Privacy Policy
Last updated: 5 March 2026 · Controller: IBG Consulting OÜ, Pärnu, Estonia
Controller
IBG Consulting OÜ
Aida tn 9
80011 Pärnu
Estonia
Email: legal@ibg-consulting.eu
Trading as: IBG Marketing, Pärnu
Overview of processing
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Inventory / master data
- Payment data
- Contact data
- Content data
- Contract data
- Usage data
- Meta, communication and procedural data
Categories of data subjects
- Customers
- Communication partners
- Prospective customers
- Users
- Business and contractual partners
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations
- Contact requests and communication
- Security measures
- Direct marketing
- Reach measurement and tracking
- Office and organisational procedures
- Management and response to enquiries; feedback
- Marketing; profiles with user-related information
- Provision of our online services and usability; IT infrastructure
Relevant legal bases
Below is an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR, national data protection provisions may apply in your or our country of residence or domicile. Where more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) — the data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) — processing is necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) — processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) — processing is necessary for the purposes of the legitimate interests of the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
Swiss data protection (FADP): where the Swiss Federal Act on Data Protection applies, this notice also serves as information under the FADP. For broader geographic applicability and readability, GDPR terminology is used; the legal meaning of the terms continues to be governed by the FADP within its scope of application.
Security measures
We take appropriate technical and organisational measures in accordance with legal requirements, taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access, as well as access, input, transfer, availability and separation of the data. We have also established procedures to ensure the exercise of data subject rights, the erasure of data and responses to threats to data. Furthermore, we consider the protection of personal data as early as the development and selection of hardware, software and procedures, in line with the principle of data protection by design and by default.
Transmission of personal data
In the course of our processing of personal data, data may be transmitted to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients may include, for example, service providers commissioned with IT tasks or providers of services and content embedded in a website. In such cases, we comply with legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Where we process data in a third country (i.e. outside the EU or the EEA), or where processing takes place in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies, this is only done in accordance with legal requirements. Where the level of data protection in the third country has been recognised by an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Information on third-country transfers and adequacy decisions is available from the European Commission.
EU-US Data Privacy Framework (DPF): under the adequacy decision of 10 July 2023, the EU Commission has recognised the level of data protection for certain US companies as adequate. The list of certified companies and further information is available at dataprivacyframework.gov.
Rights of data subjects
As a data subject, you are entitled to various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Art. 6(1)(e) or (f) GDPR, including profiling based on those provisions. Where personal data is processed for direct marketing, you have the right to object at any time to such processing, including related profiling.
- Right to withdraw consent: you have the right to withdraw your consent at any time.
- Right of access: you have the right to request confirmation as to whether data concerning you is being processed and to obtain information about that data as well as a copy of it.
- Right to rectification: you have the right to request the completion of data concerning you or the correction of inaccurate data.
- Right to erasure and restriction of processing: you have the right to request that data concerning you be erased without undue delay, or alternatively to request a restriction of processing.
- Right to data portability: you have the right to receive data concerning you that you have provided to us in a structured, commonly used, machine-readable format, or to request its transmission to another controller.
- Right to lodge a complaint with a supervisory authority: without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement — if you consider that the processing of your personal data infringes the GDPR. In Estonia, the competent authority is the Data Protection Inspectorate (Andmekaitse Inspektsioon).
Use of cookies
Cookies are small text files, or other means of storing and reading information on end devices. For example, they store a login status in a user account, the contents of a basket in an online shop, the content accessed, or functions used in an online offering. Cookies can also be used for different purposes, e.g. to ensure the functionality, security and comfort of online offerings and to analyse visitor flows.
Consent: we use cookies in accordance with legal requirements and therefore obtain prior consent from users unless it is not legally required. Consent is not required where the storage and reading of information, including cookies, is strictly necessary to provide a telemedia service expressly requested by the user. The revocable consent is clearly communicated to users and contains information on the respective use of cookies.
