Privacy policy
Learn how Leetio OÜ collects, uses, shares, and protects your personal data across leetio.org, in line with the GDPR and other applicable data protection laws.
Last updated: 22.07.2026
Scope of this policy
Leetio OÜ (“we”, “us”, “our”, “Company”, “Leetio“)
is committed to protecting your privacy. On this page, you can learn what information about you we collect while you interact with Leetio and how we process the personal data you provide us with.
This Policy is intended to help you understand:
why we collect your personal data;
how we collect, use and store your personal data;
which rights relating to your personal data you have;
how you can exercise the rights relating to your personal data;
how we use cookies and other tracking technologies;
how we share and disclose your personal data.
This Privacy Policy (“Policy”) applies between you and Leetio. It describes how we handle the data you provide us with through our website https://leetio.org/ (“Website”) , including via contact forms, when you interact with us via our email address info@leetio.org or on our social media sites, including, but not limited to, Facebook, Instagram, LinkedIn (“Social media accounts”) , during video or phone calls or otherwise provide us with information about yourself.
When processing your personal data, Leetio can play different roles under the GDPR, UK GDPR, EPDPA, LOPDGDD, CCPA, CPA, CTDPA, VCDPA, MCDPA, TIPA, and other applicable laws and regulations. Depending on the factual circumstances of the processing, we may act as a data controller or data processor under the GDPR or UK GDPR and business and service provider under the US privacy laws and regulations respectively.
You can be a Website Visitor, Client, Job Applicant, or Third Party:
You are a Website Visitor when you merely browse our Website and provide us with your data through cookies and other tracking technologies or contact us via email, phone or available contact forms on our Website;
You are a Client when you contact us via email, contact forms on our Website, or our Social media accounts for assistance and/or to leave feedback, share personal data during video or phone calls, or otherwise provide us with personal data when you use our services;
You are a Job Applicant when you submit your personal data through the Website or job boards to apply for a job;
You are a Third Party when we process your personal data as a data processor on behalf of our Client.
Interpretation and definitions
We use the following definitions in this Policy:
“GDPR” means the General Data Protection Regulation (Regulation (EU) 2016/679).
“UK GDPR” means the United Kingdom General Data Protection Regulation.
“EPDPA” means the Estonian Personal Data Protection Act.
“LOPDGDD” means the Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights.
“CCPA” means the California Consumer Privacy Act.
“CPRA” means the California Privacy Rights Act.
“CPA” means the Colorado Privacy Act.
“CTDPA” means the Connecticut Data Privacy Act.
“VCDPA” means the Virginia Consumer Data Protection Act.
“MCDPA” means Minnesota Consumer Data Privacy Act.
“TIPA” means Tennessee Information Privacy Act.
“data controller” means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and how any personal data is processed.
“data processor” means the natural or legal person who processes personal data on behalf of the data controller.
“data subject” is a person who can be identified, directly or indirectly, by details like their name, identification number, location, online identifier, or factors related to their physical, physiological, genetic, mental, economic, cultural or social identity.
“personal data” means any information relating to you and helping identify you (directly or indirectly), such as your name, last name, email, location, etc.
“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
The definitions of terms used within this Policy are taken from the GDPR, considering the definitions established in the CCPA and other US privacy laws and regulations. The group of definitions “personal data” and “personal information”; “controller” and “business”; “processor” and “service provider”; “data subject” and “consumer” may be used interchangeably unless another meaning is mentioned.
Types of personal data we collect
We collect and process information about you in accordance with this Policy. We may collect your personal data through the Website (including contact forms), email, Social media accounts, and during video or phone calls, or via other ways of communication.
We collect the following basic types of information about you in connection with our Website and services: Client and Website Visitor Data, Job Applicant Data and Third-Party Data, which relate to Website Visitors, Clients, Job Applicants and Third Parties respectively. In particular, we collect the following:
Client and Website Visitor Data:
(a) Contact Information. When you contact us through the Website, email, social media accounts, or otherwise communicate with us, we may collect your email address, first and last names, company name, phone number, job title, and any other information you choose to provide.
(b) Communication Information. We may collect information contained in your inquiries, requests, feedback, correspondence, and other communications with us, including records of our interactions and information necessary to respond to your requests.
(с) Commercial Information. We may collect personal data to facilitate the due diligence process and sign the contracts, ensuring the proper execution of contracts. This information may include your full name, job position, company-employer name, the document authorising you to represent the company, and other professional contact information you provide to us.
(d) Cookies Information. We may use cookies and other tracking technologies on our Website to function correctly, for analytics, marketing activities, remembering your preferences, and for other purposes. Such use may involve the transmission of information from us to you and from you to a third-party website or us. To learn more regarding our use of cookies, please, read the ‘USE OF COOKIES’ section of this Privacy Policy and our Cookies Policy.
