Legal

Privacy Policy

We collect as little as possible, use it only to answer you, and never sell or trade it.

Last updated: 24 August 2026

1. Who is responsible for your data

OptiRank OÜ, registered in Estonia, operates the website optirank.agency and is the data controller for the personal data described here. All requests reach us through the contact form on the home page.

2. What we collect

There are exactly two ways personal data reaches us through this website.

  • The contact form. The name, email address, optional website address, selected topic and the message you write. Everything in that form is voluntary — you decide what to tell us.
  • Technical request data. Our hosting provider processes standard connection data (IP address, user agent, requested URL, timestamp) to deliver pages and to protect the site against abuse.

We run no analytics, no advertising pixels and no third-party trackers on this site. We do not profile visitors and we make no automated decisions about you.

3. Why we use it, and on what legal basis

  • To answer your enquiry and prepare an offer — Article 6(1)(b) GDPR (steps taken at your request before entering into a contract).
  • To keep the site available and secure — Article 6(1)(f) GDPR (our legitimate interest in a functioning, non-abused website).
  • To comply with accounting and tax obligations, where an enquiry turns into a paid engagement — Article 6(1)(c) GDPR.

4. Cookies

This site sets no analytics or marketing cookies and shows no cookie banner, because there is nothing to consent to. Our infrastructure provider may set a strictly necessary security cookie to distinguish humans from automated traffic; it carries no marketing identifier and is not used to track you across websites.

5. Who else processes it

We keep the list of processors deliberately short. Each of them acts on our instructions under a data processing agreement:

  • Cloudflare, Inc. — hosting, CDN and protection of this website.
  • Our email provider — delivery and storage of the message you send us.

We do not sell personal data, and we do not share it for anyone else's marketing.

6. International transfers

Our providers may process data outside the European Economic Area. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard under Chapter V of the GDPR.

7. How long we keep it

Enquiries that do not lead to an engagement are deleted within 24 months. If we start working together, correspondence is kept for the duration of the engagement and for as long as accounting, tax and limitation periods require. Technical logs are retained on a short rolling window by our hosting provider.

8. Your rights

Under the GDPR you may request access to your data, correction of it, erasure, restriction of processing, and portability, and you may object to processing based on legitimate interest. Send the request through the contact form and we will respond within one month.

If you believe we handled your data improperly, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or with the supervisory authority of your country of residence.

9. Security

The site is served over HTTPS only. Access to enquiry data is limited to the people who need it to answer you. Where a submission is stored, it is stored on infrastructure protected by access control and encryption in transit.

10. Changes

If this policy changes, the revised version appears on this page with a new "last updated" date. Material changes affecting people who already contacted us will be communicated by email.

Questions about this document?

Send them through the contact form and we will answer within one business day.

Open the form