GDPR Compliance Statement
Last updated: 8 April 2026
RADEVS OÜ is committed to protecting the personal data of our website visitors, clients, candidates and partners in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Estonian Personal Data Protection Act.
This statement outlines how we comply with GDPR and the measures we take to safeguard personal data.
1. Our Role
Depending on the context, RADEVS OÜ acts as either a Data Controller or a Data Processor:
- Data Controller — when we determine the purpose and means of processing (e.g. when you contact us through our website, when we manage our employees, or when we communicate with prospects).
- Data Processor — when we process personal data on behalf of our clients as part of our outstaffing and software development services, under a Data Processing Agreement (DPA).
2. Principles We Follow
We process personal data in line with the core principles of GDPR (Art. 5):
- Lawfulness, fairness and transparency — we process data only when we have a valid legal basis and clearly inform data subjects about it.
- Purpose limitation — we collect data for specific, explicit and legitimate purposes only.
- Data minimisation — we collect only the data we actually need.
- Accuracy — we keep data accurate and up to date.
- Storage limitation — we retain data only as long as necessary.
- Integrity and confidentiality — we protect data with appropriate technical and organisational measures.
- Accountability — we can demonstrate compliance with the above.
3. Legal Bases for Processing
We rely on the following legal bases under Art. 6 GDPR:
- Consent — for analytics cookies, marketing communication, and optional processing.
- Contract — to perform services under client and employment agreements, and for pre-contractual steps such as responding to inquiries.
- Legal obligation — to comply with tax, accounting and employment law.
- Legitimate interest — for limited internal purposes such as IT security and fraud prevention, always balanced against the rights of data subjects.
4. Data Subject Rights
We respect and facilitate the following rights for all data subjects:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time (Art. 7)
- Right not to be subject to automated decision-making (Art. 22)
- Right to lodge a complaint with a supervisory authority (Art. 77)
Requests can be submitted to office@ra-devs.com. We respond within 30 calendar days, as required by Art. 12(3) GDPR.
5. Technical and Organisational Measures
We apply appropriate technical and organisational measures to protect personal data, including:
Technical measures
- Encryption of data in transit (HTTPS/TLS) and at rest
- Access controls based on the principle of least privilege
- Strong password policies and multi-factor authentication for internal systems
- Regular software updates and security patches
- Backup and disaster recovery procedures
- Network security (firewalls, intrusion detection)
Organisational measures
- Confidentiality obligations for all employees and contractors
- Security awareness and GDPR training for staff
- Clear internal policies on data handling
- Data Processing Agreements with all processors
- Regular review of security practices and access rights
- Incident response procedures
6. Data Processors We Use
We work only with processors that provide sufficient guarantees of GDPR compliance. Each processor is bound by a Data Processing Agreement under Art. 28 GDPR. Our main processors include:
- DigitalOcean, LLC — website hosting (EU data centre in Frankfurt)
- Pipedrive OÜ — CRM system (EU-based, Estonian company)
- Google Ireland Ltd. — website analytics (Google Analytics 4)
A full list of processors can be provided on request.
7. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) as approved by the European Commission
- Supplementary technical measures such as encryption
- Assessment of the recipient country's legal framework (transfer impact assessments where required)
8. Data Breach Notification
In the unlikely event of a personal data breach, we follow a defined incident response procedure:
- Containing and investigating the breach without delay
- Notifying the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) within 72 hours where required by Art. 33 GDPR
- Informing affected data subjects where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR)
- Documenting the breach and our response
9. Records of Processing Activities
In line with Art. 30 GDPR, we maintain internal records of our processing activities, including the purposes, categories of data subjects and data, recipients, retention periods, and security measures. These records are available to supervisory authorities on request.
10. Data Protection Officer
RADEVS OÜ is not required to appoint a Data Protection Officer under Art. 37 GDPR, as our processing activities do not meet the criteria set out in that article. However, all GDPR-related inquiries can be directed to:
Email: office@ra-devs.com
Attn: Data Protection Contact
11. Supervisory Authority
The supervisory authority responsible for RADEVS OÜ is:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Website: www.aki.ee
Data subjects may also lodge complaints with the supervisory authority in their country of residence.
12. Contact
For any questions about our GDPR compliance or to exercise your rights:
RADEVS OÜ
Email: office@ra-devs.com
Address: Võru tn 11, Lasnamäe linnaosa, Tallinn 13612, Estonia
Registry code: 16555481