ProductPricing
Book a demo→
— Legal
Privacy PolicyCookie PolicyTerms of UseLegal NoticeData Processing AgreementSubprocessorsAcceptable Use Policy

Privacy Policy

How Artidal collects, uses, shares, and protects personal data across our website and services, the legal bases we rely on, and the rights you have under the EU GDPR and Estonian law.

Last updated: September 1, 2026

This Privacy Policy explains how Artidal OÜ ("Artidal", "we", "us", "our") collects, uses, shares, and protects personal data. It is written to meet the requirements of Regulation (EU) 2016/679 (the "GDPR") and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).

It applies to personal data we handle as a data controller — chiefly visitors to www.artidal.com, people who contact us or request a demo, prospective and existing customers and their staff, and job applicants. Where we process personal data on behalf of a customer inside the Artidal platform (for example their guests' booking data), we act as a data processor; that processing is governed by our Data Processing Agreement rather than this policy.

1. Who we are (data controller)

The data controller responsible for your personal data is:

Artidal OÜ, registered at Narva mnt 5, Kesklinna linnaosa, Tallinn, Harju maakond 10117, Estonia. VAT number EE103012461.

For any privacy matter, or to exercise your rights, contact us at privacy@artidal.com or by post at the address above.

We have assessed whether we are required to appoint a Data Protection Officer (DPO) under Article 37 GDPR and have determined that we are not, as our core activities do not involve large-scale systematic monitoring or large-scale processing of special-category data. You can still direct all privacy questions to privacy@artidal.com.

2. The personal data we collect

Depending on how you interact with us, we may collect:

  • Identity and contact data — your name, business email address, phone number, employer, and job title, for example when you request a demo, take an assessment, subscribe to updates, or email us.
  • Customer and account data — the details needed to set up and administer a customer account and to contact account administrators.
  • Enquiry and communications data — the content of messages, form submissions, assessment answers, and support requests, and our correspondence with you.
  • Usage and device data — IP address, approximate location, browser and device type, pages viewed, and interactions with the site, collected through cookies and similar technologies (see our Cookie Policy).
  • Recruitment data — where you apply for a role, the information in your application, CV, and any interview notes.

We do not intentionally collect special categories of personal data (such as health, religion, or political opinions) through our website, and we ask that you do not send such data to us unsolicited. We do not knowingly collect data from children; our services are directed at businesses.

3. How we use your data and our legal basis

Under the GDPR we must have a lawful basis for each purpose for which we use personal data. Our purposes and bases are:

  • Responding to enquiries, demos, and assessments — to take steps at your request before entering into a contract (Art. 6(1)(b)), and our legitimate interest in responding to business enquiries (Art. 6(1)(f)).
  • Providing and administering our services to customers — performance of our contract with the customer (Art. 6(1)(b)).
  • Marketing and updates about Artidal to business contacts — your consent where required (Art. 6(1)(a)), or our legitimate interest in promoting our services (Art. 6(1)(f)). You can opt out of marketing at any time.
  • Operating, securing, analysing, and improving our website and services — our legitimate interest in running and protecting our business (Art. 6(1)(f)).
  • Recruitment — to take steps prior to a possible employment relationship, and our legitimate interest in assessing candidates (Art. 6(1)(b) and (f)).
  • Meeting legal, tax, and accounting obligations — compliance with a legal obligation (Art. 6(1)(c)).

4. Providing your data is sometimes necessary

Where you contact us or request a service, providing certain data (such as your name and email) is necessary for us to respond or to enter into a contract. If you do not provide it, we may be unable to help you or deliver the service. Providing marketing consent is always optional.

5. Who we share your data with

We share personal data only where necessary, with the following categories of recipients:

  • Service providers (processors) who help us run our website and business — including cloud hosting and infrastructure, content management, analytics, email and communications, CRM, and customer-support tools. A current list is in our Subprocessors document.
  • Payment and financial providers, where relevant to a transaction.
  • Professional advisers such as lawyers, accountants, and auditors, where needed.
  • Authorities, regulators, or courts where we are required to do so by law, or to establish, exercise, or defend legal claims.
  • A buyer or successor entity in the event of a merger, acquisition, or reorganisation, subject to appropriate confidentiality safeguards.

We require all processors to act only on our instructions and to protect the data they handle. We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.

6. International data transfers

Some of our providers are located outside the European Economic Area (EEA), including in the United States. Where we transfer personal data outside the EEA, we rely on an appropriate safeguard under Chapter V of the GDPR, such as:

  • an adequacy decision of the European Commission for the destination country;
  • the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with additional measures where needed; or
  • the EU-U.S. Data Privacy Framework, where the recipient is certified.

You can request more information about these safeguards, or a copy of the relevant clauses, by contacting privacy@artidal.com.

7. How long we keep your data

We keep personal data only for as long as necessary for the purposes described above, and then delete or anonymise it. In general:

  • Enquiry, demo, and marketing-contact data — kept for up to 24 months after our last meaningful interaction, unless you ask us to delete it sooner or you remain a customer.
  • Customer account data — kept for the duration of the customer relationship and for a reasonable period afterwards.
  • Accounting and tax records — kept for 7 years, as required by Estonian law.
  • Recruitment data — kept for up to 12 months after a decision, unless you consent to us keeping it longer for future roles.

8. How we protect your data

We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse — including access controls, encryption of data in transit, regular backups, and staff confidentiality obligations. No system is completely secure, but we work to protect your data and to review our measures regularly.

9. Your rights

Subject to the conditions in the GDPR, you have the right to:

  • Access — obtain confirmation of whether we process your data and a copy of it (Art. 15).
  • Rectification — have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — have your data deleted where it is no longer needed or you withdraw consent (Art. 17).
  • Restriction — ask us to limit processing in certain circumstances (Art. 18).
  • Portability — receive certain data in a structured, commonly used, machine-readable format (Art. 20).
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email privacy@artidal.com. We will respond within one month, as required by the GDPR. There is normally no charge, though we may charge a reasonable fee or refuse clearly unfounded or excessive requests.

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), or with the supervisory authority in your country of residence or work. We would appreciate the chance to address your concerns first.

10. Cookies and third-party links

Our website uses cookies and similar technologies as described in our Cookie Policy. Our site may link to third-party websites that we do not control; this policy does not apply to them, and we encourage you to read their privacy notices.

11. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top of this page shows when it last changed. Where changes are significant, we will take reasonable steps to bring them to your attention.

The operating system for travel & hospitality.

hello@artidal.com
+372 623 7035
— Platform
Bookings & ReservationsOperationsGuest ExperienceCommunicationRevenue & PaymentsMarketing & GrowthAll Modules
— Solutions
Surf CampsYoga & Wellness RetreatsAdventure LodgesBoutique Eco-ResortsMulti-Location Operators
— Resources
BlogPricingRSS Feed
— Legal
Privacy PolicyCookie PolicyTerms of UseLegal NoticeData Processing AgreementSubprocessorsAcceptable Use Policy
artidal.
© 2026 Artidal OÜ · all rights reservedPrivacy Policy · Cookie Policy · Terms of Use · Legal Notice · Data Processing Agreement · Subprocessors · Acceptable Use Policy