Effective date: 01.07.2026 · Last updated: 16.07.2026 (this version replaces the version of 14.07.2026)
Eesti keeles: Privaatsuspoliitika (Estonian original). This is a translation; the English translation may be updated with a delay, and in case of any conflict the Estonian version always prevails. This Privacy Policy explains how RATTURI KALA OÜ processes personal data in providing the website tarje.ee and the Tarje web-based point-of-sale and management system. The Policy has been drawn up in accordance with the European Union General Data Protection Regulation (GDPR), the Personal Data Protection Act (isikuandmete kaitse seadus, IKS) and the Electronic Communications Act (elektroonilise side seadus, ESS).
1. Definitions and scope
This Privacy Policy (hereinafter the Policy) describes how RATTURI KALA OÜ (hereinafter Tarje or we) processes personal data. The Policy is based on Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, hereinafter the GDPR), the Personal Data Protection Act (isikuandmete kaitse seadus, IKS) and the Electronic Communications Act (elektroonilise side seadus, ESS).
The Policy applies to:
- the website tarje.ee and its English-language version tarjepos.com (hereinafter the Website);
- the web-based point-of-sale and management system at pos.tarje.ee (hereinafter the Application; the Website and the Application together hereinafter the Service).
The following terms are used in the Policy:
- Client — a legal person (a restaurant, café, bar or other catering business) that uses the Service under a contract concluded with Tarje. The Service is intended solely for businesses (B2B).
- User — a natural person who uses the Service on behalf of the Client (e.g. the Client's representative, manager or employee).
- End Customer — a customer of the Client (e.g. a restaurant guest) whose data the Client enters into the Application in the course of its business activities.
- DPA — the data processing agreement applicable between Tarje and the Client within the meaning of Article 28 of the GDPR, available at tarjepos.com/dpa-en.html.
- Terms of Service — the terms governing the use of the Service, available at tarjepos.com/terms-en.html.
The Estonian-language version of the Policy prevails over all translations.
2. Controller and contact details
| Data field | Value |
|---|---|
| Business name | RATTURI KALA OÜ (private limited company) |
| Registry code | 17385866 |
| Registered address | Ratturi, Reigi küla, Hiiumaa vald, Hiiu maakond 92265 |
| VAT number | Not registered for VAT |
| info@tarje.ee |
Tarje has not appointed a data protection officer (DPO), as the appointment obligation under Article 37 of the GDPR does not apply to Tarje. Tarje responds to all data protection enquiries at info@tarje.ee.
3. Tarje's roles — controller and processor
Tarje's role in data protection depends on which data are processed and in what context:
| Data context | Tarje's role | Client's role |
|---|---|---|
| Visiting the Website, enquiries and correspondence, creating and managing a Tarje account, billing, customer support, security of the Service | Controller | — |
| End Customer data entered by the Client into the Application (e.g. orders, loyalty customers, gift cards, e-invoice recipients) and work-related data of the Client's employees in the Application (e.g. shifts, sales transactions broken down by user) | Processor | Controller |
In respect of processing carried out as a processor, Tarje processes data solely on the basis of the Client's documented instructions. A data processing agreement (DPA) under Article 28 of the GDPR applies between the parties and is available at tarjepos.com/dpa-en.html. If you are an End Customer or an employee of a Client and wish to obtain information about the processing of your data in the Application, please first contact the controller — i.e. the restaurant, café or bar serving you. Tarje assists the Client in responding to such requests in accordance with the procedure agreed in the DPA.
4. Categories and sources of the personal data processed
4.1. Data you provide to us yourself
- Account and contact data — name, e-mail address, company details, user role and login details that you provide when creating an account (including when starting the 14-day trial period) or via the forms on the Website.
- Authentication data — password (stored only in hashed form) and two-factor authentication (2FA) factors, where the User has enabled 2FA.
- Correspondence — enquiries and customer support requests sent to info@tarje.ee or through the Service.
4.2. Data we receive from the Client (your employer)
- Where the Client creates a User account for its employee, Tarje receives the employee's name, e-mail address and role from the Client, not from the data subject themselves. In such a case the source of the information is the Client (Article 14 of the GDPR).
4.3. Data collected automatically
- Usage and log data — technical information about the use of the Service: IP address, device and browser details, login times, activity logs and device error logs (application error reports). These are used to ensure the security, operation and development of the Service.
- Technical data of the Website — when the Website is displayed, the visitor's IP address is technically processed by Tarje's web server. All Website content, including fonts, is served from Tarje's own server; no third-party font or content services are used (see sections 6 and 8).
4.4. Billing data
- The plan subscribed to, payment history and invoices. Card payments are processed via the payment service provider Stripe; Tarje does not store card details. Stripe transmits to Tarje the payment status and the data necessary for billing.
4.5. Data that Tarje processes as a processor
- Data that the Client enters into the Application in the course of its business activities: orders, loyalty and customer relationship data, gift card (QR/PIN) data, data of recipients of e-invoices and e-receipts, and work-related data of the Client's employees. In respect of these data the controller is the Client (see section 3).
