Privacy Policy
Updated 1 October 2026
- THE A EU OÜ
- Service / trading name: Aspthea (a service of THE A EU OÜ)
- Registered office: Tuuliku tee 4c, 10621 Tallinn, Estonia
- Registry code: 16643088 (Estonian Commercial Register); registered on 2 January 2023
- VAT number: EE102578456
- Management Board member and authorised representative: Anton Homza
- Company website (THE A EU OÜ): https://www.theamarketingagency.com/
- Company email (THE A EU OÜ): [email protected] | [email protected]
- Service website (Aspthea): aspthea.com
- Service email (Aspthea), for all privacy questions and requests: [email protected]
- WhatsApp (messages and calls): +44 7389 769266
This Policy explains how THE A EU OÜ (“we”, “us”), the company behind Aspthea, uses personal data when you visit aspthea.com, contact us, ask for a preview, buy from us or work with us. Section 11 briefly explains our different role when we build or host a website for a business.
In short
- We use your details to reply to you, prepare a preview or quote, deliver and bill our work, and keep the records the law requires.
- aspthea.com has no analytics, advertising pixels or tracking cookies. We do not sell personal data.
- Providers help us run the service, including some outside the European Economic Area (EEA). Sections 6 and 7 name them and the safeguards.
- You can ask to see, correct or delete your data, or object to its use: write to [email protected].
- You can complain to the Estonian Data Protection Inspectorate (section 10.4).
1. Who we are and how to contact us
1.1 THE A EU OÜ is a private limited company established in Estonia. Aspthea is a service of THE A EU OÜ: the name under which we design, build, host and look after websites for businesses. For the processing described as our own in this Policy, we determine the purposes and essential means and act as an independent data controller. The EU General Data Protection Regulation (EU GDPR) and Estonian law apply to processing in the context of our Estonian establishment. The UK GDPR, the UK Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR), as amended, apply to relevant UK activities where their territorial requirements are met.
1.2 For any question, rights request, security concern or data protection complaint about our own processing, email [email protected], or write to the registered office above, marked “Data Protection”. This is our privacy contact; it does not by itself appoint a statutory data protection officer. If a data protection officer is appointed, we will publish their contact details here.
1.3 Our role depends on whose data it is:
| Situation | Our role | Who gives you the main privacy information |
|---|---|---|
| aspthea.com, enquiries, previews, quotes, client contacts, billing and our portfolio | Independent controller | THE A EU OÜ, through this Policy |
| Visitor, enquiry or booking data on a client’s website that we build, host or support for that client | Processor | The client, through its own privacy notice; our Data Processing Agreement (DPA) with the client governs our part |
1.4 UK representative under Article 27 UK GDPR: where the UK GDPR applies, we will assess whether THE A EU OÜ has a UK establishment and, if not, whether Article 27 requires the appointment of a UK representative. If such an appointment is required, the representative’s details will be published here before the relevant processing begins.
2. What we collect and where it comes from
2.1 The project form on aspthea.com. The form asks what kind of business you have, what it has online today, a link to it, what would help most, a site you like the look of, an optional note, your name, your email address, how you would like us to reply and, if you choose WhatsApp or a call, your phone number. When you press Send, your answers go to Web3Forms, a form delivery service, which emails them to our mailbox at [email protected]. If sending fails, the form offers to put your answers into a WhatsApp message or an email that you send yourself.
2.2 Email and WhatsApp. If you write to [email protected], we receive your address, name, message and any attachments. Our only phone number, +44 7389 769266, is used through WhatsApp, for messages and for calls. If you message or call us on WhatsApp, or we call you there, we receive your number, the profile name and picture WhatsApp shows us, your messages, files and voice notes, and the time and length of calls. If you tap a WhatsApp link on our site, WhatsApp opens a chat with us and may learn that you came from our site.
2.3 Visiting aspthea.com. Our site is hosted by Cloudflare. When your browser loads a page, Cloudflare processes your IP address, the page requested, the time, your browser and device type and the referring page, so that it can deliver the page and protect the site against attacks and abuse. Cloudflare also asks browsers to report network errors (Network Error Logging): your browser keeps a short instruction from our site for a limited time and, if a page fails to load, may later send Cloudflare a report with the page address, the type of error and timing. Cloudflare uses the IP address in such a report only while processing it and keeps derived information such as country and network. This information may be personal data even if it does not show your name.
2.4 Previews, quotes and work. If you ask for a preview, a quote or work, we collect your business details, contact details and the material you send us: text, logos, photographs, domain or account details and project requirements. Photographs can show identifiable people, such as staff or customers. When we register a domain in your business’s name, we use the registrant details you give us. We may prepare a free preview of part of your website on your material before any order. We use that material only to prepare and show you the preview and do not submit it to image or video generation services. We share the preview link only with you and keep it out of search engines. If no Order Form is signed within 30 days after we send you the preview, we delete the preview and the material you sent us for it.
