Testmera / Privacy
Privacy, in plain terms.
A minimal website. Email contact. Clear purposes for the data needed to operate them.
Who is responsible
The controller is Testmera (company registration in progress), based in Tallinn, Estonia. Company details are coming soon. Contact hello@testmera.com for privacy questions or rights requests.
This notice covers this website and email enquiries. Assessment engagements require separately agreed confidentiality and data-processing terms.
Data we handle
- Website requests: IP address, requested URL, request time, browser or device information and technical security records processed by the hosting and DNS provider.
- Email enquiries: your email address, any name or organisation you provide, message content, attachments and correspondence metadata.
The site includes no analytics, advertising trackers, forms or accounts. Fonts and assets are served with the site. We do not set tracking cookies or use browser storage for tracking. Provider-level security processing may still occur.
You choose whether to contact us. Without a reply address and enough context, we may be unable to answer. Please do not include secrets, personal datasets or sensitive findings in an initial email.
Purposes and legal bases
- Deliver and protect the site
- Legitimate interests in operating a reliable website and preventing abuse (GDPR Article 6(1)(f)). Technical data is used for service delivery and security, not audience profiling.
- Answer enquiries and coordinate disclosure
- Legitimate interests in responding to communications and handling security reports (Article 6(1)(f)).
- Prepare an engagement you request
- Steps taken at your request before entering a contract (Article 6(1)(b)), where applicable. For business representatives, our legitimate interest in managing business correspondence applies.
- Meet applicable legal duties
- Compliance with a legal obligation (Article 6(1)(c)), when a specific duty applies.
We do not sell personal data, use it for advertising, or make automated decisions with legal or similarly significant effects.
Providers and international processing
We use Cloudflare for website hosting and DNS, and Proton for email. They process relevant technical data or correspondence to provide those services. Access is limited to people and providers who need it for the stated purposes; disclosures may also be necessary to comply with law.
Cloudflare operates internationally; Proton is based in Switzerland and describes mail storage in Switzerland, Germany or Norway. Processing locations and transfer safeguards depend on the provider arrangements. EU-sovereign assessment requirements are agreed separately.
Where processing involves transfers outside the EEA, the applicable arrangement must use an adequacy decision or appropriate safeguards, such as standard contractual clauses, as required. The owner must confirm the actual contracts, subprocessors and transfer arrangements before publishing this notice.
Provider references: Cloudflare data processing terms, Proton data processing terms and Proton Mail privacy notice.
Retention
Enquiry correspondence is kept while needed to answer, manage follow-up or prepare an engagement. Closed enquiries should be reviewed for deletion when that purpose ends. Security correspondence may be retained through investigation, remediation and coordinated disclosure. Records needed for legal obligations or claims are kept only for the applicable requirement.
Technical records and backup copies follow provider settings and deletion cycles. Exact settings and any fixed retention periods must be confirmed by the owner before publication. You may ask us about the retention criteria or request deletion.
Your rights
Subject to the conditions in data-protection law, you may request access, correction, erasure, restriction or portability of your data. You may object to processing based on legitimate interests. If we rely on consent for any future processing, you may withdraw it without affecting earlier lawful processing.
Email hello@testmera.com. We may ask for proportionate information to confirm identity. We normally respond within one month; if a lawful extension is needed, we explain it.
You may complain to the Estonian Data Protection Inspectorate or your local supervisory authority.
Rights reference: European Commission information for individuals.
Updates
This draft reflects a static site with email contact only. We will revise the notice when the registered controller, services or data practices change.