(e) Usage Data. When you interact with our Website, we may collect and process information regarding your use of the Website to better understand how visitors engage with our content and to improve the Website's performance and user experience. This information may include pages visited, time spent on the Website, traffic sources, approximate geographic location, and other Website usage statistics. We may use third-party analytics providers, such as Google Analytics, to assist in collecting and analysing this information.
(f) Automatically Collected Information. When you access the Website, we may automatically collect certain technical information about your device and connection, including your IP address, browser type and version, operating system, device type, language settings, and similar technical information. We use this information to ensure the proper functioning, security, maintenance, and improvement of the Website.
Job Applicant Data:
(g) Job Applicant Information. When you apply for a job through the Website, we can collect your personal data. This data may include your first name, last name, phone number, email address, your CV, and other information you decided to provide us. We may also receive your CV and other personal data if you submit it through the job boards we partner with. Please review their privacy documentation before providing any data.
Third-Party Data:
(h) Client-Managed Information. We can have access to data provided by our Client for the performance of services to our Client by us. In this case, the exact categories of personal data and the respective legal basis for processing is determined by the Client.
We use the personal data we collect and process only for the purposes listed in this Policy. We may share personal data with third parties solely for the purposes listed herein.
As a data controller, we DO NOT intentionally collect and process the personal data of children and any sensitive personal data. Please, refrain from sharing your or third-party sensitive personal data.
We DO NOT sell your data.
We DO NOT use automated decision-making, including profiling, which produces legal effects concerning a data subject or similarly significantly affects a data subject
Grounds for processing
We collect and process your personal data in accordance with the provisions of the GDPR, CCPA and other applicable laws and regulations.
Under the GDPR there is an exclusive list of lawful bases, allowing us to process your personal data. During personal data processing, we rely only on four of them, namely:
Article 6.1 (a): consent
We collect the information you choose to give us, and we process it under your consent. You may withdraw your consent to the processing of your personal data at any time.
You may withdraw your consent to the processing of your personal data by emailing us at info@leetio.org or contacting us in any other way convenient for you.
Article 6.1 (b): performance of a contract
When you provide us with personal data via available options on our Website, this can sometimes be considered a request to form a contract or perform a contract between you and us. However, we may ask you for clear consent in case of doubt.
Article 6.1 (c): legal obligation
We process your personal data to fulfil our legal obligations, such as complying with tax or regulatory requirements. If you request to exercise your rights under the GDPR, we may ask you for some personal data for verification purposes to identify you and comply with the applicable law.
Article 6.1 (f): legitimate interest
We process your personal data for the purposes of our legitimate interests, such as preventing fraud and ensuring the security of our Website.
We only collect and use the strictly necessary data to achieve these purposes provided that your interests and fundamental rights and freedoms are not overridden.
How we use your data
When acting as a data controller, we use your personal data for the purposes listed in the table below, where we also detail the types of personal data processed, legal bases we rely on to do so, third parties with whom we may share your personal data and information on the source of such data:
| Purpose of Processing | Types of Personal Data | Legal Grounds | Third-party Recipients | Source |
|---|---|---|---|---|
| Providing services for clients | (c) Commercial Information | Performance of a contract (Article 6(1)(b)) | Contractors | Client |
| Communication with Clients and Website Visitors (including responding to inquiries through the forms on the Website) | (a) Contact Information (b) Communication Information | Your consent (Article 6(1)(a)) Performance of a contract (Article 6(1)(b)) | Storyblok GmbH, Contractors | Client, Website Visitor |
| Due diligence and conclusion of the contract | (c) Commercial Information | Performance of a contract (Article 6(1)(b)) | Contractors | Client |
| Analytics and developing activities (for optimising and enhancing our Website and services) | (d) Cookies Information (e) Usage Data (f) Automatically collected Information | Your consent (Article 6(1)(a)) Our legitimate interest (Article 6(1)(f)) | Google LLC, Contractors, Design Barn Inc. Clutch Co. Inc. | Client, Website Visitor |
| Job applications management | (g) Job Applicant Information | Your consent (Article 6(1)(a)) | Contractors | Job Applicant, Job Boards |
| Fraud prevention | (d) Cookies Information (f) Automatically Collected Information | Our legitimate interest (Article 6(1)(f)) | Contractors, Google LLC | Client, Website Visitor |
| Legal compliance (including cookie consent management) | (c) Commercial Information (d) Cookies Information (f) Job Applicant Information | Legal obligation (Article 6(1)(c)) | Contractors | Client, Website Visitor, Job Applicant, Job Boards |
We can also process personal data as a data processor , at the request and pursuant to the instructions given by our Client as a data controller or by the respective data controller if our Client acts as a data processor. We describe the situation when we act as a data processor and process personal data on behalf of the Client in the table below:
| Purpose of Processing | Types of Personal Data | Legal Grounds | Recipients | Source |
|---|---|---|---|---|
| Provision of services | (h) Client-Managed Information | Determined by the Client | Depends on the particular service and is specified in the DPA with the Client. | Client |
Use of cookies
When you visit our Website, we can gather certain information through cookies. These cookies, for example, can help us understand your interactions with our Website, enhance your browsing experience, improve our Website and services, and conduct marketing activities. To learn more about the types of cookies we use and how you can customise your cookie preferences, please review our detailed Cookies Policy.