2.5 Clients and payments. We keep contract and project records, approvals, support requests, invoice and tax details, payment dates, amounts, references, payment status and refunds. We invoice the website build, and it is paid by bank transfer to our company bank account. A Care Plan subscription is paid by card through Stripe, and so is a build charge where the Order Form provides for card payment as an exception; Stripe processes your card details and gives us only limited payment information. We do not ask clients to send full card numbers or bank login details in correspondence.
2.6 From other sources. We may receive a business contact’s details from that person, from their business, from someone who introduces them, from a business card, or from a public business listing, website or register. We will not treat public availability as unrestricted permission to market to an individual. Where the data comes from elsewhere, we provide the information required by Article 14 GDPR, normally in our first message to you.
2.7 Sensitive data and children. Please do not send health information, identity documents, children’s information or criminal-offence data through the form or to our ordinary inbox or WhatsApp unless we have specifically agreed a secure way to do so. If we receive such information without asking for it, we restrict access and delete what we do not need. Our services and website are aimed at businesses and adults, not children.
2.8 What you have to give us. A name and an email address are needed for us to reply to the form, and a phone number only if you ask us to reply by WhatsApp or phone; the other answers are optional. Agreed business, invoicing and payment details are needed to enter into and perform a contract. If necessary information is withheld, we may be unable to quote, contract, invoice or provide a particular service.
3. Why we use data and our lawful bases
3.1 We identify a purpose and lawful basis for each use. Article 6(1)(b) GDPR, steps towards or performance of a contract with an individual, applies where you are yourself a party, for example as an individual trading in your own name; it is not the basis merely because a named employee represents a company that has a contract with us. For those representatives we rely on our legitimate interests in dealing with the business, subject to the required balancing assessment. A legal obligation applies only to the processing needed to meet that obligation.
| What we do | Lawful basis |
|---|---|
| Reply to an enquiry by the channel you chose, arrange a call, prepare a quote or a free preview | Article 6(1)(b) for steps you ask for before a contract, if you trade in your own name; otherwise Article 6(1)(f), our interest in answering business enquiries and offering relevant services |
| Make and manage an Order, communicate about the project, design, build, host and look after the website, and give support | Article 6(1)(b) for a contracting individual; Article 6(1)(f) for company contacts, namely performing the business relationship and resolving questions about work agreed |
| Invoice, collect and reconcile payments, administer a Care Plan, prevent duplicate or fraudulent transactions and deal with payment disputes | Article 6(1)(b) for a contracting individual; Article 6(1)(f) to collect legitimate debts and protect our business; Article 6(1)(c) for required accounting and tax records |
| Keep legally required accounting, tax and corporate records; answer a valid request from a competent authority | Article 6(1)(c), the applicable Estonian or other binding legal obligation |
| Keep records of what was agreed, approvals, instructions, incidents and complaints; establish, exercise or defend claims | Article 6(1)(f), protecting our legal position and showing what was agreed; Article 6(1)(c) where the law requires a record |
| Deliver and secure aspthea.com, prevent abuse and diagnose faults using limited device, log and network error information | Article 6(1)(f), reliable and secure operation of the site; information is stored on or read from your device only where strictly necessary for that |
| Follow up a business we met or that contacted us about a relevant service | Article 6(1)(f) where direct marketing is legally permitted and proportionate; Article 6(1)(a) where the electronic-marketing rules require consent |
| Show completed work, a business testimonial or case study in our portfolio | Article 6(1)(f), showing our work, only where the business permits it under our Terms and individuals’ interests have been assessed; where necessary, the identifiable person’s consent before we publish their name, image or testimonial |
| Work with and pay suppliers and contractors | Article 6(1)(b) for an individual contracting with us; Article 6(1)(f) for business contacts; Article 6(1)(c) for payment and tax records |
3.2 Our legitimate interests are limited to running and protecting a business that provides agreed services, answering relevant business enquiries, keeping accurate records, preventing misuse and showing authorised examples of our work. Before relying on that ground for a new activity, we assess necessity and the impact on the individual. You may ask us for more information about that assessment.
3.3 We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. We do not sell personal data and do not use visitor data from our clients’ websites for our own advertising.
4. Following up and our portfolio
4.1 If we met your business or you contacted us, we may follow up about a relevant service where the applicable electronic-marketing rules allow it, with our identity and an easy way to opt out in each message. An enquiry, purchase or signed Order is not by itself consent to promotional messages. We act on an objection immediately and keep only what we need to avoid contacting you again.
4.2 Messages about a quote you asked for, an Order, an incident, an essential change, an invoice, a trial period or a cancellation are service messages, not marketing. A client’s permission to show a completed website in our portfolio does not by itself allow us to publish the name, face or testimonial of every individual shown on it.
