EverlumEverlum

Everlum Clinic private parking · Uuslinna 11

Separate terms govern client vehicle registration, control of spaces E1-E8, photo and GPS evidence, parking notices, and processing of data connected with parking claims.

Privacy Policy & Cookies

Controller: Delta Invest Group OÜ; data-protection contact — everlumclinic@gmail.com, +372 5566 4136; supervisory authority — Estonian Data Protection Inspectorate (AKI), Tatari 39, 10134 Tallinn.

Categories: guest or account data (first and last name, phone and/or email); request and booking data (service, practitioner, date and time, selected payment method and status); transactional notices and enquiries; health data (with explicit consent); technical logs, payments and cookies.

Purposes and legal bases (GDPR Arts 6 and 9): handling a request and creating or performing a booking or contract; securely managing schedules, resources, conflicts and operation evidence — contract, pre-contractual steps and legitimate interests; compliance with legal duties; separate consent for marketing, non-essential cookies and health data.

Guest booking and contact: an account and email or phone verification are not conditions for creating a booking. A first name, last name and at least one contact — phone or email — are sufficient. The contact is used to service the booking and provide transactional notice: by email or by manual phone contact; automated phone messaging is used only after the relevant channel is enabled. The contact is used for marketing only with separate consent.

Cookies/CMP: no non-essential cookies before consent.

Recipients: hosting, email/analytics/payment providers and AI providers receive only the data required for their service (DPAs in place). For payment initiation and confirmation, the necessary order and payment data are transmitted to Maksekeskus AS, which operates the MakeCommerce payment service and processes data under its own legal obligations. Outside EEA — SCC 2021/914 + TIA.

Retention: contact data are kept while needed for the booking, service, follow-up or dispute, then deleted. Booking records retained by law or for the defence of claims are separated from direct contact values and pseudonymised. Medical, payment and audit records are retained separately for the applicable mandatory periods; payment documents for 7 years and access or technical logs usually for 12–24 months.

Access and erasure: a request may be made using an email or phone number; to protect the data, we may verify the requester's identity. Where no other lawful duty applies, direct contact values are erased and retained records are pseudonymised. An active or future booking, unfinished notice, or mandatory medical, accounting or audit retention may limit immediate erasure of the relevant record, but does not permit using it for a new incompatible purpose.

Rights: access, rectification, erasure, portability, restriction, objection and withdrawal of consent; complaints may be submitted to the Estonian Data Protection Inspectorate (AKI).

AI assistant: informational replies; short chat logs to admin email only with separate consent.

Privacy Policy & Cookies · Everlum Legal