European Power Solutions Estonia OÜ, a private limited company incorporated under the laws of the Republic of Estonia under registration code 12895367, with its registered office at Viru väljak 2, Kesklinna linnaosa, Tallinn, Harju maakond, 10111, Estonia (hereinafter “EPSE”, “we”, “us” or “our”), is the controller of personal data processed in connection with this website (www.epse.ee) and its commercial operations as an industrial trading company. We may be contacted at info@epse.ee or +372 6307700 for any matter relating to personal data, including the exercise of the rights described in this policy.
This Privacy Policy explains, in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter “GDPR”), the Estonian Isikuandmete kaitse seadus (Personal Data Protection Act, hereinafter “IKS”), and § 102¹ of the Elektroonilise side seadus (Electronic Communications Act) so far as it concerns cookies and similar tracking technologies, what personal data we collect, on what legal basis we process it, with whom we share it, for how long we retain it, where it may be transferred, and which rights you may exercise in relation to it. We have not appointed a Data Protection Officer because we do not meet the criteria set out in Article 37(1) of the GDPR; all data protection matters are handled directly by our management, reachable at the contact details above.
We process personal data of four principal categories of data subjects. The first category consists of visitors to our website, in respect of whom we process technical data automatically generated by the use of the site (IP address, browser type and version, operating system, referrer URL, pages viewed, date and time of visit, and similar log data), information voluntarily submitted through our contact form (name, email address, and the content of the message), and data collected through analytics and advertising technologies described in the section on cookies below. The second category consists of representatives, contact persons and authorised signatories of our business counterparties (suppliers, manufacturers, industrial buyers, freight forwarders, customs brokers, banks, insurers, auditors and professional advisers), in respect of whom we process name, position, employer, business contact details (email, telephone, postal address), correspondence, and any further information necessary for the performance of the relevant commercial transaction. The third category consists of beneficial owners and authorised representatives of corporate counterparties, in respect of whom, where required by anti-money-laundering legislation applicable to EPSE, by the customer due diligence procedures of our banks, or by sanctions and export-control screening duties incumbent upon EPSE as an EU operator, we may process identification data (full name, date of birth, citizenship, country of residence, identification document data, signature, beneficial ownership share) and information obtained through standard due diligence checks. The fourth category consists of recipients and senders of our commercial correspondence and any other natural person whose personal data is contained in invoices, contracts, transport documents, customs declarations or related logistics documentation.
We do not knowingly collect, and the website is not directed at, persons under the age of 16. We do not process special categories of personal data within the meaning of Article 9 of the GDPR. We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning data subjects or similarly significantly affect them within the meaning of Article 22 of the GDPR.
Each processing activity is conducted on a lawful basis as required by Article 6(1) of the GDPR. The processing of contact form submissions and any pre-contractual correspondence is carried out on the basis of Article 6(1)(b) (taking steps at the request of the data subject prior to entering into a contract) and, where the enquiry originates from a corporate representative rather than the data subject acting in personal capacity, on the basis of Article 6(1)(f) (the legitimate interests of EPSE in responding to commercial enquiries and conducting its trading activity). The processing of personal data necessary for the negotiation, conclusion and performance of supply, procurement, logistics and ancillary contracts is carried out on the basis of Article 6(1)(b) where the counterparty is a natural person, and on the basis of Article 6(1)(f) where the counterparty is a legal person and we process personal data of its representatives, with our legitimate interest being the conduct of B2B commercial operations. The processing of personal data for the purposes of complying with bookkeeping, tax, customs, export control and sanctions obligations applicable to EPSE as an Estonian and EU operator is carried out on the basis of Article 6(1)(c), with reference in particular to the Raamatupidamise seadus (Accounting Act), the Maksukorralduse seadus (Taxation Act), Regulation (EU) No 952/2013 (Union Customs Code), Council Regulation (EU) 2023/1529 and the consolidated EU sanctions framework. The processing of identification data of beneficial owners and authorised representatives for anti-money-laundering and counter-terrorist-financing purposes is carried out, depending on the applicable regime, either on the basis of Article 6(1)(c) where EPSE is subject to direct statutory obligations under the Rahapesu ja terrorismi rahastamise tõkestamise seadus, or on the basis of Article 6(1)(f) where such processing is necessary to comply with the customer due diligence requirements imposed on EPSE by its banks and other regulated counterparties, our legitimate interest in both cases being the prevention of unlawful conduct and the maintenance of access to essential banking and financial services. The processing of technical website data and the establishment, exercise or defence of legal claims is carried out on the basis of Article 6(1)(f), our legitimate interest being respectively the security and proper functioning of our website and the protection of our legal position. Where we rely on consent, including in respect of non-essential cookies, analytics, advertising technologies, and any direct marketing communications, the legal basis is Article 6(1)(a), and such consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Personal data is obtained primarily from the data subject directly, either through the website contact form, through email and telephone correspondence, or in the course of contractual negotiations. Where personal data is obtained indirectly, the sources are typically the employer of the data subject (for example, when a company introduces its representative as a contact person), publicly available registers such as the Estonian Commercial Register (e-äriregister) and equivalent registers in the jurisdictions of our counterparties, sanctions and politically-exposed-persons screening databases operated by reputable providers, and banking institutions performing customer due diligence on our behalf or in parallel with us.