Storage duration: temporary (session) cookies are deleted at the latest after a user leaves an online offering and closes their device. Permanent cookies remain stored even after the device is closed; unless we provide explicit information on the type and storage duration of cookies, users should assume that cookies are permanent and can be stored for up to two years.
Opt-out: users can withdraw consent at any time and object to processing in accordance with legal requirements, including by restricting the use of cookies in their browser settings. An objection to the use of cookies for online marketing purposes can also be declared via optout.aboutads.info and youronlinechoices.com.
Legal bases: consent (Art. 6(1)(a) GDPR) and legitimate interests (Art. 6(1)(f) GDPR). We use a cookie consent management procedure to obtain, manage and enable withdrawal of consent. The consent declaration is stored so that it does not have to be requested again and can be evidenced; it may be stored for up to two years.
Business services
We process data of our contractual and business partners, e.g. customers and prospects, within the scope of contractual and comparable legal relationships and related measures, and in the context of communication with contractual partners (or pre-contractually), e.g. to respond to enquiries.
We process this data to fulfil our contractual obligations, to safeguard our rights, and for administrative tasks and business organisation. We also process the data on the basis of our legitimate interests in proper and efficient business management and in security measures to protect our contractual partners and our business operations from misuse and threats to their data, secrets, information and rights.
We erase the data after expiry of statutory warranty and comparable obligations, i.e. generally after 4 years, unless the data is stored in a customer account or must be retained for statutory archiving reasons. Statutory retention periods for tax-relevant records are up to ten years (e.g. commercial books, inventories, annual financial statements, booking vouchers) and six years for received/sent commercial and business letters.
Data types: master data, payment data, contact data, contract data. Data subjects: prospects, business and contractual partners. Legal bases: Art. 6(1)(b), (c) and (f) GDPR.
Provision of online services and web hosting
We process users' data to provide our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
Access data and log files: access to our online offering is logged in the form of server log files, which may include the address and name of the web pages and files accessed, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user's operating system, referrer URL and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes and to ensure server load and stability, on the basis of our legitimate interests (Art. 6(1)(f) GDPR). Log file information is stored for a maximum of 30 days and then deleted or anonymised, unless it must be retained for evidentiary purposes.
Contact and enquiry management
When you contact us (e.g. by post, contact form, email, telephone or via social media), and within existing user and business relationships, the information of the enquiring persons is processed to the extent necessary to respond to the contact requests and any requested measures. Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
Newsletter and electronic notifications
To subscribe to our newsletter it is generally sufficient to provide your email address. We may ask you to provide a name for personalised address or further information where necessary for the purposes of the newsletter.
Double opt-in: subscription takes place via a double opt-in procedure — you will receive an email asking you to confirm your registration, to ensure that no one can register using another person's email address. Registrations are logged (including registration and confirmation time and the IP address) to evidence the process in accordance with legal requirements.
Performance measurement: newsletters contain a web beacon (a pixel-sized file retrieved from our server or the dispatch provider's server when the newsletter is opened). This collects technical information such as browser and system, IP address and time of retrieval, and whether and when newsletters are opened and which links are clicked. This helps us adapt our content to readers' habits. Opt-out: you can cancel the newsletter at any time via the unsubscribe link at the end of each newsletter. Legal basis: consent (Art. 6(1)(a) GDPR).
Promotional communication (email, post, fax, telephone)
We process personal data for the purpose of promotional communication via various channels such as email, telephone, post or fax, in compliance with legal requirements. Recipients have the right to withdraw consent at any time or to object to promotional communication at any time. After withdrawal or objection, we store the data required to evidence a former authorisation to contact, on the basis of our legitimate interests, for up to three years after the end of the year of the withdrawal/objection, limited to defending against potential claims. Legal bases: consent (Art. 6(1)(a) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
Web analytics, monitoring and optimisation
Web analytics (reach measurement) serves to evaluate the visitor flows of our online offering and may include behaviour, interests or demographic information about visitors as pseudonymous values. With reach analysis we can, for example, recognise when our online offering or its functions or content are most frequently used, and identify areas that need optimisation. We may also use testing procedures (e.g. A/B tests) to test and optimise different versions of our online offering.
