Privacy Policy
LEI Universal OÜ (hereinafter “LEI Universal”) values your privacy and complies with all applicable data protection laws and regulations. This privacy policy explains what personal data we collect, how we use it and what your rights are.
We process data in accordance with the EU General Data Protection Regulation (GDPR), the Estonian Personal Data Protection Act and other privacy laws that apply to our services.
Data controller
For any privacy-related questions, please contact us at the email address above.
What data we collect
We collect data both directly from you (for example, when submitting an LEI application) and automatically when you visit our website.
- Personal data — first and last name, email address, postal address, phone number and communication history.
- Company data — legal entity name, address, legal form, registry number and information about any parent company. This data is shared with the LEI issuer (LOU) and GLEIF for the purpose of LEI registration.
- Payment data — transaction amount and reference number. We do not store card transaction details (such as card numbers) — these are processed in a secure environment by our payment service provider.
- Technical data — IP address, browser type and version, pages visited, time of visit and other log data transmitted by your browser.
- LoA signing data — the signatory’s name, email address and role, drawn electronic signature, signature stroke data, signing time, IP address, browser information, consent wording, the signed Letter of Authorization and its audit record.
Why and on what legal basis we process data
We always have a legal basis for processing personal data. The main grounds are:
- Performance of a contract (GDPR Art. 6(1)(b)) — registering, renewing and transferring LEI numbers, signing a Letter of Authorization, and client communications.
- Legal obligation (GDPR Art. 6(1)(c)) — providing GLEIF with the required data and meeting obligations under accounting and tax laws.
- Legitimate interest (GDPR Art. 6(1)(f)) — ensuring website security, preventing fraud and improving our service.
- Consent (GDPR Art. 6(1)(a)) — use of analytics and advertising cookies and marketing communications. You can withdraw consent at any time.
Who we share data with
We share your data with third parties only in the following cases and only to the extent necessary:
- LEI issuer (LOU) — RapidLEI (Ubisecure Oy, Finland). Company data and, where required, the signed Letter of Authorization and its audit record are shared for LEI registration, transfer and management.
- GLEIF — Global Legal Entity Identifier Foundation (Switzerland). LEI data is published in GLEIF’s public global registry.
- Payment service providers — Stripe and PayPal. Transaction data is shared for payment processing.
- IT and infrastructure providers — server hosting, website analytics and customer management tools.
- Public authorities — where required by law.
Some of our service providers (for example Stripe and Google) may process data outside the European Economic Area (EEA). In such cases, we use appropriate safeguards required by applicable data protection law, such as the European Commission’s Standard Contractual Clauses.
How long we retain data
- LEI number data — retained for the full validity period of the LEI number. Data linked to an LEI number remains in the GLEIF public registry permanently.
- Accounting records — 7 years, in accordance with the Estonian Accounting Act.
- Signed Letter of Authorization and audit record — for as long as needed to demonstrate authority, perform the contract and resolve potential claims, taking account of applicable limitation and record-keeping periods.
- Client communications history — up to 3 years from the last contact.
- Contact form data — up to 1 year if no client relationship develops afterwards.
- Cookies and website logs — in line with the settings of each service (Google Analytics up to 14 months, server logs up to 12 months).
Your rights
Under the GDPR and other applicable privacy laws, you may have the following rights regarding your personal data:
- Access — obtain a copy of the data we hold about you.
- Rectification — request the correction of inaccurate or incomplete data.
- Erasure — request the deletion of your data under certain conditions.
- Restriction of processing — request the restriction of data processing under certain conditions.
- Data portability — receive your data in a structured, commonly used format and transfer it to another controller.
- Object — object to processing based on legitimate interest, including direct marketing.
- Withdraw consent — withdraw any previously given consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights, please email us at [email protected]. We will respond to your request within one month at the latest.
If you believe the processing of your data breaches data protection law, you have the right to lodge a complaint with a supervisory authority:
- In Estonia — Estonian Data Protection Inspectorate (AKI), aki.ee, Tatari 39, 10134 Tallinn.
Data security
We apply reasonable technical and organizational measures to protect your data against unauthorized access, loss, misuse or alteration. Please note that no method of transmitting information over the internet is 100% secure.
Use of cookies
The website leiuniversal.ie uses cookies — small text files that are stored on your device when you visit the site. Cookies help remember your actions and preferences to provide a better user experience.
Types of cookies we use
- Functional cookies — strictly necessary for the correct operation of the website (for example, shopping cart functionality, saving consent preferences). No consent is required for their use.
- Analytics cookies — help us understand how visitors use our website. We ask for your consent to use these cookies.
- Advertising cookies — help measure the performance of our advertising campaigns, including Google Ads conversions. We ask for your consent to use these cookies.
Services that set cookies on our website
- WordPress and WooCommerce — our website and e-commerce platforms, which use functional cookies for core functionality.
- Cookie consent tool — stores your consent preferences.
- Google Analytics — website analytics used only with your consent.
- Google Ads — advertising measurement used only with your consent.
- Stripe and PayPal — payment providers that may use necessary cookies for secure transaction processing and fraud prevention.
- Crisp — customer-support chat that uses functional cookies to provide the chat service.
Managing consent
When you first visit our website, a cookie banner will appear, allowing you to accept or decline analytics and advertising cookies. You can change your preferences at any time by clicking the cookie icon in the corner of the website.
Links to other websites
Our website may contain links to other websites. We have no control over third-party sites and accept no responsibility for their content or privacy practices.
Updates to this privacy policy
We reserve the right to update this privacy policy as needed. For significant changes, we will notify you by email or prominently on the website. For minor changes, we will update only the date below.