Privacy Policy

1. Purpose and Scope

This Privacy Policy outlines how Encomage OÜ (hereinafter referred to as "Encomage OÜ" or "We") collects, uses, protects, and manages your personal data in the context of providing consultative and managed development services.

This policy applies to all individuals whose personal data we process, including clients, prospective clients, business partners, suppliers, and website visitors. By engaging with our services or accessing our website, you agree to the terms outlined in this Privacy Policy.

2. Information We Collect

We may collect and process the following types of personal information:

  • Contact Information: name, email address, phone number, company name.
  • Technical Information: IP address, browser type, device identifiers, cookies.
  • Usage Data: pages visited, time spent on the site, interactions.
  • Inquiry or Quote Requests: details you provide when contacting us.

3. How We Use Your Information

We use the collected data to:

  • Provide and maintain our services
  • Communicate with you regarding inquiries or ongoing projects
  • Improve user experience and optimize our website
  • Ensure legal compliance and prevent fraud

4. Legal Bases for Processing (for EEA Users)

We process your personal data based on the following legal grounds:

  • Consent: when you submit a contact form or subscribe to updates
  • Contractual necessity: to fulfill obligations under a service agreement
  • Legitimate interests: to improve our services and ensure security

5. Sharing of Information

We do not sell your personal information. We may share it with:

  • Service providers (e.g., hosting, analytics, CRM) under confidentiality agreements
  • Legal authorities if required by law

6. Cookies

We use cookies and similar technologies to enhance site functionality and analyze traffic. You can manage cookie preferences in your browser settings.

Site measurement without cookies

Alongside the cookie-based tools above, we run our own visitor counter on our own servers. It sets no cookie and writes nothing at all to your device — no local or session storage, and no identifier. It records daily totals per page: how many times a page was opened, the approximate country a visit came from (as reported to us by our network provider, Cloudflare), and a general device type — desktop, mobile or tablet. Because these totals describe pages rather than people, this measurement is not covered by the cookie banner and runs regardless of the choice you make there.

So that a single visit is not counted twice, our server briefly recognises repeat requests using a one-way hash of your IP address, your browser’s user-agent and the page address. The secret used to create that hash is random, generated afresh every time our software restarts, and is never saved anywhere; the hash itself is held only in memory, for at most 30 minutes, and is never written to a database or a log file. The counter stores neither your IP address nor your user-agent. This also means our visitor numbers are approximate rather than exact.

We also record where a visit came from: the domain name of the site that linked to us — for example google.com or linkedin.com — and never the address of the page you were on. The words you type into a search engine, and the page you were reading before you arrived, are therefore never sent to us. If the link you followed carried campaign labels (utm_source, utm_medium, utm_campaign), we record those as well; we deliberately do not read per-click identifiers such as gclid or fbclid.

When you send us an enquiry through a form on this site, that same information — the referring domain, any campaign labels, and the first page you opened during your visit — is saved with your message, so that we can tell which channel brought you to us. It is kept for as long as the enquiry itself (see section 9). Statistics about the search terms that lead people to our website come from Google Search Console in aggregate form only, and are never linked to an individual visit or enquiry.

7. Data Security

We implement appropriate security measures to protect your personal data from unauthorized access, alteration, or destruction.

8. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccuracies
  • Request deletion
  • Object to or restrict processing
  • Withdraw consent at any time

To exercise your rights, please contact us at [email protected].

9. Data Retention

We retain personal information only as long as necessary for the purposes outlined above or to comply with legal obligations.

10. International Transfers

Your information may be transferred and processed outside your country of residence, including to servers in the EU or other jurisdictions where we or our service providers operate.

11. Third-Party Links

Our website may contain links to third-party sites. We are not responsible for their content or privacy practices.

12. Changes to This Privacy Policy

We may update this policy from time to time. Changes will be posted on this page with an updated effective date.

Contact Us

If you have questions about this Privacy Policy, contact us at [email protected].