Whether provision of data is mandatory: the provision of account and billing data is a precondition for concluding and performing the contract. If these data are not provided, Tarje cannot provide the Service. The provision of other data (e.g. marketing consent) is voluntary.
Tarje does not knowingly collect or process special categories of personal data within the meaning of Article 9 of the GDPR.
5. Purposes and legal bases of processing
Tarje processes personal data as a controller for the following purposes and on the following legal bases:
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing an account, providing the Service, enabling the 14-day trial period | Performance of a contract and pre-contractual measures (Article 6(1)(b)) |
| Processing payments and billing | Performance of a contract (Article 6(1)(b)) |
| Accounting and compliance with tax obligations | Legal obligation (Article 6(1)(c)) — Accounting Act (raamatupidamise seadus), tax legislation |
| Ensuring the security, operation and development of the Service, security logs, detecting and fixing errors, fraud prevention | Legitimate interest (Article 6(1)(f)) — the interest of Tarje and its Clients in a secure and reliable Service |
| Customer support and notifications about the Service (e.g. maintenance, significant changes) | Performance of a contract / legitimate interest (Article 6(1)(b) and (f)) |
| Displaying the Website (including serving fonts from Tarje's own server) and remembering the language preference | Legitimate interest (Article 6(1)(f)) — providing a consistent and usable Website |
| Marketing communications (where applicable) | Consent (Article 6(1)(a)) |
| Establishing, exercising and defending legal claims | Legitimate interest (Article 6(1)(f)) |
Where consent has been given, the data subject has the right to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal. The data subject has the right to object to processing based on legitimate interest (see section 10).
6. Cookies, localStorage and similar technologies
The information under this section is provided to comply with the requirements of § 102¹ of the ESS and the GDPR.
6.1. The website tarje.ee
- The Website does not use analytics or advertising cookies or any other tracking technologies.
- The Website stores the visitor's language preference in the browser's localStorage in order to display the page in the chosen language (the Website is available in 23 languages). This is functional storage necessary for providing a service requested by the user within the meaning of § 102¹ of the ESS; no separate consent is required for it. The language preference is retained only on the visitor's own device and is not transmitted to Tarje's servers.
- The Website's fonts are served from Tarje's own server. The Website does not use Google Fonts or any other third-party font or content services, which means that when fonts are loaded, the visitor's IP address and other data are not transmitted to any third party.
6.2. The application pos.tarje.ee
- The Application uses necessary cookies and similar technologies to maintain the login session and to ensure security. These are strictly necessary for the operation of the Service and do not require consent.
- When a payment is made, Stripe creates a payment session and may set cookies that are necessary for the secure processing of the payment and for fraud prevention.
- The Application stores data in the device's cache to allow sales to continue even if the internet connection is interrupted; once the connection is restored, the data are synchronised with the server.
6.3. Management
Visitors can manage and delete cookies and localStorage entries in their browser settings. Disabling necessary technologies may restrict or prevent the operation of the Service. If Tarje introduces cookies requiring consent in the future (e.g. analytics), consent will be requested in advance and this Policy will be updated.
7. Recipients of data and processors
To provide the Service, Tarje uses the following service providers, who process personal data on Tarje's instructions and in accordance with applicable data protection requirements:
| Service provider | Role / purpose |
|---|---|
| Supabase | Database and cloud hosting |
| Stripe | Payment processing |
| Resend | Sending e-mails (including, on the Client's instruction, e-receipts and invoices to End Customers) |
| veebimajutus.ee (Elkdata OÜ) | Hosting and domain, DNS and e-mail infrastructure |
The Website's fonts are served from Tarje's own server; no third-party services (e.g. Google Fonts) are used for loading fonts, and there is no additional recipient of data in that regard.
Tarje concludes the necessary data processing agreements with its processors, ensuring an appropriate level of protection of personal data. The sub-processors used in the processing of Client data carried out by Tarje as a processor are listed in the DPA (tarjepos.com/dpa-en.html).
In addition, Tarje may transfer data to:
- the Merit Aktiva accounting software — only where the Client has itself activated the Merit integration; in that case the sales and invoice data specified by the Client are transferred, at the Client's initiative and on the Client's instruction, to the Client's Merit account;
- competent public authorities (e.g. the Estonian Tax and Customs Board (Maksu- ja Tolliamet), courts, law enforcement authorities), where the obligation to transfer arises from legislation;
- legal, audit or other advisers, where necessary to protect Tarje's rights, subject to a duty of confidentiality.
Tarje does not sell personal data and does not share them with third parties for marketing purposes.
8. Transfers of data outside the EU/EEA
Personal data are, as a rule, processed within the European Union or the European Economic Area (EU/EEA).
Tarje's database (Supabase) is located in the European Union (Frankfurt, AWS eu-central-1), which means that Client and User data are not regularly transferred outside the EU/EEA. The provider of hosting and of domain, DNS and e-mail infrastructure, veebimajutus.ee (Elkdata OÜ), is located in Estonia (EU). The Website's fonts are served from Tarje's own server, which means that no transfer of data to third parties or to third countries takes place in connection with the loading of fonts.
