Legal
Privacy notice
Last updated: [CONFIRM — insert launch date]
This notice explains how UMCI OÜ collects and uses personal data through this website and in the course of its advisory work. It is written to meet the requirements of the EU General Data Protection Regulation (2016/679) and, where UMCI processes the data of individuals in the United Kingdom, the UK GDPR and Data Protection Act 2018.
1. Who we are
UMCI OÜ is the data controller for the personal data described in this notice.
UMCI OÜ
Ahtri tn 12, 10151 Tallinn, Estonia
Registry code: 14615395
Email: newbusiness@umci.one
privacy@umci.one alias. UMCI is unlikely to require a statutory Data Protection Officer on current scale, but this should be confirmed: the threshold turns on large-scale regular and systematic monitoring or large-scale processing of special category data, neither of which appears to apply.2. What personal data we collect
When you contact us. Name, email address, organisation, position, jurisdictions relevant to your enquiry, the subject and content of your message, and the date and time of submission.
When you request a document. Name, organisation, email address, and a record of which document was requested and when.
When you visit the website. IP address, browser type and version, device type, operating system, pages visited, time spent, referring source, and information collected through cookies. See our Cookie notice.
In the course of a mandate. Where you become a client or act for one, we may process contact and identification details, professional and financial background information relevant to the mandate, correspondence, and information required for client due diligence and anti-money-laundering purposes.
We do not knowingly collect special category data (data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation) through this website, and ask that you do not include it in enquiry messages.
3. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry | Legitimate interests — responding to a request you have made; or steps prior to entering a contract |
| Sending a requested document | Legitimate interests — fulfilling a request you have made |
| Providing advisory services under a mandate | Performance of a contract |
| Client due diligence, identity verification and anti-money-laundering checks | Legal obligation |
| Maintaining business records, accounts and correspondence files | Legal obligation; legitimate interests |
| Website security, integrity and fraud prevention | Legitimate interests — protecting our systems |
| Website analytics | Consent |
| Establishing, exercising or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interest in operating and protecting a professional advisory business does not override your rights and freedoms. You may object to this processing — see section 8.
4. We do not send marketing
UMCI does not operate a mailing list and does not send marketing communications. Contacting us or requesting a document will not result in you receiving unsolicited material.
5. Who we share it with
We share personal data only where necessary:
- Service providers who host this website, deliver our email, and store our files, acting on our instructions as processors under written agreement. [CONFIRM — list actual providers: hosting platform, email provider, cloud storage, form handler, analytics provider]
- Professional advisers engaged on a mandate, where sharing is necessary to deliver the services and has been agreed with you.
- Regulators, law enforcement and courts, where we are required to disclose by law.
- Our own professional advisers, including lawyers, accountants and auditors, under duties of confidentiality.
We do not sell personal data, and we do not share it for the marketing purposes of any third party.
6. International transfers
UMCI is established in Estonia and processes data principally within the European Economic Area. Some service providers may process data outside the EEA, including in the United Kingdom and the United States.
Where data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one applies (including the United Kingdom), or otherwise on Standard Contractual Clauses together with supplementary measures where required.
7. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become mandates | 24 months from last contact, then deleted |
| Document request records | 24 months |
| Mandate files, correspondence and deliverables | 7 years from close of mandate [CONFIRM] |
| Client due diligence and AML records | 5 years from the end of the business relationship, or longer where required by law |
| Accounting records | 7 years, as required by Estonian accounting law |
| Website analytics | 14 months [CONFIRM against your analytics configuration] |
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you
- rectification of inaccurate or incomplete data
- erasure of your data in certain circumstances
- restriction of processing in certain circumstances
- data portability where processing is based on consent or contract and carried out by automated means
- object to processing based on legitimate interests
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal
To exercise any right, write to newbusiness@umci.one. We will respond within one month. We may need to verify your identity first, and we may extend the period by two further months for complex requests, telling you why.
Some rights are qualified. Where we are required by law to retain records — for example client due diligence records — we may be unable to erase them on request.
9. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
10. Security
We maintain technical and organisational measures appropriate to the sensitivity of the information we handle, including access controls, encryption in transit, and confidentiality obligations on all personnel and subconsultants. Given the nature of our work, confidentiality is a professional obligation as well as a legal one.
11. Complaints
If you are dissatisfied with how we have handled your data, please contact us first at newbusiness@umci.one so that we can try to resolve the matter.
You also have the right to lodge a complaint with a supervisory authority:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
www.aki.ee
If you are in the United Kingdom, you may complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — www.ico.org.uk
12. Changes
We will update this notice when our processing changes. The date at the top shows when it was last revised.
