Skip to content
Sunlonix Logo

Privacy Policy

Information about the handling of your personal data in accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR)

1. Data Controller

Responsible for data processing on this website is:

Sunlonix OÜ

Tallinn, Estonia

(Full business address will be added after registration in the commercial register)

Management: Gönül Güneş

Contact:

Phone: +49 2773 947 94 97

Email: [email protected]

Website: www.sunlonix.com

2. Data Protection Officer

The appointment of a Data Protection Officer is not legally required for Sunlonix OÜ (Art. 37 GDPR). For data protection inquiries, please contact: [email protected]

3. General Information on Data Processing

We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the General Data Protection Regulation (GDPR) and this privacy policy.

We collect and use personal data of our users only to the extent necessary to provide a functional website and our content and services.

4. Legal Bases for Data Processing

Where we obtain consent for the processing of personal data, Art. 6(1)(a) GDPR serves as the legal basis.

For the processing of personal data necessary for the performance of a contract, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to pre-contractual measures.

Where processing is necessary for compliance with a legal obligation, Art. 6(1)(c) GDPR serves as the legal basis.

Where processing is necessary for the purposes of legitimate interests pursued by our company and your interests, fundamental rights and freedoms do not override those interests, Art. 6(1)(f) GDPR serves as the legal basis.

5. Security Measures

We implement appropriate technical and organizational measures in accordance with legal requirements to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to data. Furthermore, we consider the protection of personal data already in the development and selection of software and processes.

6. Hosting and Server Log Files

This website is hosted on our own EU infrastructure (self-hosted). The servers are located in the European Union.

With each access to our website, the following data is automatically collected by the system:

  • Browser type and version
  • Operating system
  • Referrer URL (previously visited page)
  • IP address (anonymized)
  • Date and time of access
  • Page accessed

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical operation).

Retention period: Log files are automatically deleted after 30 days. These data are not merged with other data sources.

7. Contact Form

When you send us inquiries via the contact form, your information from the form is stored for processing the inquiry.

The following data is collected:

  • Name
  • Email address
  • Company (optional)
  • Subject and message

Additionally, the following is stored at the time of submission:

  • IP address of the user
  • Date and time of submission

Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (pre-contractual measures).

Retention period: Your data will be deleted after processing is complete, unless legal retention obligations apply (maximum 3 years).

No data is shared with third parties. The data is used exclusively for processing the conversation.

8. Email Contact

Alternatively, you can contact us via the provided email address. In this case, the personal data transmitted with the email will be stored.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). If the contact aims at concluding a contract, Art. 6(1)(b) GDPR serves as an additional legal basis.

9. Cookies

Our website does not use tracking cookies. Only technically necessary cookies are used that are required for the operation of the website.

Since we do not use cookie-based tracking, a cookie banner is not required.

10. Website Analytics

We use Umami Analytics — a privacy-friendly, self-hosted web analytics solution. Umami does not set cookies, does not store personal data, and is fully GDPR-compliant.

Data is processed exclusively on our own infrastructure in the European Union. No data is transmitted to third parties.

11. SSL/TLS Encryption

This website uses SSL/TLS encryption (HTTPS) for security purposes. This means that data you transmit to us is protected from third-party access. You can recognize an encrypted connection by the lock symbol in the browser bar.

12. Disclosure of Data to Third Parties

Your personal data will not be disclosed to third parties unless:

  • this is necessary for contract fulfillment,
  • you have explicitly consented, or
  • there is a legal obligation.

13. Transfer to Third Countries

No transfer of personal data to countries outside the European Union (third countries) takes place. All data processing is carried out on EU-based infrastructure.

14. Data Deletion and Retention Period

Personal data will be deleted or blocked as soon as the purpose of storage ceases to apply. Storage may continue if this has been provided for by European or national legislation. Data will also be deleted when a prescribed retention period expires, unless there is a need for further storage for the conclusion or performance of a contract.

15. Your Rights as a Data Subject

You have the following rights regarding your personal data:

a) Right of Access (Art. 15 GDPR)

You may request information about your personal data processed by us.

b) Right to Rectification (Art. 16 GDPR)

You have the right to rectification of inaccurate data or completion of incomplete data.

c) Right to Erasure (Art. 17 GDPR)

You may request the deletion of your personal data, provided one of the grounds stated in Art. 17 GDPR applies.

d) Right to Restriction of Processing (Art. 18 GDPR)

Under certain conditions, you may request the restriction of processing of your data.

e) Right to Data Portability (Art. 20 GDPR)

You have the right to receive your data in a structured, commonly used and machine-readable format.

f) Right to Object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your data based on Art. 6(1)(f) GDPR. The controller shall then no longer process the data unless it can demonstrate compelling legitimate grounds.

g) Right to Withdraw Consent (Art. 7(3) GDPR)

You have the right to withdraw your consent to data processing at any time. The withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal.

16. Automated Decision-Making

No automated decision-making including profiling pursuant to Art. 22 GDPR takes place.

17. Competent Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR.

The competent supervisory authority for Sunlonix OÜ is:

Andmekaitse Inspektsioon (AKI)

Estonian Data Protection Inspectorate

Tatari 39, 10134 Tallinn, Estonia

Phone: +372 6828 712

Email: [email protected]

Website: https://www.aki.ee

18. Changes to this Privacy Policy

We reserve the right to update this privacy policy as needed to adapt it to current legal requirements or to implement changes to our services. The current version applies to your renewed visit.

Last updated: March 2026