5. Cookies and similar technologies
5.1 aspthea.com uses no analytics, advertising or social-media cookies, pixels or similar tracking tools, and loads no content from other websites when a page opens. Our hosting provider may use strictly necessary technologies: network error reporting (section 2.3) and, if a connection needs to be checked for abuse, a security cookie.
5.2 If you pay by card, Stripe’s payment page uses its own cookies, explained in Stripe’s cookie policy. A link to WhatsApp or another service takes you to that service, which is governed by its own privacy notice.
5.3 Before adding any optional technology, we will ask for your consent where the law requires it and update this Policy.
6. Who we share data with
6.1 We share personal data only as needed for the purposes in section 3. The recipients include:
- Cloudflare, Inc. (United States): hosting of aspthea.com and of our clients’ websites, DNS, security, request logs and network error reports;
- Web3Creative, operator of Web3Forms (India): delivery of the answers to our project form by email to [email protected];
- Heinlein Hosting GmbH, operator of mailbox.org (Germany): our email at [email protected], including the answers to our project form;
- WhatsApp Ireland Limited (Ireland), part of Meta: our WhatsApp messages and calls;
- GitHub, Inc. (United States): storage of website code and project files;
- Higgsfield Inc. (United States): creating images and video for a client’s own website from that client’s material, only where the client has ticked the consent box in the Order Form; under its own terms it may use the uploaded material to train its models;
- Stripe Payments Europe, Limited (Ireland), with Stripe, LLC (United States): card payments for Care Plan subscriptions and, where the Order Form provides for it, for a website build;
- Vercel Inc. (United States): hosting of a client website;
- our business developer, an independent contractor in the United Kingdom who handles enquiries and contact with clients for us;
- our bank, for invoice payments;
- our accountant and professional advisers;
- the domain registrar chosen for a client’s domain, which receives the registrant details;
- authorities such as the Estonian Tax and Customs Board, where the law requires it.
6.2 Some of these recipients, such as WhatsApp, Stripe, banks and domain registrars, also use data for their own purposes under their own privacy notices, as independent controllers. We do not share personal data for anyone else’s marketing.
7. Transfers outside the EEA
7.1 Some providers process data outside the European Economic Area, and a server region alone does not determine every place from which data can be accessed. We use a provider outside the EEA only where the transfer is covered by an adequacy decision of the European Commission or by an appropriate safeguard under Article 46 GDPR:
| Recipient | Where | Safeguard |
|---|---|---|
| Cloudflare, Inc. | United States and Cloudflare’s global network | EU–US Data Privacy Framework (Cloudflare is certified); standard contractual clauses in Cloudflare’s data processing addendum |
| Web3Creative (Web3Forms) | India | Standard contractual clauses in the Web3Forms data processing agreement |
| GitHub, Inc. | United States | EU–US Data Privacy Framework (GitHub is certified); standard contractual clauses |
| Vercel Inc. | United States | EU–US Data Privacy Framework (Vercel is certified); standard contractual clauses |
| Higgsfield Inc. | United States; Higgsfield also names a location in Kazakhstan | Used only where the EU–US Data Privacy Framework or standard contractual clauses cover the transfer |
| Stripe Payments Europe, Limited | Ireland; Stripe, LLC in the United States | EU–US Data Privacy Framework (Stripe, LLC is certified); standard contractual clauses |
| WhatsApp Ireland Limited | Ireland; WhatsApp transfers data to the United States and other countries | WhatsApp’s own transfer safeguards, described in its privacy policy |
| Our business developer (independent contractor) | United Kingdom | Adequacy decision of the European Commission for the United Kingdom |
7.2 Where UK GDPR applies, transfers from the United Kingdom to Estonia or another EEA country are covered by the UK’s adequacy regulations for the EEA. You may ask for information on the safeguards for our own processing at [email protected]; we may redact unrelated commercial terms.
7.3 Where we process data for a client as its processor, the DPA with that client governs transfers.
8. How long we keep data
8.1 We keep data only as long as needed for the purpose, a legal duty or an identified claim, then delete or anonymise it. Where more than one period applies to the same record, the longest justified period applies, with access restricted to that purpose.