We disclose personal data only to a limited number of recipients and only to the extent necessary for the purposes set out above. The recipients are: our hosting provider, which operates the servers on which this website and the personal data submitted through it are stored; our email and office productivity service providers; the providers of analytics and advertising technologies referred to in the cookies section below, including Google Ireland Limited (Google Analytics) and LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag), each acting as a separate or joint controller in respect of the data they collect through their services in accordance with their own privacy policies; our accountants and auditors; our external legal advisers; banks and payment service providers processing settlements related to our supply transactions; logistics, freight forwarding, customs and insurance providers involved in the cross-border transportation of goods; competent public authorities of the Republic of Estonia and the European Union, in particular the Tax and Customs Board (Maksu- ja Tolliamet), the Data Protection Inspectorate (Andmekaitse Inspektsioon), the Financial Intelligence Unit (Rahapesu Andmebüroo) where applicable, and any court or law-enforcement authority exercising lawful powers; and our manufacturers, suppliers and industrial buyers to the extent strictly required for the performance of the relevant transaction. All processors acting on our instructions are bound by written agreements meeting the requirements of Article 28 of the GDPR. We do not sell personal data, and we do not disclose it for marketing purposes of third parties.
Because EPSE relies on a hosting provider established in Ukraine for the operation of this website, and because our commercial activity involves the supply of industrial electrical equipment to industrial partners in Ukraine and Azerbaijan and the sourcing of equipment from manufacturers established in Switzerland, Italy, Spain and Poland, personal data is in a number of cases transferred outside the European Economic Area. Transfers to Switzerland take place on the basis of the European Commission’s adequacy decision of 26 July 2000, as confirmed and updated, so no additional safeguards are required. Transfers to the United States in connection with the use of analytics and advertising services provided by Google and LinkedIn take place on the basis of the European Commission’s adequacy decision of 10 July 2023 establishing the EU-US Data Privacy Framework, to which both Google LLC and LinkedIn Corporation are certified. Transfers to Ukraine, both to our hosting provider and to our industrial counterparties, and transfers to Azerbaijan in connection with the supply of equipment, take place in the absence of an adequacy decision on the basis of the appropriate safeguards provided for in Article 46 of the GDPR, specifically the Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914 of 4 June 2021, supplemented by appropriate technical and organisational measures designed to ensure a level of protection of personal data essentially equivalent to that guaranteed within the European Union, including in particular encryption in transit, access controls, contractual confidentiality obligations and data minimisation. Where neither an adequacy decision nor Article 46 safeguards can be relied upon in respect of a specific transfer, that transfer is made only on the basis of a derogation under Article 49 of the GDPR, in particular where the transfer is necessary for the performance of a contract between the data subject and the controller, for the conclusion or performance of a contract concluded in the interest of the data subject, or for the establishment, exercise or defence of legal claims. A copy of the safeguards relied upon for a specific transfer may be obtained on request to info@epse.ee.