Profiles may be created for these purposes and information stored and read in a browser or device. Collected information includes pages visited and elements used, as well as technical information such as browser, computer system and usage times. IP addresses are stored, but we use an IP-masking procedure (pseudonymisation by truncation) to protect users. As a rule, no clear data (such as email addresses or names) is stored, but pseudonyms. Legal bases: consent (Art. 6(1)(a) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
Services used: Google Analytics 4 and Google Tag Manager (Google Ireland Limited). Google Tag Manager is used to manage tags (services and code blocks) without itself storing user data in cookies. Google Analytics is used for reach measurement and to create pseudonymous user profiles. Data transfers to the USA are based on the EU-US Data Privacy Framework and Standard Contractual Clauses. More information: Google Privacy Policy.
Online marketing
We process personal data for online marketing purposes, which in particular includes the marketing of advertising space and the display of advertising and other content based on potential user interests, as well as measuring their effectiveness. User profiles are created and stored in a cookie or by similar methods, containing information such as content viewed, websites visited, online networks used, and technical information. IP addresses are stored using IP-masking procedures; as a rule, no clear data is stored but pseudonyms.
In the context of conversion measurement, we can check which of our online marketing methods led to a conversion (e.g. a contract with us). Unless otherwise stated, please assume that cookies used are stored for two years. Legal bases: consent (Art. 6(1)(a) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
Service used: Meta Pixel (Meta Platforms Ireland Limited) for conversion measurement and audience building. Data transfers to the USA are based on the EU-US Data Privacy Framework and Standard Contractual Clauses. Opt-out: Europe youronlinechoices.eu; cross-regional optout.aboutads.info.
Affiliate programmes and affiliate links
We integrate affiliate links or other references to third-party offers and services in our online offering. If users follow these links or subsequently use the offers, we may receive a commission or other benefits from these third parties. To track whether users have used the offers, the respective third parties need to know that users followed an affiliate link within our online offering. The assignment of affiliate links to the respective transactions serves solely the purpose of commission accounting and is removed once no longer required. Legal bases: consent (Art. 6(1)(a) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
Customer reviews and rating procedures
We participate in review and rating procedures to evaluate, optimise and promote our services. Where users rate us or otherwise provide feedback via participating platforms, the terms and privacy notices of the respective providers apply. To ensure that reviewers have actually used our services, we transmit — with the customer's consent — the data required about the customer and the service used to the respective review platform (including name, email address and order/item number), used solely to verify the authenticity of the user. Legal basis: legitimate interests (Art. 6(1)(f) GDPR); security measure: IP masking.
Presence on social networks (social media)
We maintain online presences within social networks and process users' data in this context to communicate with active users or to offer information about us. Please note that user data may be processed outside the European Union, which may create risks for users because, for example, enforcing users' rights could be more difficult.
Within social networks, user data is usually processed for market research and advertising purposes. Usage profiles can be created based on user behaviour and resulting interests, and used to place advertisements inside and outside the networks. For these purposes, cookies are usually stored on users' devices. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
Instagram & Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland). For our Facebook page, we are jointly responsible with Meta for the collection (but not the further processing) of data of visitors to our page, on the basis of the “Page Insights” agreement. Data transfers to the USA are based on the EU-US Data Privacy Framework and Standard Contractual Clauses. Privacy policies: Instagram, Facebook.
Plugins and embedded functions and content
We integrate functional and content elements into our online services that are obtained from the servers of their respective providers (“third parties”), such as graphics, videos or maps. This always requires the third parties providing the content to process the users' IP addresses, as they could otherwise not send the content to the users' browsers. The IP address is therefore necessary to display this content. Third parties may also use pixel tags (invisible graphics, also known as web beacons) for statistical or marketing purposes. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).