Skip to content
Back to home

Privacy Policy

How we process and protect your data

Data Controller

Service: DoraAudit.eu

Operated by: Doraaudit

Location: Estonia

Email: info@doraaudit.eu

Data We Collect

Contact Information

Name and email address — upon registration and lead magnet use.

Company Information

Company name, sector, and size — in scope checks and assessments.

Payment Information

Payments are processed via LemonSqueezy. We do not store or process card data ourselves.

Technical Information

IP address and browser type — in server logs for security purposes.

Cookies

Functional cookies for session management and analytics cookies for service improvement (with consent only).

Legal Basis for Processing

We process your data based on the following GDPR Article 6 grounds:

  • Art. 6(1)(b)Contract performance — necessary to provide the service
  • Art. 6(1)(f)Legitimate interest — to ensure service security and quality
  • Art. 6(1)(a)Consent — for marketing communications (via email)

Data Retention

Account dataUntil account deletion
Assessment results2 years
Payment records (invoices)7 years (accounting law)
Server logs12 months

Data Sharing with Third Parties

We only share your data with the following service providers:

LemonSqueezy

Payment processing (USA — Standard Contractual Clauses)

Hetzner

Server hosting (Germany)

We do not sell or share your data with advertisers or other third parties.

Your Rights

Under GDPR, you have the following rights:

Art. 15Right of access
Art. 16Right to rectification
Art. 17Right to erasure
Art. 18Right to restriction of processing
Art. 20Right to data portability
Art. 21Right to object

To exercise your rights, contact: info@doraaudit.eu

You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (AKI) at www.aki.ee

Cookies

RequiredFunctional cookies — session management
OptionalAnalytics cookies — with consent only
Not usedMarketing cookies

Security Measures

  • HTTPS encryption for all data transfers
  • Access restricted to authorized personnel
  • Regular backups for data protection

Policy Changes

We will notify you of significant changes via email. We recommend reviewing this page regularly.

Last updated: 08.02.2026