Privacy Policy
Effective Date: August 20, 2025
1. Introduction
Welcome to Nextartive OÜ and our services at thinkartive.com. Protecting your privacy is a top priority for us. This Privacy Policy (“Policy”) explains how we collect, use, and safeguard your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable laws. Please read it carefully and contact us if you have any questions.
2. Applicability
This Policy applies to all users accessing or using the Nextartive OÜ website and services. By using our services, you agree to the terms outlined here. If you do not agree, please stop using our services.
3. About the Data Controller
Nextartive OÜ (Reg. no. 17304784),
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Parda tn 6, 10151, Estonia,
is the data controller responsible for your personal data processing under this Policy.
Contact: support@thinkartive.com
4. Data We Process
We collect and process personal data, including but not limited to:
- Contact information: email, phone, address;
- Account details: username, login data, preferences;
- Identity verification: name, date of birth, ID documents;
- Authentication data: multi-factor authentication details;
- Payment and financial data: payment cards, transaction history;
- Legal compliance data: AML/KYC documentation, sanctions screening;
- Technical data: IP address, device, browser type, usage logs;
- Support communications: emails, chats, calls;
- Marketing preferences: subscription choices;
- Claims and disputes data;
- Surveillance data: if applicable at office premises.
5. How We Collect Data
- Directly from you: during registration, purchases, or communication;
- From third parties: such as payment providers, authorities, analytics services.
6. Purposes and Legal Bases for Processing
We process your data based on the following purposes and legal grounds:
- Account creation and management – Legal basis: Contractual necessity.
- Service delivery and order fulfilment – Legal basis: Contractual necessity.
- Identity verification and authentication – Legal basis: Legal obligation, legitimate interest.
- Payment processing – Legal basis: Contractual necessity, legitimate interest.
- Customer support and communication – Legal basis: Contractual necessity, legitimate interest.
- Legal and regulatory compliance (e.g., AML) – Legal basis: Legal obligation, public task.
- Business risk management – Legal basis: Contractual necessity, legal obligation, legitimate interest.
- Marketing and personalized content – Legal basis: Consent, legitimate interest.
- Service improvement – Legal basis: Legitimate interest.
- Technical troubleshooting – Legal basis: Contractual necessity.
- Fraud prevention – Legal basis: Legal obligation, legitimate interest.
- Security assurance – Legal basis: Contractual necessity, legal obligation, legitimate interest.
- Claims and dispute resolution – Legal basis: Contractual necessity, legal obligation, legitimate interest.
7. Who Can Receive Your Data
Your personal data may be shared with:
- Service providers and partners assisting us (e.g., payment processors);
- Competent governmental or regulatory authorities;
- Other parties, if you instruct us or when legally required.
8. International Data Transfers
Data is primarily processed within the EU/EEA. If transferred outside these areas, we ensure appropriate safeguards are in place according to applicable laws to protect your data.
9. Data Retention
We keep your data only as long as necessary for the purposes stated or as required by law (e.g., AML, accounting). When no longer needed, your data is securely deleted or anonymized.
10. Data Security
We use technical and organizational measures such as encryption, access controls, audits, and staff training to protect your personal data. You also share responsibility by using strong passwords and securing your devices.
11. Why You Need to Provide Data
- Mandatory data: Needed to perform the contract and comply with the law. Without it, you may be unable to use certain services.
- Optional data: Voluntary information to improve your experience or marketing. You can withdraw consent anytime without losing core service access.
12. Your Rights
Under GDPR, you have the right to:
- Access your personal data;
- Correct inaccuracies;
- Request deletion (where lawful);
- Restrict processing;
- Object to processing (e.g., marketing);
- Withdraw consent;
- Data portability (receive your data in a machine-readable format).
We may ask for proof of identity before fulfilling your requests. Note some rights may be limited by law.
13. Automated Decision-Making and Profiling
We may use automated processes to:
- Detect and prevent fraud (e.g., suspending suspicious transactions);
- Offer personalized recommendations;
- Profile user preferences to enhance your experience.
We aim for transparency and fairness in these processes.
14. Complaint and Dispute Resolution
If you have concerns about data processing, contact us at support@thinkartive.com. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate.
15. Updates to This Policy
We may update this Privacy Policy from time to time. Changes take effect upon posting on our website. We encourage you to review it periodically. Significant changes may be notified directly.
16. Contact Information
For questions or to exercise your rights, contact:
Nextartive OÜ
support@thinkartive.com
Harju maakond, Tallinn, Kesklinna linnaosa, Parda tn 6, 10151, Estonia