Skip to content
U.AVERO
ExpertiseSectorsApproachDiagnosticContact
УкраїнськаBook a 30-minute call
ExpertiseSectorsApproachDiagnosticContactУкраїнська
Home/ legal/ privacy

Legal

Privacy Policy

Effective date 30 August 2026.

Controller and contact details

U.Avero is a brand operated by U.Agency OÜ, registry code 14888621, Sakala tn 7-2, Kesklinna linnaosa, 10141 Tallinn, Harju maakond, Estonia. U.Agency OÜ is the controller of the personal data described in this Privacy Policy.

Email contact@uavero.com. Phone +372 5 947 47 55.

Scope

This Policy explains how we process personal data when you use uavero.com, submit a website enquiry, contact us by email or telephone, or communicate with us about a possible engagement.

Personal data processed during a client engagement is governed by the relevant contract, instructions and any engagement-specific privacy or data-processing terms.

Personal data we collect

Diagnostic answers and readiness-checklist selections are evaluated in the active page. The selected answers are not sent to the website database. Diagnostic start and completion events may be recorded, but not the answers themselves.

Do not submit classified, export-controlled, special-category or other sensitive information through the public form. Contact us first to agree a suitable channel. If you provide another person’s data, you must have the right to do so and give that person the required information.

Enquiry information

The website form requires an email address and message. Name, company, telephone, sector and referral source are optional. We may also receive other business or project information that you choose to include.

Submission information

The website records the language, source page, submission time, reference number, notice version and acknowledgement time, status and deletion threshold. UTM source and campaign values are recorded only when present in the URL.

Usage events

The website records page views and may record booking, email, telephone, form and diagnostic actions. Each event contains its type, page path, language, time and any UTM source or campaign in the URL. The application adds no cookie, advertising identifier or persistent visitor identifier to these records.

Technical and security data

Hosting, network and security infrastructure processes request data needed to deliver and protect the website, such as IP address, request time, requested resource, browser information and security signals.

Purposes and legal bases

We use enquiry and correspondence data to review and respond to a request, arrange a discussion, assess whether and how we may help, and prepare a proposed scope of work. Where you ask us to take steps before a possible contract with you, the legal basis is GDPR Article 6(1)(b). Where you act for an organisation or that basis does not apply, we rely on our legitimate interests under Article 6(1)(f) in handling genuine business enquiries and protecting our legal and business interests.

We use usage events and technical or security data to operate, secure and diagnose the website, prevent spam and abuse, understand whether pages and contact routes work, and create limited performance statistics. The legal basis is our legitimate interests under Article 6(1)(f). We do not use these records for advertising, cross-site tracking or a persistent visitor profile.

The form acknowledgement records that this Policy was shown and read. It is not consent and is not the legal basis for the processing described above. We do not use enquiry data for marketing without first providing the required information and establishing a separate legal basis.

Required and optional information

Providing information is not a statutory requirement. A valid email address, a message of at least 20 characters and confirmation that you have read this Policy are required to submit the website form. Without them, the form cannot be sent and we may be unable to respond. Other visible fields are optional. A later contract or legal obligation may require additional information, which will be explained separately.

Recipients and service environment

Access is limited to authorised people working for U.Agency OÜ and service providers that support the website, database, network, security, email and business operations, in each case only as needed for the relevant purpose. We may also disclose data to professional advisers or public authorities where the law requires it or where necessary to establish, exercise or defend legal claims.

Website enquiries and usage events are currently stored in the ChatGPT Sites website environment. When an enquiry is taken forward, relevant correspondence or working records may be handled in Gmail, Google Drive or Airtable. No advertising network or separate third-party analytics platform receives the website event records. We do not sell personal data.

International transfers

The service environment may involve processing outside the European Economic Area. Where personal data is transferred to a country without an applicable adequacy decision, U.Agency OÜ requires an appropriate safeguard permitted by GDPR Chapter V, such as the European Commission’s standard contractual clauses, together with supplementary measures where required. Information about the applicable safeguard can be requested at contact@uavero.com.

Retention

The website intake database assigns each enquiry a deletion threshold 30 days after submission. Expired enquiries are removed during the next website housekeeping cycle. Usage-event records older than 90 days are removed during the same process. These thresholds govern the temporary website intake and measurement databases rather than all later business records.

If an enquiry continues by email, telephone or as a client engagement, relevant correspondence may be retained for as long as needed to manage the relationship, meet contractual or legal obligations, and establish, exercise or defend legal claims. Provider security and backup records follow the applicable provider retention and deletion controls. Data is deleted or anonymised when it is no longer needed for these purposes.

Security

We use proportionate controls for the website, including input validation and length limits, same-origin checks where origin information is available, anti-spam and form-timing controls, per-address rate limiting, non-cached API responses and browser security headers. Access to personal data is limited according to need.

No internet transmission or storage system is completely secure. Do not send sensitive material through the public form. This section does not represent a specific certification or guarantee absolute security.

Your rights and complaints

Subject to the GDPR and its conditions or limitations, you may request access, correction, erasure, restriction and portability of your personal data. You may object, for reasons relating to your situation, to processing based on Article 6(1)(f).

Send a request to contact@uavero.com. We may ask for information reasonably needed to verify identity. We normally respond without undue delay and within one month, subject to the extensions permitted by the GDPR.

You may complain to the Estonian Data Protection Inspectorate, Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, or another competent supervisory authority, including in the EEA country of your habitual residence, workplace or the alleged infringement. You also have a right to judicial remedy.

Automated decisions and changes

The diagnostic and readiness checklist provide directional results from choices made on the page. They do not create a contract, determine eligibility for a service or produce legal or similarly significant effects. We do not use the processing described in this Policy for solely automated decisions within GDPR Article 22.

We may update this Policy when the website, data handling or legal requirements change. The current text and effective date will be published on this page. Where required, we will provide additional information before a new purpose or materially different processing begins.

U.AVERO

C-level advisory, hands-on execution, automation and BPO for technology businesses across Ukraine and the EU.

ExpertiseService linesSectorsDiagnostic
CompanyApproachReadiness checklist
Contactcontact@uavero.com+372 5 947 47 55Submit an enquiry

U.Avero is a brand operated by U.Agency OÜ, registry code 14888621, Sakala tn 7-2, Kesklinna linnaosa, 10141 Tallinn, Harju maakond, Estonia. contact@uavero.com · +372 5 947 47 55

PrivacyCookiesTerms