Privacy Policy
This policy explains how Pi-Pi collects, uses, and protects your personal data in accordance with GDPR.
Data Controller
TSSTBOX OÜ
Veerme tn. 23, 11625 Tallinn, Estonia
VAT: EE102594197
Email: mail@pi-pi.ee
What Data We Collect
We collect the minimum amount of personal data necessary to process orders and support customers:
- Contact Information: name, email, phone number
- Company Data: name, VAT number, registered address
- Order Data: ordered products, delivery address, payment information
- Usage Data: anonymous site analytics (via Google Analytics)
How We Use Your Data
We use your personal data for the following purposes:
- Processing and fulfilling orders
- Responding to inquiries and customer support
- Improving the site and service based on aggregated data
- Fulfilling legal obligations (tax accounting, bookkeeping)
Legal Basis (GDPR)
We process personal data on the following legal bases:
- Contract performance: order processing and product delivery
- Consent: analytical cookies (with your consent)
- Legitimate interest: service improvement, fraud prevention
- Legal obligation: tax and accounting requirements
Data Retention Period
We retain personal data only as long as necessary: order and invoice data — 7 years (legal requirement), contact form inquiries — 2 years, analytics data — 26 months. You can request deletion of non-essential data at any time.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of your personal data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data
- Right to data portability: receive data in a machine-readable format
- Right to object: object to processing based on legitimate interest
Third Parties
We share data with trusted third parties only when necessary:
- Google Analytics: anonymous site usage data (with your consent)
- Hosting providers: data processing for site operation (in the EU)