This notice sets out what personal data we handle when you use the rudi.red site or the services offered on it, why we handle it, how long we keep it, and what you can do about it.
1. Who handles your data
The controller is Reindeer Entertainment OÜ (Estonia), which operates rudi.red and provides the advisory services offered on it. The company’s registration details are in the site footer.
For anything to do with privacy, write to rudolf@rudi.red.
We are not required to appoint a data protection officer, because we carry out no large-scale, regular and systematic monitoring.
2. What we handle, why, and on what basis
Getting in touch
If you write by email, call, or message on WhatsApp, we handle your name, your contact details and whatever you tell us about yourself or your company, so that we can reply. Legal basis: steps taken prior to entering a contract at your request, and our legitimate interest in answering business enquiries.
Booking a slot
Booking happens on Google’s scheduling page, not on this site. Google records your name, your email address and any note you add there. Legal basis: performance of a contract, or steps taken prior to it.
Payment
The AI audit is paid through Stripe. We never see or store your card details; Stripe handles those directly. What reaches us is the fact of the transaction, the amount, and your billing details. Legal basis: performance of a contract, and legal obligation for the billing data.
Invoicing and accounts
We have to keep issued invoices and the related records under accounting rules. Legal basis: legal obligation.
Website analytics
Section 3 sets out the detail. Legal basis: our legitimate interest in seeing how the site is used and what is worth improving.
3. Website analytics
The site uses analytics we built ourselves, operated by the same company that runs the
site. The data goes to core.reindeer.red and is not passed to any third-party
advertising or analytics service. There is no Google Analytics, Meta Pixel or similar
external tag on this site.
We use no cookies. The analytics stores a random session identifier in your browser’s
session storage (sessionStorage), under a reindeer_session_… key. This is not a
cookie: your browser discards it when you close the tab, and it cannot be used to link
separate visits.
What your browser sends:
- the path of the page you opened, and where you came from if it was an external site
- campaign parameters in the address (
utm_*,ref) and no other parameters - your browser identifier (user agent), language setting and time zone
- your screen and window size, your platform, and whether you are on mobile
- how long you stayed on the page and how far you scrolled
What the server stores from that:
- the above, with a timestamp
- a short hash derived from a truncated version of your IP address, instead of the address itself
- a visitor identifier that changes daily, hashed from your IP address, your browser identifier and that day’s date
We do not store your full IP address. These hashes do not identify you directly, but they count as pseudonymous data, so this notice and the rights below apply to them in full.
We do not derive your country from your IP address. We estimate it from your browser’s time zone, and only use it in aggregate reporting.
If Do Not Track is enabled in your browser, the analytics never starts and sends nothing about you.
4. Who else sees it
We do not sell your data and we do not use it for advertising. To run the service we use these processors:
| Who | For what |
|---|---|
| Google Ireland Ltd. | scheduling, business email |
| Stripe Payments Europe Ltd. | card payment for the AI audit |
| Meta Platforms Ireland Ltd. | only if you message on WhatsApp |
| Our server provider | serving the site and the analytics |
| Our accountant | processing invoices |
Beyond that, we may be required to disclose data to authorities.
Your data stays within the European Union by default. Google and Stripe may in some cases transfer data to the United States; both are certified under the EU-US Data Privacy Framework or rely on the European Commission’s standard contractual clauses.
5. How long we keep it
- Enquiries: while we are dealing with them, then for up to 1 year, so there is something to refer back to if you write again.
- Contract and delivery documents: until the limitation period for claims arising from the contract has run out.
- Invoices and accounting records: 7 years, under Estonian accounting rules.
- Analytics events: up to 90 days, after which we delete them.
6. Your rights
You can ask us for access to the data we hold about you, ask us to correct inaccurate data, erase your data, or restrict how we use it. You can also ask us to hand it over in a portable format. You can object to us handling your data on the basis of legitimate interest, and that includes the analytics.
Send your request to rudolf@rudi.red. We answer within a month.
One limitation applies to analytics: the visitor identifier is a hash that changes daily, so without further information we cannot retrieve one specific person’s analytics events. You can, however, opt out of measurement at any time by turning on Do Not Track.
If you think we are handling your data unlawfully, you can complain to a supervisory authority. Since the company is registered in Estonia, that is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). You may also go to the authority where you habitually reside.
7. Automated decision-making
We do not make automated decisions about you and we do not carry out profiling.
8. If this changes
If we amend this notice, we will publish the new version here and change the update date above.