Privacy Policy
How we collect, use and protect the contact details and technical files you send us.
Tandix Group OÜ (“we”, “us”) respects your privacy and is committed to protecting the personal data you share with us through this website. This policy explains what we collect, why, how long we keep it, and the rights you have over it.
1. Data controller
Tandix Group OÜ (registry code 14785236, VAT EE101234567), located at Laevastiku 3S, 10313 Tallinn, Harjumaa, Estonia, is the data controller responsible for the personal data you submit through this website. You can reach us at rfq@tandix.ee or +372 58569319.
2. What personal data we collect
We collect only the personal data you voluntarily provide through the quote request (RFQ) form and the contact form on this website. This may include: your name, company name, email address, phone number, country, a description of the part or project, the requested quantity and material, any CAD or drawing files you upload (.step, .stp, .dxf, .pdf, .zip), and any additional comments or messages you include. If you submit a request for a non-disclosure agreement (NDA), we also process the information needed to prepare and sign that agreement.
3. Legal basis for processing
We process your personal data on the following legal bases under the EU General Data Protection Regulation (GDPR): (a) your consent, given when you check the GDPR consent box and submit a form (Article 6(1)(a)); (b) the processing is necessary to take steps at your request prior to entering into a contract — preparing a quotation (Article 6(1)(b)); and (c) our legitimate interests in responding to your enquiry, maintaining business records and protecting against disputes (Article 6(1)(f)).
4. Why we use your data
Your data is used solely to: review the manufacturability of your part, prepare a price quotation, reply to your enquiry, communicate about a potential or confirmed order, prepare and sign an NDA when requested, maintain records required by Estonian accounting and tax law, and protect our legitimate business interests. We do not sell your personal data, and we do not share it with third parties for their own marketing.
5. Technical files and confidentiality
Technical documentation — CAD models, drawings and specifications — is treated as commercially confidential and is shared only with the engineers and production staff directly involved in preparing your quotation. On request, we will sign a mutual NDA before receiving your files. Files are stored on access-controlled systems within the European Economic Area.
6. Recipients of your data
Your personal data and technical files are accessible to authorised employees of Tandix Group OÜ and, when strictly necessary to prepare a quotation, to trusted subcontractors and certified partners (for example, surface-treatment or material-testing providers) bound by confidentiality obligations. We do not transfer your data to parties outside this scope without your separate consent, except as required by law.
7. International transfers
As a rule, your data is processed within the European Economic Area. If a transfer to a third country becomes necessary (for example, because you are located outside the EEA or a partner is), it will take place only on the basis of an adequacy decision, Standard Contractual Clauses or another safeguard provided for by the GDPR. You may request a copy of the relevant safeguards by contacting us at the address below.
8. Retention
We keep enquiry data and files for as long as needed to handle your request and any resulting order, and afterwards for the retention period required by Estonian accounting law (generally seven years for accounting-relevant records). If no order results, we delete or anonymise your enquiry data and files within a reasonable period, no later than 24 months after your last contact with us, unless a longer retention is required by law.
9. Cookies
This website does not use advertising or tracking cookies. Any strictly necessary or functional cookies used are minimal and serve only to make the site work or remember your preferences (such as the selected language). You can clear cookies at any time through your browser settings. Because no tracking cookies are used, no consent banner is required.
10. Data security
We apply appropriate technical and organisational measures to protect your data: access control and authentication, encryption in transit, access logging, and regular review of who has access. Access to technical files and personal data is restricted to authorised staff on a need-to-know basis. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, the affected individuals without undue delay.
11. Your rights under the GDPR
As a data subject in the European Union, you have the right to: access your personal data (Article 15); request rectification of inaccurate data (Article 16); request erasure (the right to be forgotten) where applicable (Article 17); restrict or object to processing (Articles 18 and 21); request data portability (Article 20); and withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal. To exercise any of these rights, write to us at the contact address below.
12. Right to lodge a complaint
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), the supervisory authority in Estonia. Contact details are available at www.aki.ee. You may also seek a judicial remedy in the competent courts.
13. Changes to this policy
We may update this privacy policy to reflect changes in our practices or in applicable law. The “last updated” date below indicates when the policy was last revised. We encourage you to review this page periodically.
Contact
Tandix Group OÜ, Laevastiku 3S, 10313 Tallinn, Harjumaa, Estonia — rfq@tandix.ee — +372 58569319
