Privacy Policy
Version of 11.10.2026
This Policy explains how we process personal data on the bezkordoniv.com website and on the Bez Kordoniv platform (the “Platform”) in accordance with Article 13 of the General Data Protection Regulation (EU) 2016/679 (GDPR).
1. Who is responsible for your data
The controller is BezKordoniv OÜ, Tartu mnt 52/1, 10115 Tallinn, Estonia; registry code 17461320; e-mail info@bezkordoniv.com. No data protection officer (DPO) has been appointed; please send any data protection questions to this address.
2. This website
- The website sets no cookies, uses no analytics or trackers and has no forms.
- The website is hosted and protected by Cloudflare. When you visit, technical data (IP address, time of request, browser type, requested page) is processed to deliver the site and protect it from attacks. Legal basis: our legitimate interest in operating the site securely (Art. 6(1)(f) GDPR).
3. Writing to us
If you write to us, we process your e-mail address, name and the content of your message in order to reply. Legal basis: steps prior to or performance of a contract (Art. 6(1)(b)) or our legitimate interest in answering enquiries (Art. 6(1)(f)).
4. Data on the Platform
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account: name, e-mail, password (stored only as a hash), role | Creating the account, signing in, service e-mails | Art. 6(1)(b) |
| Expert profile: photo, description, speciality, experience, languages, country and city, services and prices, certificates | Public profile in the catalogue, moderation | Art. 6(1)(b) |
| Bookings: service, date and time, status, format, meeting link | Providing the consultation | Art. 6(1)(b) |
| Chat and attachments | Communication between client and expert | Art. 6(1)(b) |
| Reviews and ratings | Publishing reviews, expert rating | Art. 6(1)(b), 6(1)(f) |
| Payments: amount, currency, status, Stripe identifiers (no card details) | Payment, refunds, accounting | Art. 6(1)(b), 6(1)(c) |
| Experts’ tax data where required by law | Digital platform reporting (DAC7) | Art. 6(1)(c) |
| Technical logs: IP address, security events | Protection against abuse and attacks | Art. 6(1)(f) |
Health data. In medical or psychological consultations you may share health data. Please share only what the consultation requires. Such data is processed to provide the consultation on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you may withdraw.
An expert to whom you disclose information during a consultation processes it as an independent controller and is responsible for handling it lawfully.
5. Recipients and processors
- Cloudflare — website hosting, content delivery network, DNS, attack protection.
- Stripe — payments, refunds, onboarding and verification of experts. For some data (in particular identity verification and fraud prevention) Stripe acts as an independent controller: stripe.com/privacy.
- Microsoft Azure — cloud services, including sending service e-mails.
- Google Workspace — team e-mail and office services.
- Zoho — e-mail (the info@bezkordoniv.com mailbox).
- The other party to a booking — the expert sees the client data needed for the consultation; the client sees the expert’s public profile.
- Public authorities — only where required by law.
Data processing agreements (Art. 28 GDPR) are or will be concluded with processors. We do not sell personal data.
6. Transfers outside the EEA
Some of the providers named above may process data outside the European Economic Area, in particular in the USA. Such transfers rely on the European Commission’s adequacy decision (EU–US Data Privacy Framework) or on standard contractual clauses (Art. 46 GDPR).
7. Retention
- Account data — for as long as the account is active. When an account is deleted, personal data is anonymised, except data we are legally required to keep.
- Accounting records of payments — 7 years under the Estonian Accounting Act.
- Correspondence — as long as needed to reply and to defend against possible claims.
- Technical logs — for the limited time needed for security.
8. Your rights
You have the right to access, rectify and erase your data, to restrict processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent at any time (Art. 15–21 GDPR). Write to info@bezkordoniv.com. You may also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with the supervisory authority of your country of residence.
9. Cookies
- This website sets no cookies.
- The Platform uses only strictly necessary cookies: for signing in (session) and for protecting forms against request forgery. They do not require consent.
- On the payment page and when connecting payouts, Stripe may set its own cookies for security and fraud prevention.
- There are no analytics, advertising or tracking cookies. If this changes, we will ask for your consent first.
10. Mandatory data and automated decisions
Account and booking data are required to use the Platform: without them we cannot provide the service. We do not make automated decisions, including profiling, that have legal or similarly significant effects on you; expert applications are moderated by people.
11. Changes
We update this Policy when our processing changes. The current version is always on this page, with its date at the top.