Privacy policy
Last updated: 4 April 2026
This privacy policy explains how Hololife Center OÜ (“we”, “us”) processes personal data when you visit www.hololife.ee (the “website”) and when you use our contact, event registration, or trial application forms. We process personal data in accordance with Regulation (EU) 2016/679 (“GDPR”) and the Estonian Personal Data Protection Act.
Data controller and contact
The data controller is Hololife Center OÜ, registry code 14867168, registered office Tööstuse 43-100, 10411 Tallinn, Estonia.
To exercise data subject rights or ask about processing, use the contact form or the contact details in the site footer and indicate “Data protection” in the subject or message so we can handle your request without delay.
Online identifiers and optional analytics or advertising
Strictly necessary technologies (which may include cookies or local storage) are used so the website functions and so we can honour your choices about optional processing.
If you give consent, we deploy Google Tag Manager and related services such as Google Analytics for aggregated traffic analysis, and the Meta Pixel for measuring advertising performance. Those services may process online identifiers and usage data according to their own terms and, where applicable, as independent controllers. Consent is obtained through the first-layer banner and can be changed later via “Cookie preferences” in the footer; withdrawal applies prospectively.
Personal data collected through website forms
When you submit our contact, event registration, or free trial application forms, we process the information you enter (such as name, email address, phone number if provided, and the content of your message or registration details).
Purposes and legal bases (GDPR Art 6):
- Handling your request or registration — to respond to enquiries, manage event participation, and process trial applications. This is necessary for steps taken at your request prior to a possible contract and/or for the performance of our agreement with you, or where applicable on the basis of our legitimate interest in communicating with prospective members and visitors.
- Service emails — such as confirmations related to your submission, on the same bases as above.
- Marketing and newsletters — only if you opt in. This is based on consent, which you may withdraw at any time without affecting the lawfulness of processing before withdrawal. We may use a marketing platform (such as Klaviyo) to send messages and manage subscriptions in line with your choices.
Recipients and processors: We use trusted service providers who process data on our instructions (processors), including for website hosting (e.g. Netlify), email delivery, and — if you opt in — email marketing (e.g. Klaviyo). Analytics and advertising tools (Google / Meta) operate as separate controllers or processors depending on the product; their use of data is described in their privacy notices when those tools are activated with your consent.
Transfers outside the EEA: Some providers may process data in the United States or other countries. Where required, we rely on appropriate safeguards under GDPR Chapter V (such as the European Commission’s standard contractual clauses and, where applicable, supplementary measures) or other lawful transfer mechanisms.
Retention: We keep form and registration data only as long as needed for the purposes above, including statutory limitation periods, accounting or tax obligations where relevant, and to establish or defend legal claims. Marketing data is kept until you unsubscribe or withdraw consent and for a short period thereafter to evidence your preferences, unless a longer period is required by law.
Security: We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, or unlawful processing, taking into account the nature of the processing and the risks involved.
Automated decision-making: We do not use solely automated decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you in connection with the website or the forms described here.
Your rights
If you are in the European Economic Area (including Estonia) or otherwise covered by the GDPR, you have the right to request access to your personal data, rectification of inaccurate data, erasure in certain cases, restriction of processing, data portability where processing is based on consent or contract and carried out by automated means, and to object to processing based on legitimate interests (including profiling). Where processing is based on consent, you may withdraw consent at any time.
These rights are not absolute; exceptions may apply under applicable law.
To exercise these rights, contact us using the contact details in the “Data controller and contact” section. We may need to verify your identity before responding. We will respond within one month, which may be extended by up to two further months where the request is complex; we will inform you of any extension.
Right to lodge a complaint: If you believe our processing infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Estonia, the supervisory authority is the Data Protection Inspectorate (Andmekaitse Inspektsioon). If you reside in another EEA country, you may instead contact the supervisory authority there.
Changes
We may update this privacy policy from time to time. The “Last updated” date at the top will be revised when we do. Material changes may also be signposted on the website where appropriate.