Personal data is retained only for as long as necessary for the purposes for which it was collected, after which it is deleted or anonymised. Contact form messages and related correspondence that do not lead to a contractual relationship are retained for up to 12 months from the last communication, after which they are deleted unless a longer retention period is justified by the establishment, exercise or defence of legal claims. Personal data contained in accounting source documents (invoices, contracts, transport documents and related records) is retained for seven years from the end of the financial year to which the document relates, in accordance with § 12 of the Raamatupidamise seadus. Personal data processed for customer due diligence purposes in the context of anti-money-laundering and counter-terrorist-financing requirements is retained for the period prescribed by the applicable legislation and by the procedures of our banking counterparties, which is, in the case of direct obligations under § 47 of the Rahapesu ja terrorismi rahastamise tõkestamise seadus, five years from the termination of the business relationship or the completion of the occasional transaction, with a possible extension of up to five additional years where required by the competent authority. Personal data relevant to the establishment, exercise or defence of legal claims is retained for the duration of the applicable limitation period under Estonian law, in particular the three-year period set out in § 146(1) of the Tsiviilseadustiku üldosa seadus for contractual claims, extended where a longer period applies under the specific contract or the law. Server logs are retained for up to 12 months for security and troubleshooting purposes. Once the relevant retention period has expired, data is securely deleted or irreversibly anonymised.
We implement appropriate technical and organisational measures within the meaning of Article 32 of the GDPR to ensure a level of security appropriate to the risk, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. These measures include encrypted transmission of data over the website (TLS), access controls and role-based permissions for internal systems, restricted access to physical and electronic records, contractual confidentiality obligations on staff and processors, regular backups, and procedures for the handling of personal data breaches in accordance with Articles 33 and 34 of the GDPR, including notification to the Andmekaitse Inspektsioon within 72 hours where the breach is likely to result in a risk to the rights and freedoms of natural persons.
This website uses cookies and similar technologies. Strictly necessary cookies, which are required for the proper functioning of the website and the transmission of communications, are deployed on the basis of § 102¹(2) of the Elektroonilise side seadus and Article 6(1)(f) of the GDPR without requiring consent. All other cookies, including those deployed by Google Analytics for the purposes of statistical analysis of website usage and by the LinkedIn Insight Tag for the purposes of conversion measurement and audience analytics, are deployed only after the user has given freely, specifically, informed and unambiguous consent through the cookie consent banner displayed on first visit, which consent may be withdrawn or modified at any time through the cookie settings interface accessible from any page of the website. Detailed information about the specific cookies used, their providers, purposes, retention periods and the recipients of the data they generate is set out in our separate Cookies Policy, which forms an integral part of this Privacy Policy.
Subject to the conditions and limitations set out in the GDPR, every data subject has the right to obtain confirmation as to whether personal data concerning them is processed and, where this is the case, access to that data and the information referred to in Article 15; the right to rectification of inaccurate data and completion of incomplete data under Article 16; the right to erasure under Article 17 where one of the grounds in that provision applies; the right to restriction of processing under Article 18; the right to data portability under Article 20 in respect of data processed by automated means on the basis of consent or contract; the right to object under Article 21 to processing based on legitimate interests, on grounds relating to the data subject’s particular situation, with such objection being upheld unless we demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or the establishment, exercise or defence of legal claims; the right to withdraw consent at any time under Article 7(3) where processing is based on consent, without affecting the lawfulness of processing carried out prior to withdrawal; and the right not to be subject to a decision based solely on automated processing under Article 22, although we confirm that we do not engage in such processing. Requests may be addressed to info@epse.ee, and we will respond within one month of receipt of the request, with a possible extension of two further months where necessary taking into account the complexity and number of requests, in accordance with Article 12(3) of the GDPR. We may require the requester to provide additional information necessary to confirm their identity where we have reasonable doubts as to that identity, in accordance with Article 12(6).
Without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. The supervisory authority competent for EPSE is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, telephone +372 627 4135, email info@aki.ee, website www.aki.ee.
We reserve the right to amend this Privacy Policy from time to time to reflect changes in our processing activities, legal requirements, or supervisory authority guidance. The most recent version is always available on this page, marked with the date of its last update. Where changes are material, we will notify affected data subjects through appropriate means, including by email or a prominent notice on the website, prior to the changes taking effect.
For any question, request or complaint relating to the processing of personal data by EPSE, please contact us at info@epse.ee or by post at Viru väljak 2, Kesklinna linnaosa, Tallinn, Harju maakond, 10111, Estonia.
This Privacy Policy was last updated on 13 May 2026.
EPSE © 2026. All rights reserved.