1. Who is responsible
Ofelia Hartmann is the named contact for the Ceprefi website and enquiries: F. R. Kreutzwaldi 4, Tallinn, Estonia; +372 5330 0080.
This policy explains the website’s local brief tool, privacy preferences and information shared when you contact Ofelia.
2. Information you provide
The brief form asks for your name, optional team or project name, topic and notes. It creates a text file locally on your device. The website does not send these entries to Ceprefi or place them in browser storage. Anyone with access to your downloaded file may be able to read it, so store or delete it with care.
If you call or write by post, the information you choose to provide can be used to reply and discuss your request. Keep passwords, private keys and sensitive personal information out of an initial conversation.
3. Website requests and cookies
Your browser sends information such as your IP address, requested page and browser details to the hosting provider when it fetches this site. The provider may record access and security logs. Technical records can be used to deliver pages, diagnose faults and protect the website. The information recorded depends on the hosting configuration.
The site stores your cookie choices in ce_consent for 180 days. Measurement and marketing tags are absent in this version. Browser hints for font and CDN hosts may establish connections, but the site does not fetch remote fonts or libraries. See the cookie policy for the exact cookie record.
4. Why information is used
Enquiry information is used to read your request, reply and discuss a possible engagement. Where you ask for steps towards an agreement, the basis is taking those steps at your request. General business correspondence and basic site security may rely on legitimate interests, subject to an assessment of your rights and reasonable expectations. A legal duty may require retention of records.
Optional measurement or marketing would require a separate, informed choice before activation. Sending an enquiry does not subscribe you to marketing.
5. Who can receive information
Ofelia and service providers needed for hosting, communications and agreed work may process relevant information. Professional advisers or authorities may receive information when necessary for a legal duty or claim. Providers should receive only what they need and be covered by suitable terms.
This version has no embedded maps, social feeds or enquiry-processing service. Any processing outside the European Economic Area must have an applicable legal basis and safeguards where required, such as an adequacy decision or approved contractual clauses. Ask Ofelia for information about providers used for a particular engagement.
6. How long information is kept
Information from an enquiry is retained only for as long as needed to respond, manage related work or meet an applicable legal obligation. Relevant factors include whether a discussion remains active, whether it leads to an agreement and whether a record is needed for a legal claim. You can ask Ofelia about the retention period that applies to your correspondence. Files prepared by the local brief tool remain under your control.
The consent cookie expires after 180 days. You can replace your choices at any time or remove the cookie through your browser.
7. Your choices and rights
Depending on the circumstances, you may request access, correction, erasure, restriction or a portable copy of your personal information. You may object to processing based on legitimate interests. Where processing uses consent, you may withdraw it without affecting earlier lawful processing.
Contact Ofelia using the details above. We may need proportionate information to confirm your identity. The usual response period under the GDPR is one month, with extensions where the law permits. You can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or another competent supervisory authority.
8. Security, audience and updates
The site uses no accounts and makes no automated decisions about you. Its content is intended for people learning about or working on digital companies. It is not directed at children.
Access to personal information should be limited to the people who need it for the stated purpose. No communication system is risk-free. This policy should be updated before tools, providers or purposes change. The revision date at the top identifies this version.