Some of the service providers named in section 7 are groups with ties to the United States, which means that part of the processing may also take place outside the EU/EEA. In such cases Tarje applies safeguards in accordance with Chapter V of the GDPR:
- Stripe and Resend — where processing takes place outside the EU/EEA, the transfer is based on the Standard Contractual Clauses (SCCs) approved by the European Commission, together with supplementary safeguards where necessary (Article 46 of the GDPR), as also set out in the list of sub-processors in the DPA (tarjepos.com/dpa-en.html).
The data subject has the right to obtain further information about the safeguards applied and a copy of them by contacting info@tarje.ee.
9. Retention periods
Tarje retains personal data only for as long as necessary to fulfil the purposes of processing or as required by legislation:
| Category of data | Retention period |
|---|---|
| Account and usage data | For the duration of the contract and for a reasonable period after its termination — until the data are exported and deleted in accordance with the Terms of Service |
| Correspondence and customer support requests | Up to 3 years from the last communication — for resolving requests and handling potential claims (legitimate interest) |
| Accounting source documents and invoices | 7 years from the end of the financial year in which the business transaction was recorded in the accounting records on the basis of the source document (§ 12 of the Accounting Act (raamatupidamise seadus)) |
| Log and security data | For a limited period for the purpose of ensuring security — up to 12 months from the creation of the log entry |
| Backups | Up to 60 days; backups are deleted through automatic rotation |
| Data relating to the contract and potential claims | Until the expiry of the limitation period for legal claims |
| Data of End Customers and the Client's employees (processing as a processor) | In accordance with the Client's instructions and the DPA; upon termination of the contract the data are returned or deleted in the manner set out in the DPA |
Upon expiry of the retention period, the data are deleted or anonymised.
10. Rights of the data subject
Under Articles 15–22 of the GDPR, the data subject has the following rights:
- the right of access to their personal data and to obtain a copy of them (Article 15);
- the right to rectification of data that are inaccurate or incomplete (Article 16);
- the right to erasure ('right to be forgotten'), where a legal ground for erasure exists (Article 17);
- the right to restriction of processing in the cases provided by law (Article 18);
- the right to data portability in a structured, commonly used and machine-readable format (Article 20); in the Service, data can also be exported in CSV and Excel formats;
- the right to object to processing based on legitimate interest (Article 21);
- the right to withdraw consent, where processing is based on consent (Article 7(3));
- the right not to be subject to a decision based solely on automated processing (Article 22; see section 11).
To exercise these rights, please contact info@tarje.ee. Tarje responds to a request without undue delay and at the latest within one month; in the case of complex or numerous requests, the period may be extended by two months, with the applicant being notified of the extension. Fulfilling a request is, as a rule, free of charge. Tarje may request additional information necessary to verify the identity of the applicant.
Where the personal data have been entered into the Service by the Client and Tarje acts as a processor in respect of them, the request is referred to the controller (the Client), and Tarje assists the Client in fulfilling the request in accordance with the DPA.
If you consider that Tarje is processing your personal data unlawfully, we recommend that you first contact Tarje at info@tarje.ee. You also have the right at any time to lodge a complaint with the supervisory authority — the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) — and to bring proceedings before a court to protect your rights (Articles 77–79 of the GDPR).
11. Automated decisions and profiling
Tarje does not make decisions concerning data subjects based solely on automated processing that would produce legal effects concerning the data subject or similarly significantly affect them (Article 22 of the GDPR), and does not use personal data for profiling.
12. Security of personal data and breach notification
Tarje implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction (Article 32 of the GDPR). These measures include, among others:
- encryption of data in transit;
- storage of passwords only in hashed form and the option of two-factor authentication (2FA);
- restriction of access rights on a need-to-know basis;
- secure hosting with trusted service providers;
- regular backups and their automatic rotation;
- maintenance and monitoring of security logs.
However, no method of data transmission or storage is completely secure. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, Tarje will notify the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 of the GDPR). Where the breach is likely to result in a high risk, Tarje will also notify the affected data subjects (Article 34 of the GDPR). Acting as a processor, Tarje will notify the Client of a breach in the manner set out in the DPA.
13. Children's data
The Service is intended solely for businesses (B2B) and is not directed at children. Tarje does not knowingly collect or process the personal data of children under the age of 13. If Tarje becomes aware that a child's personal data have been provided to it without a legal basis, it will delete them within a reasonable time.
14. Amendments to the Privacy Policy
Tarje has the right to update this Policy from time to time, for example in connection with the development of the Service, changes of service providers or changes in legislation. The current version is always published at tarjepos.com/privacy-en.html. Clients will be notified of material changes a reasonable time in advance through the Service or by e-mail.
This Policy entered into force on 01.07.2026. Last updated: 16.07.2026 (replaces the version of 14.07.2026; the main changes — clarification of the description of cookies and localStorage, confirmation that the Website's fonts are served from Tarje's own server without third-party services, and alignment of the information on recipients and third-country transfers with the data processing agreement).