terms of use, which are available to you and are reasonable, and the fact that only data required to identify the device is processed, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests. For this purpose, we retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account.
Published data
We monitor public websites, social networks and other sources to identify breaches of the terms of use (e.g. publishing screenshots from study materials, providing access to the account to third parties or a corresponding offer, etc.) The legal basis for processing is the legitimate interest of Liikluslab group of companies to ensure compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. Considering the legitimate purpose of data processing, the fact that Liikluslab group of companies very often has problems with breaching the listed terms of use, the fact that the terms of use are available to you and are reasonable, and the fact that those sources are public, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests. For this purpose, we retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account.
Choosing a driving school
When registering you are asked to select your driving school. This is an option, not an obligation. When the driving school is selected, your theory teacher is able to see your full name, e-mail address, if registering with Facebook - name in Facebook, online environment usage statistics. We offer the option to upload a profile picture, if desired, so that the driving school can provide a better user experience and customer service during client engagement. Uploading a profile picture is optional, not mandatory, and can be deleted by the user at any time. We process this personal data to simplify and personalise the learning process and to allow giving driving theory tests online. The legal basis for processing is the legitimate interest of Liikluslab group of companies. To reach these goals, we retain and process personal data while your driving school is selected. You can cancel your choice of a driving school at any time by selecting "I will choose later / the school is not in the list" under the "School" inscription in the "My profile" section of the online environment.
Registration for driving school courses
On the liikluslab.ee website you can choose a driving school and register for training courses. This is an option, but not an obligation. When registering for a training course, you will need to fill in the information requested on the registration form, including your personal and contact details, which are required to register you for the course and to send you invoices. After registration, your data will be sent to the driving school via the Liikluslab admin panel; your name, contact details and training preferences will be sent to the driving school by email. This data will be processed by a person appointed by the driving school for the purpose of registering you for training, including billing you for training and clarifying your training preferences.
We keep and process your data for as long as it is necessary to register you for training and enable you to take advantage of the bonuses provided by Liikluslab, generally 1 year, after which the data is automatically deleted.
Paying for our services
Mobile app doesn't support paying for our services.
The payment system requests and processes the personal data required for making the payment. The payment system services are provided by Maksekeskus AS (registry code: 12268475, address: Niine 11, Tallinn 10414, Estonia) and Montonio Finance OÜ (registry code: 14557628, address: Kai 1, Tallinn 10111, Eesti). We do not retain or process the client data, with the exception of the name of the payer, which is forwarded to us by Maksekeskus AS and Montonio Finance OÜ.
In order to, if necessary, identify the persons responsible for breaches, the name of the payer will be added as a watermark to all images of the learning materials. We retain and process personal data until the achievement of the goals listed above, generally for up to three years after the closure of your account. The legal basis for processing is the legitimate interest of Liikluslab group of companies to ensure compliance with the terms of use and, if necessary, to identify the persons responsible for breaches. Considering the legitimate purpose of data processing, the fact that your card obviously will not be used to pay for the services used by a stranger, the fact that the terms of use are available to you and are reasonable, and the fact that only your name is used, your interests, fundamental rights and freedoms for which personal data should be protected, in our opinion, do not outweigh our interests.
We retain and process your name, e-mail address, and the payer name in accordance with the provisions of the Accounting Act and the relevant taxation legislation. We retain this data for seven years as an accounting source document. The legal basis for processing is compliance with legal obligations.
Health Check Service
The group of Liikluslab companies offers the opportunity to undergo a health check for motor vehicle drivers at its partner clinics. The service's Terms of Use are available here.
When you register for a health check, we will ask for your name, personal identification number, e-mail address, telephone number, communication language and the group of health certificate you are applying for. We process this personal data to enable you to complete the health check and to provide you with information about the service. The legal basis for the processing is the legitimate interest of the Liikluslabi group of companies to ensure compliance with the terms and conditions of the service referred to above and to enable health checks to be carried out by partner clinics. In view of the legitimate purpose of the processing, the fact that the conditions of the service referred to above are available to you and reasonable, we consider that your interests or the fundamental rights and freedoms for the protection of personal data do not outweigh our interest. To this end, we will retain and process the personal data until the purposes set out above have been fulfilled, normally for a period of six months after the health check.
The health check is carried out by the Liikluslab Tervis OÜ clinic (license no. L07248) or a Liikluslab partner clinic. Liikluslab does not have access to your health data — such data is only accessible to healthcare professionals who perform the health check and enter the information into the National Health Portal. We do not collect or process this data.
