Privacy Policy
Interchange Holdings OÜ · Registry code 14372515 · Tallinn, Estonia
Last updated: June 2026
Interchange Holdings OÜ (“Interchange Holdings”, “we”, “us” or “our”) is committed to protecting the personal data of everyone who interacts with us. This Privacy Policy explains what personal data we collect, why we collect it, how we use it and the rights you hold in relation to it.
We are registered in Estonia (registry code 14372515) and are subject to Regulation (EU) 2016/679 (the General Data Protection Regulation, or GDPR) and the Estonian Personal Data Protection Act. We act as data controller in respect of the personal data described in this policy.
1Who This Policy Applies To
This policy applies to:
- visitors to our website at interchange.ee;
- prospective and current business partners, clients and investors;
- representatives of government bodies and corporate clients who engage with us;
- job applicants and contractors; and
- any other individual whose personal data we process in the course of our business activities.
2What Personal Data We Collect
2.1 Data you provide to us
When you contact us, submit an enquiry or engage with us professionally, we may collect:
- your name, job title and the organisation you represent;
- your business email address and telephone number;
- the content of any correspondence or communications you send us; and
- any other information you choose to provide.
2.2 Data collected automatically
When you visit our website, we may collect:
- your IP address and approximate geographic location;
- browser type, device type and operating system;
- pages visited, time spent on pages and referring URLs; and
- cookie identifiers (where you have consented to their use).
2.3 Data from third parties
We may receive information about you from third parties such as publicly available business registries, professional networking platforms and referrals from existing partners, where this is relevant to a legitimate business relationship.
3How We Use Your Personal Data
We process personal data on the following legal bases and for the following purposes:
- Legitimate interests (Article 6(1)(f) GDPR): to respond to enquiries, manage business relationships, conduct due diligence on prospective partners, and improve our website and services.
- Contractual necessity (Article 6(1)(b) GDPR): to fulfil our obligations under agreements with clients, partners and service providers.
- Legal obligation (Article 6(1)(c) GDPR): to comply with applicable laws, including anti-money laundering, financial regulation and tax requirements.
- Consent (Article 6(1)(a) GDPR): where we have asked for and received your consent, for example in relation to non-essential cookies or marketing communications. You may withdraw consent at any time.
4Cookies
Our website uses cookies to ensure it functions correctly and to help us understand how visitors use it. We distinguish between essential cookies (which are necessary for the site to operate) and non-essential cookies (such as analytics cookies), which we deploy only with your consent.
You may manage your cookie preferences at any time via the cookie settings banner on our website. Detailed information about the cookies we use, their purpose and their duration is set out in our separate Cookie Policy.
5How Long We Keep Your Data
We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. In practice:
- Contact and enquiry data is generally retained for up to three years from the date of last interaction, unless a continuing business relationship requires longer retention.
- Data held in connection with a contractual relationship is retained for the duration of that contract and for a further period of up to seven years in accordance with our legal obligations.
- Website analytics data is typically retained in anonymised or aggregated form for no longer than 26 months.
6Who We Share Your Data With
We do not sell or rent your personal data to third parties. We may share data in the following circumstances:
- Service providers: we engage trusted third-party providers (such as IT and cloud services, analytics providers and legal advisers) who process data on our behalf under appropriate data processing agreements.
- Group companies: where relevant, data may be shared with companies within the Interchange Holdings group for legitimate business purposes.
- Regulatory authorities and law enforcement: where required by law or to protect our legal rights.
- Business transactions: in the context of a merger, acquisition or sale of assets, subject to appropriate confidentiality obligations.
7International Transfers
As an Estonian-registered company operating within the European Economic Area, we process most personal data within the EEA. Where we transfer data outside the EEA, we do so only in accordance with Chapter V of the GDPR, relying on adequacy decisions, Standard Contractual Clauses or other approved mechanisms.
8Your Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Right of access: you may request a copy of the personal data we hold about you.
- Right to rectification: you may ask us to correct inaccurate or incomplete data.
- Right to erasure: in certain circumstances, you may ask us to delete your data.
- Right to restriction: you may ask us to restrict processing in certain circumstances.
- Right to data portability: where processing is based on consent or contract, you may request your data in a structured, machine-readable format.
- Right to object: you may object to processing based on our legitimate interests.
- Rights in relation to automated decision-making: we do not carry out automated decision-making that produces legal or similarly significant effects.
To exercise any of these rights, please contact us at the address below. We will respond within one month. If you are unsatisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with the supervisory authority in your country of residence.
9Security
We take reasonable technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include access controls, encryption in transit and regular security reviews. However, no data transmission over the internet is entirely secure, and we cannot guarantee absolute security.
10Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the date at the top of this document and, where appropriate, by providing more prominent notice. We encourage you to review this policy periodically.
11Contact Us
If you have any questions about this policy or the way we handle your personal data, please contact:
Interchange Holdings OÜ
Registry code 14372515
Tallinn, Estonia
E-mail: [email protected]