This policy describes how we collect, use, store, and protect your personal data when you use the beclicked.agency website and our client area.
It reflects our approach to data sovereignty: knowing where your data lives and who can access it. We also name our trade-offs here, rather than pretending we have none.
Be Clicked Agency OÜ
Mannimäe, Pudisoo village, Kuusalu municipality, Harju county, 74626 Estonia
Registration number: 14574911
VAT number: EE102116834
Email : info@beclicked.agency
This policy covers the beclicked.agency website as well as the client area accessible at clients.beclicked.agency, both operated by Be Clicked Agency OÜ.
It does not cover our clients' websites, even when we maintain them. See section 12 for details.
Name, first name, email address, phone number if provided, content of your message.
Name, first name, email address, reserved slot, information you provide about your request.
Email address, first name if provided, registration date, open and click statistics for our emails.
Professional contact details, billing address, order content, subscription and billing history, account identifiers. Credit card data never passes through our servers and is processed directly by the payment provider.
History of exchanges, contractual documents, support requests.
IP address, browser type, pages visited, date and time of visit. This data is used for traffic statistics and website security.
Traffic measurement is provided by Independent Analytics Pro, a solution installed directly on our servers. It does not place any cookies, create any individual profiles, or transmit any data to third-party services or ad networks.
| Purpose | Legal basis |
|---|---|
| Respond to your requests and follow up with you | Pre-contractual measures or legitimate interest |
| Manage an appointment | Contract execution |
| Perform a service, billing, or subscription | Contract execution |
| Send you our newsletter | Consent |
| Measure website audience | Legitimate interest, measurement without cookies or individual identification |
| Ensure the security of the site and prevent fraud | Legitimate interest |
| Comply with our accounting and legal obligations | Legal obligation |
You may withdraw your consent at any time when processing relies on it. Withdrawal does not affect the validity of what was done before.
| Data | Duration |
|---|---|
| Messages received via form | 3 years from the last contact |
| Appointment data | 3 years from the appointment |
| Newsletter subscription | Until unsubscription, then a maximum of 3 years as proof of consent |
| Customer account space | Duration of the contractual relationship, then 1 year |
| Order and billing data | Applicable legal accounting retention period |
| Technical and safety journals | Maximum 12 months |
| Website traffic statistics | Aggregated data, without individual identifier retention |
Your data is neither sold, rented, nor transferred to third parties for commercial purposes.
They are accessible to service providers strictly necessary for the operation of our services:
| Processor | Role | Location |
|---|---|---|
| Infomaniak Network SA | Website hosting, messaging, calendar, storage, videoconferencing | Switzerland |
| Sweego | Sending transactional emails | European Union |
| BunnyWay d.o.o. (BunnyNet) | Video and static file distribution | European Union, Slovenia |
| Cloudflare | Anti-robot form protection (Turnstile) | United States |
| SureCart | Management of orders and subscriptions in the client area | United States |
| Payment provider | Payment processing | View your own policy |
Each of these service providers is bound by a subcontracting agreement and uses your data only for the entrusted service.
Our services are hosted in Switzerland, a country recognized by the European Commission as offering an adequate level of protection for personal data.
Two service providers are based in the United States, and we prefer to state this rather than keep it hidden:
These transfers are based on the European Commission's standard contractual clauses and a subcontracting agreement compliant with the GDPR. We are working to replace them with European solutions when reliable equivalents exist.
Outside of these cases, no data is transferred outside the European Union or Switzerland.
Our servers and websites are protected by an encrypted HTTPS connection, an application firewall, monitoring of access attempts, and daily encrypted backups. Administrator and server access is restricted, named, protected by two-factor authentication, and key-based authentication.
No system offers absolute security. In the event of a data breach that could create a high risk to your rights, you will be notified in accordance with applicable regulations.
Your data is not subject to any fully automated decision-making or profiling that produces legal effects concerning you.
You have the following rights regarding your data:
: write to info@beclicked.agencyWe respond within one month. Proof of identity may be requested in case of reasonable doubt.
If you believe your rights are not respected, you can file a complaint with the Estonian Data Protection Authority, the Andmekaitse Inspektsioon, or with the competent data protection authority in your country of residence.
As part of our services, we work on our clients' websites and tools. We act as a subcontractor, under the client's instructions, who remains responsible for the processing of their own data. These interventions are governed by a subcontracting agreement.
If you are a visitor or customer of a website we maintain, your rights are exercised with the website's publisher, whose contact details appear in its legal notices.
The use of cookies and trackers on this site is described in the Cookie policy, which specifies their purpose, duration, and how to change your choices at any time.
This policy may be updated to reflect changes in our services, tools used, or regulations. The date below indicates the last effective version.
Last updated: 28/08/2026