Vastutav töötleja ja kontakt
Vastutav töötleja on dha.ee teenuse operaator. Isikuandmete ja õigustega seotud taotlused saab saata aadressile [email protected]. Registreeritud ärinimi ja postiaadress lisatakse pärast ärioperaatori ametlikku määramist.
Data categories
The service may process account and contact data, encrypted security settings, session and device information, 2FAS verification results, payment and gift records, support requests, and security audit data.
Purposes and legal bases
Account and gift services are processed to perform the service contract. Security, fraud prevention, and incident investigation rely on the controller’s legitimate interests and applicable legal obligations. Consent is requested where it is the appropriate basis.
Service areas
Device and session signals protect access. 2FAS and PIN results protect restricted actions. Payment providers process payment details when a payment is made. Messages and support requests are processed to deliver and answer them.
Retention and deletion
Data is kept only for the period required for its purpose, contract, accounting, dispute, and security obligations. Expired sessions and challenges are deleted automatically. Security signals described below are deleted no later than 24 months after the event, unless a shorter period applies.
Turvalisuse tagamiseks ja volitamata juurdepääsu uurimiseks võib sait töödelda IPv6 EUI-64 tunnuseid ja nende kaitstud HMAC-pseudonüüme. Säilitusaeg on kuni 24 kuud sündmusest, seejärel andmed kustutatakse.
Processors and recipients
Categories of processors may include hosting and network protection, email and SMS delivery, payment providers, and technical support. Data is disclosed to authorities only when a valid legal duty applies.
Transfers outside the EEA
A processor may handle data outside the EEA only where a lawful transfer mechanism and appropriate safeguards apply. Current processor information can be requested from the contact above.
Cookies
Strictly necessary cookies maintain the session, CSRF protection, and security state. Non-essential cookies are not activated without the consent required by law.
Teie õigused
Sõltuvalt õiguslikust alusest ja asjaoludest võib taotleda andmetega tutvumist, parandamist, kustutamist, töötlemise piiramist või andmete ülekandmist või esitada vastuväite. Nõusoleku võib tagasi võtta, ilma et see mõjutaks tagasivõtmisele eelnenud töötlemise seaduslikkust. Praegu esitatakse tagasivõtmise taotlus aadressil [email protected]; tegemist on andmesubjekti õiguste taotluse, mitte täieliku tehnilise nõusoleku tagasivõtmise mehhanismiga.
Taotlused
Saatke taotlus aadressile [email protected].
Profiling and automated decisions
The service does not make decisions producing legal or similarly significant effects solely by automated processing. Automated security rules may temporarily delay or block suspicious attempts; the underlying event can be reviewed by authorised staff.