Privacy Policy

Last updated: July 2026

This Privacy Policy explains how EFFICIENT DIGITAL MARKETING AGENCY OÜ, trading as Efficient Digital Marketing Agency (“Efficient”, “we”, “us”), collects, uses and protects personal data — both when you use this website and when we deliver services to you. We process personal data in line with the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).

1. Who is responsible for your data

The data controller is EFFICIENT DIGITAL MARKETING AGENCY OÜ, registered under company number 16955965, registered address Narva mnt 5, Kesklinna linnaosa, 10117 Tallinn, Harju maakond, Estonia. You can reach us about anything in this policy at .

Where we handle personal data on behalf of a client — for example contacts in a client’s advertising account or email list — we act as a processor, and the client remains the controller. That relationship is governed by a separate data processing agreement.

2. What we collect

  • Information you send us. When you email us: your name, email address, company, and whatever you choose to put in the message — which in our case often includes budget and performance information.
  • Client and engagement data. Contact details for the people we work with, contractual and billing information, and the marketing data needed to deliver the engagement.
  • Data we process on your behalf. Where you grant us access to your advertising, analytics, CRM or email platforms, we may encounter personal data belonging to your customers and prospects. We access it only to do the work.
  • Technical data. Standard server log information generated when this site is requested, such as IP address, user agent, and the time of the request.

This website has no contact form, no account system and no advertising or tracking pixels. It asks once, through the cookie notice, whether you are willing to allow analytics. If you decline — or ignore it — no analytics runs and nothing about your visit is recorded by us beyond ordinary server logs. Either way, the only thing written to your browser is the answer itself. See the Cookie Policy.

3. Why we process it, and on what basis

  • To answer your enquiry and take steps before entering a contract — Art. 6(1)(b) GDPR, and our legitimate interest in responding to prospective clients, Art. 6(1)(f).
  • To deliver our services under a contract with you — Art. 6(1)(b). Where we act as processor, we do so on your documented instructions.
  • To run and secure this website — our legitimate interest in a functioning, secure site, Art. 6(1)(f).
  • To meet legal obligations, in particular accounting and tax record-keeping — Art. 6(1)(c).

4. Third parties this website relies on

We think you should know what a page load actually does. This site loads two things from external providers, and in both cases your IP address is necessarily transmitted to them in order to serve the file:

  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — serves the typefaces used on this site.
  • jsDelivr (cdn.jsdelivr.net) — serves the animation library used by the homepage.

Neither sets a cookie on this site. If you would prefer these requests not to be made at all, a content blocker will prevent them; the site remains fully usable without them.

5. Who else sees your data

We do not sell personal data, and we do not share it for anyone else’s marketing. We share it only with providers who process it on our behalf — hosting, email, accounting and, where an engagement requires it, advertising and analytics platforms — each under an appropriate agreement. We may also disclose data where the law requires it.

6. Transfers outside your region

We are an Estonian company and prefer to keep data inside the European Economic Area. Some providers we rely on operate outside it. Where personal data is transferred outside the EEA, we rely on an adequacy decision or on Standard Contractual Clauses together with any additional safeguards required.

7. How long we keep it

  • Enquiries that do not become engagements — up to 12 months, then deleted.
  • Client records — for the duration of the engagement and afterwards for seven years afterwards, as the Estonian Accounting Act requires.
  • Data processed on a client’s behalf — returned or deleted at the end of the engagement, as set out in the data processing agreement.
  • Server logs — a short rolling window for security and diagnostics.

8. Your rights

You have the right to access the personal data we hold about you; to have it corrected; to have it erased; to restrict or object to processing; to data portability; and, where processing rests on consent, to withdraw that consent at any time. Exercising any of these costs you nothing and will not affect how we treat you.

Write to and we will respond within one month. If you are not satisfied with our response you may complain to the supervisory authority in your country — for us that is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee/en.

9. Security

We apply appropriate technical and organisational measures to protect personal data, including access control on client platforms, multi-factor authentication on the accounts we hold, encrypted transport, and the principle that nobody has access to a system they do not need for their work.

10. Children

Our services are directed at businesses. We do not knowingly collect personal data from children, and this website is not intended for them.

11. Changes to this policy

We may update this policy. The current version always lives at this address with its revision date at the top. Where a change materially affects how we handle your data, we will tell affected clients directly rather than relying on you to re-read the page.

12. Contact

Any privacy question or request: .