Your GDPR Rights
1. Your Rights at a Glance
| Right | What it means | Response time |
|---|---|---|
| Access (Art. 15) | Get a copy of all personal data we hold about you | 30 days |
| Rectification (Art. 16) | Correct inaccurate or incomplete personal data | 30 days |
| Erasure (Art. 17) | Request deletion of your personal data | 30 days |
| Restriction (Art. 18) | Limit how we use your data while a dispute is resolved | 30 days |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format | 30 days |
| Object (Art. 21) | Object to processing based on legitimate interest | 30 days |
| Withdraw consent | Withdraw consent at any time where consent is the legal basis | Immediate |
2. How to Make a Request
Email us at privacy@qann.cowith the subject line: “GDPR Data Request — [type of request]”.
Include in your email:
- Your full name
- Email address associated with any account or correspondence with us
- The specific right you are exercising
- Any relevant details (e.g. what data you want deleted or corrected)
We may ask you to verify your identity before processing the request to protect against unauthorised access to personal data. We will never charge a fee for exercising your rights, unless a request is manifestly unfounded or excessive.
3. Right of Access (Art. 15)
You can request a copy of all personal data we hold about you. We will provide:
- Confirmation of whether we process your personal data
- A copy of the data we hold (in a readable format)
- Information on how we use it, who we share it with, and how long we keep it
4. Right to Rectification (Art. 16)
If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. Tell us what is wrong and what the correct information is. We will update our records and notify any third parties we have shared the data with.
5. Right to Erasure (Art. 17)
You can request that we delete your personal data. We will do so unless we are required to retain it by law. Grounds for erasure include:
- The data is no longer needed for the purpose it was collected
- You withdraw your consent and there is no other legal basis
- You object to processing and we have no overriding legitimate interests
- The data has been unlawfully processed
Note: We are legally required to retain financial records for 7 years under Estonian accounting law. We cannot erase these, but we can restrict how they are used.
6. Right to Restriction (Art. 18)
You can ask us to limit how we use your data in certain circumstances — for example, while you contest the accuracy of data we hold, or while we assess your objection to processing. When processing is restricted, we will only store the data, not use it.
7. Right to Data Portability (Art. 20)
Where we process your data by automated means on the basis of consent or contract, you can request your data in a structured, commonly used, machine-readable format (such as CSV or JSON) and have it transferred to another provider where technically feasible.
8. Right to Object (Art. 21)
You can object to processing based on legitimate interest. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or for legal claims. You always have the right to object to direct marketing.
9. Withdrawing Consent
Where processing is based on your consent (e.g. analytics cookies), you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. To withdraw consent:
- Analytics cookies: Update your preferences via the cookie settings on this site
- Marketing communications: Use the unsubscribe link in any email, or email privacy@qann.co
10. Automated Decision-Making
Qann does not make automated decisions about individuals that produce legal or similarly significant effects. We do not engage in profiling for such decisions.
11. Complaints
If you are not satisfied with how we have handled your data or a rights request, you have the right to lodge a complaint with:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
Website: aki.ee
Email: info@aki.ee · Tel: +372 627 4135
If you are based in the Netherlands, you may also contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl
12. Contact Our Data Protection Contact
For all data protection matters:
Email: privacy@qann.co
Response time: Within 3 business days for initial acknowledgement, 30 days for full response
Post: Qann Commerce OÜ, Ahtri tn 12, Kesklinna linnaosa, 15551 Tallinn, Harju maakond, Estonia