If the health check is performed by the Liikluslab Tervis OÜ clinic, you will first be seen by a nurse who will conduct an interview and perform the necessary procedures, entering the information into the Health Portal. The doctor will then review the data along with your electronic health declaration and decide whether to issue a medical certificate for driving. During the health check, you will be asked to provide written consent for the decision to be sent to the email address you provided when booking the appointment. If you give consent, you will receive an email indicating whether the health certificate was issued. If you do not give consent, you can view the decision in the Health Portal. In case the certificate is not issued, the reason for the refusal will also be visible in the portal. We will store your written consent — including your name, email address, and signature (the signature is stored in encrypted form) — for three years. If no consent is given, no data listed above will be stored. The legal basis for data processing is Liikluslab Tervis OÜ’s legitimate interest in being able to prove your consent for sending the decision by email in the event of a potential dispute.
If the health check is carried out by a Liikluslab partner clinic, you will be seen by a doctor who will make the decision on issuing the driver's health certificate during the appointment and will inform you of the decision verbally.
At your request and with your consent, we will forward the group and the date of issue of the health certificate (hereinafter: health certificate information) to the driving school, which is a partner of Liikluslab, so that the driving school can meet requirements of MKM Regulation No. 60 § 29 and you can start learning more quickly. In order to transmit the information, the health certificate information should be entered in the Liikluslab information system and Liikluslab forwards the information to the driving school of your choice. Your consent to share your health certificate information with Liikluslab and with the driving school of your choice will be asked twice - when you register for the health check on the website liikluslab.ee and during the health check. When you give your consent, we ask you to choose the driving school (or schools) to which you want to transmit the information. If at the time of registration to the health check you do not know which driving school you will go to, you can give your consent for the health certificate information to be transmitted to Liikluslab, and you can choose the driving school to which the information will be transmitted during the health check. You can withdraw your consent to the transmission of health certificate information at the time of the health check or by clicking on the corresponding link in the confirmation e-mail you receive. The legal basis for the processing of the data is your consent. We will retain and process your name, email address, the list of chosen driving schools and corresponding consent until the above purposes are fulfilled, normally for a period of six months. If you give your consent in a writen form at your visit to Liikluslab Tervis OÜ clinic, we will also store your signature (in an encrypted form). If you do not give corresponding consent, the data listed above will not be retained.
If you are referred for a re-check during the health check, the Liikluslab group of companies will be able to offer you a discount on a re-check. In order to receive the discounted rate, it should be noted in the Liikluslab information system that you have been assigned a re-check (the reason for the re-check and the health-related information are not noted). This is an option, not an obligation. If you do not wish to receive a discount, or do not wish to provide information about the re-check, you do not have to give your consent. You can withdraw your consent by clicking on the link in the e-mail we will send you after the health check. The legal basis for the processing of the data is your consent. We will retain and process your name, personal identification code, the status "referred for a follow-up visit," and your corresponding consent until the purposes set out above have been fulfilled, normally for a period of six months. If you give your consent in a written form at your visit to Liikluslab Tervis OÜ clinic, we will also store your signature (in an encrypted form). If you do not give corresponding consent, the data listed above will not be retained.
Recipients of personal data
Personal data is forwarded to the employees of Liikluslab group of companies who need to process it due to their working duties.
Personal data is forwarded to data processors authorized by Liikluslab group of companies (e.g. data storage service provider, accountant or IT service provider) on the basis of contracts concluded between Liikluslab group of companies and the data processors. The data processors are obligated to ensure relevant protective measures in the processing of personal data.
Personal data is stored in the servers of DigitalOcean LLC, which are located in the territories of EU Member States or members of the EEA.
Data may also be forwarded to third parties if this is required by the current legislation (for example, data protection organizations) or if it is necessary in the legitimate interests of Liikluslab group of companies to protect its rights (legal consultant, collection).
Security and access to data
Liikluslab group of companies implements physical, organisational, and information technological security measures to protect personal data from accidental or illegal destruction, loss, alteration, or unauthorised disclosure or access.
Your rights in the processing of personal data
You have the following rights:
- to receive information about the processing of personal data;
- to access your personal data that Liikluslab group of companies processes;
- to request the rectification of your personal data if the personal data processed by Liikluslab group of companies is incorrect;
- to request the erasure of your personal data if, in your opinion, there is no legal basis for the processing or if the erasure is required in accordance with valid legislation;
- to object to the processing of personal data on the basis of legitimate interest. If the objection is declared valid, your personal data will be erased and will no longer be processed;
- to request the transmission of the personal data which you have submitted to us and the legal basis for the processing of which is your consent or compliance with the terms of use;
- to revoke your consent to procedures of personal data processing.
Please contact the customer service (info@liikluslab.ee) to exercise these rights. You will receive a reply within one month. Some personal data may be retained as backup copies after its erasure for a reasonable amount of time.
Settling disputes
Disputes regarding the processing of personal data are settled via the customer service (info@liikluslab.ee). The supervising authority is the Estonian Data Protection Inspectorate (info@aki.ee).