This notice describes what personal data we handle in running reindeer.red and in dealing with the company, why, for how long, and what you can do about it.
This site is the company’s record: nothing can be ordered on it, and it carries no form, no sign-up and no payment. Very little data arises as a result.
1. Who handles your data
The controller is Reindeer Entertainment OÜ (Estonia, registry code 16202332, registered office Sepapaja 6, Tallinn 15551), which operates reindeer.red. The company’s identifying details appear in the footer of every page and in the imprint.
For anything to do with data protection, write to rudolf@reindeer.red.
We are not required to appoint a data protection officer, because we carry out no large-scale, regular and systematic monitoring.
2. What data we handle, what for, and on what legal basis
Getting in touch
If you write by email or on our Facebook page, we handle your name, your contact details and whatever you tell us about yourself or your company, so that we can reply. Legal basis: answering your enquiry as a step prior to entering into a contract, and our legitimate interest in responding to business enquiries.
Business relationships, invoicing and accounting
If we deal with each other as partners, suppliers or client and provider, we handle what a contract and an invoice require: the contact person’s name and details, and the billing data. Legal basis: performance of a contract, and — for the invoicing and accounting records — a legal obligation.
Website analytics
Section 3 sets this out in full. Legal basis: our legitimate interest in seeing how the site is used and what is worth improving on it.
3. Website analytics
The site uses analytics we built ourselves, operated by the same company that operates
the site. The data goes to core.reindeer.red and is not passed to any third-party
advertising or analytics service. There is no Google Analytics, Meta Pixel or similar
external tracker on this site.
We set no cookies, which is why you see no cookie banner. The site’s fonts are served from our own server, so simply opening the page sends nothing to Google or any other outside provider.
The analytics stores one random session identifier in your browser’s session storage
(sessionStorage), named reindeer_session_…. It is not a cookie: the browser deletes
it when you close the tab, and it cannot be used to link your separate visits together.
What your browser sends:
- the path of the page you opened, and where you came from if you arrived from another site
- campaign parameters in that referring address (
utm_*,ref), and no other parameters - your browser identifier (user agent), language setting and time zone
- your screen and window size, your platform, and whether you are on a mobile device
- how long you stayed on the page and how far you scrolled
What the server keeps of it:
- the above, with a timestamp
- instead of your IP address, a shortened hash derived from a truncated IP
- a visitor identifier that rotates daily: a hash of your IP address, your browser identifier and that day’s date
We do not store your full IP address. The hashes do not make you directly identifiable, but they count as pseudonymised data, so this notice and the rights below cover them too.
Country is not derived from your IP address but estimated from your browser’s time zone, and only used in aggregate figures.
If Do Not Track is switched on in your browser, the analytics never starts and sends nothing about you.
4. Who we pass it to
We do not sell your data and we do not use it for advertising. We rely on the following processors:
| Who | For what |
|---|---|
| Google Ireland Ltd. | business email |
| Meta Platforms Ireland Ltd. | only if you write on our Facebook page |
| Our server provider | serving the site and the analytics |
| Our accountant | processing invoices |
Beyond that, we may be obliged to disclose data on an official request.
Data stays inside the European Union by default. Google and Meta may in some cases also transfer data to the United States; both are certified under the EU-US Data Privacy Framework or apply the European Commission’s standard contractual clauses.
5. How long we keep it
- Enquiries: while the enquiry is being dealt with, and for at most 1 year after that, so a follow-up question has something to refer back to.
- Contracts and delivery records: until the limitation period following the end of the contract expires.
- Invoices and accounting records: 7 years, as Estonian accounting rules require.
- Analytics events: at most 90 days, then deleted.
6. Your rights
You may ask us what data we hold about you, ask us to correct inaccurate data, to erase your data, or to restrict how we handle it. You may also ask for your data in a portable form. You may object to us handling your data on the basis of legitimate interest, and that includes the analytics.
Send your request to rudolf@reindeer.red. We reply within one month.
One limitation applies to the analytics: the visitor identifier is a hash that rotates daily, so without further information we cannot retrieve a particular person’s analytics events. You can, however, stay out of the measurement entirely by switching on Do Not Track.
If you believe we are handling your data unlawfully, you may complain to a supervisory authority. As the company is registered in Estonia, that is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). You may also turn to the authority where you habitually reside.
7. Automated decision-making
We make no automated decisions about you and carry out no profiling.
8. If this changes
If we amend this notice, we publish the new version here and update the date above.