| Data | How long |
|---|---|
| Form answers, messages and notes about an enquiry that does not become an Order | 12 months after the last meaningful exchange, unless a dispute or legal duty requires longer. Web3Forms keeps its own copy of form answers for up to three years and then deletes it automatically |
| A free preview and the material sent for it, if no Order Form is signed | Deleted if no Order Form is signed within 30 days after we send the preview |
| Contract, specification, approvals, key project correspondence and service records | Normally up to six years after the business relationship ends, to document performance and possible claims under the contract; longer only where a specific claim or law requires it |
| Accounting source documents, invoices and payment records | At least seven years from the end of the relevant financial year, as the Estonian Accounting Act requires; longer only where another rule, audit or live dispute requires it |
| Project files after a client leaves | Deleted 90 days after the end of our service, unless the DPA or law requires earlier deletion or return of personal data |
| Contacts we follow up | While there is an active relationship, reviewed at least once a year, and normally no more than 12 months after the last meaningful contact. After an opt-out, a minimal record so that we do not contact you again |
| Portfolio projects, names, images and testimonials | While publication has a valid basis and remains relevant, reviewed at least once a year; removed or changed after a valid objection or withdrawal of consent |
| Privacy requests, consents, complaints and incident records | While needed to show compliance or deal with the issue, normally up to six years after resolution if a claim remains reasonably possible; longer only for a documented legal hold or binding duty |
| Website request logs and network error reports | For the shortest period Cloudflare needs to deliver, protect and investigate the service, under its own rotation |
| Visitor, enquiry and booking data processed for a client | As the client instructs under the DPA |
8.2 Deletion from active systems can come before short-lived, protected backup copies expire. We restrict access to such copies, let them expire through the normal backup cycle and do not use a backup to restore data erased at your request, unless a specific legal exception requires it.
9. Security
9.1 We use technical and organisational measures proportionate to the data and the risk, including access only for those who need it, two-factor authentication on the accounts that hold personal data where the provider offers it, secure transmission, careful handling of credentials, checks on suppliers, and removal of access when it is no longer needed. No measure is a guarantee that a system cannot fail.
9.2 Please do not send passwords, complete card details or sensitive information to our ordinary inbox or WhatsApp. Use the secure handover method agreed for your project and tell us promptly if you suspect that your credentials or account have been compromised.
9.3 If a personal data breach affects data we control, we assess and record it, notify the Estonian Data Protection Inspectorate without undue delay and, where feasible, within 72 hours of becoming aware where the legal risk threshold is met, and inform affected individuals without undue delay where the breach is likely to result in a high risk to them. If we are a client’s processor, we notify and assist that client under the DPA.
10. Your rights and how to use them
10.1 Where we are the controller, you may ask for access to your personal data, rectification, erasure, restriction, portability where its conditions apply, and information about the processing. You may object to processing based on legitimate interests. If we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal. Rights can be subject to legal conditions and exceptions; for example, we may have to keep an invoice for the period the accounting law requires. If we refuse a request, we explain why and how you can complain or go to court.
10.2 You may object at any time to the use of your data for direct marketing. Write “Stop marketing” to [email protected] or use the opt-out in the message. We stop and keep only the minimal information needed to respect your choice. This does not stop necessary service messages about an existing Order.
10.3 Send a rights request or complaint to [email protected]. You do not need a special form or to cite the GDPR. We may ask for proportionate information to confirm your identity or authority, especially before disclosing data. We reply without undue delay and within one month; for a complex or numerous request we may extend this by up to two further months, telling you why within the first month. Requests are free, except where a request is manifestly unfounded or excessive.
10.4 You have the right to complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, [email protected], +372 627 4135, www.aki.ee. You may also complain to the supervisory authority in the EU or EEA country where you live or work or where you believe the infringement took place and, where UK GDPR applies, to the UK Information Commissioner’s Office. You also have the right to go to court. We would welcome the chance to deal with your concern first, but you do not have to contact us before complaining.
11. Data we handle for our clients
11.1 A business that collects enquiries, bookings or visitor information through its own website is the controller of that data. It decides what its forms ask, who receives the messages and how long the data is kept, and its own privacy notice, not this Policy, explains that to its visitors.
11.2 We are that business’s processor only to the extent that we build, host, maintain or support its website under its documented instructions. Before live processing we sign a DPA with the client, which lists the providers we use for it and takes priority over this Policy for that processing. We do not reuse a client’s visitor or customer data for our own purposes. We submit a client’s own material to an image or video tool only to create images and video for that client’s own website, and only with the client’s consent in the Order Form, which tells the client that the tool may use the uploads to train its models. We never submit the enquiries or bookings of the client’s customers to such a tool.
11.3 If you send us a request about data held on a client’s website, we pass it to that client promptly and help the client under the DPA. We do not decide the request ourselves or disclose the client’s records without lawful authority.
12. Changes and related documents
12.1 We review this Policy when our processing, providers, website functions or the law materially change. The current version and its date are published at aspthea.com/privacy. If a change affects how we use data we already hold, we will tell you directly or by a prominent notice where the law requires it before the new use begins, and ask for fresh consent where the new purpose requires it.
12.2 This Policy is read together with the Order Form, the Terms and Conditions, the Refund and Cancellation Policy, the Care Plan Subscription Terms and, for processing we do for a client, the signed DPA. If you need this Policy in another accessible form, contact us at [email protected].