Data retention
We keep personal data for as long as needed to fulfil the purposes outlined in this Policy, but not longer than 10 years.
We store Cookies Information for the period specified in our Cookies Policy.
As a data processor, we process Client-Managed Information for the period established by the Client in the data controller’s instructions.
We may not delete or anonymise your data if we are compelled to keep it under the GDPR and other applicable laws.
Security and integrity of the data
We have implemented appropriate organisational, technical, administrative, and physical security measures designed to protect your personal data from unauthorised access, disclosure, use, and modification. We regularly review our security procedures and policies to consider appropriate new technology and methods.
Sharing your data with other entities
We may share your personal data with other entities in accordance with the provisions specified hereafter.
Sharing data with data processors
There are many features necessary to provide you with our services that we cannot complete ourselves; thus, we seek help from third parties. We may grant some service providers access to your personal data, in whole or part, to provide the necessary services.
Therefore, we may share and disclose your personal data to other data processors, namely, to:
Google Analytics (Google Ireland Limited, Ireland): for Website analytics purposes. You may read its Privacy Policy here .
As part of our business operations, we may engage various specialists who may receive your personal data, including technical, sales, legal and marketing professionals, to provide you with better client service. Collectively, these specialists are referred to in this Policy as Contractors.
International data transfers
We may transfer your personal data to countries outside the European Union (EU) and the European Economic Area (EEA) that are not deemed to provide an adequate level of data protection under Article 45 of GDPR (adequacy decision).
In such cases, we will ensure that appropriate safeguards are implemented in accordance with the GDPR to protect your personal data, in particular, the standard contractual clauses adopted by the European Commission. Where possible, we always enter into Data Processing Agreements (DPAs) and Non-Disclosure Agreements (NDAs) with these third parties to ensure that your personal data is adequately protected.
We put supplementary technical and organisational measures in place when transferring data outside the EU and the EEA. e.g. prior assessment of the service supplier’s reliability and personal data protection practices, encryption of the transferred personal data, prompt reacting to any threats to confidentiality, integrity and availability of the personal data, conducting transfer impact assessments (TIA) when necessary, etc.
Links to third-party websites or services
This Policy applies only to this Website and our Services. We strongly recommend you review the privacy documents of any websites you may reach by following the hyperlinks presented on our Website. We have no control over the content and data practices of other websites and are not responsible for their actions.
Social media accounts
We manage the Company's official pages on various social media sites including Facebook, Instagram, LinkedIn. We can collect information about you when you interact with us via our Social media accounts by following our official pages, posting comments, or reacting to our content.
When you contact us via our Social media accounts for assistance or leave us feedback regarding the provision of services, we can collect this information for further communication purposes. You can find a detailed description of the personal data that we may collect from you above in the “HOW WE USE YOUR DATA” section of this Policy.
Please note that depending on the social media platform, additional processing operations may be conducted by the operators of these platforms. We recommend always checking social media platforms' privacy policies and rules regarding the collection of your personal data.
Data subject age
Our Website and services are intended for general audiences and are not directed to children under the age of 18. By submitting your personal data to us, you acknowledge that you have reached the age of 18, and under the laws of your country of residence, you have all rights to provide us with your personal data for processing.
Under the GDPR, we do not knowingly collect any personal data from children under age of sixteen (or a lower age if provided by EU member state law, provided that such lower age is not below 13 years).
If we learn we have collected or received personal data from a child, we will delete that information. If you have any reason to believe that a child has provided their personal data to us, please contact us at info@leetio.org .
Rights under GDPR
You may exercise the following rights by submitting a data subject request at info@leetio.org .
Please note that we may need to confirm your identity to process your requests to exercise your rights under the GDPR. Thus, we may not be able to satisfy your request if you do not provide us with sufficient detail to allow us to verify your identity and respond to your request.
| Right under the GDPR | Description | How to exercise it |
|---|---|---|
| Right to withdraw consent (Art. 7) | You can withdraw your consent for data processing at any time. | You can submit a request. |
| Right to be informed (Art. 13, 14) | You have the right to be informed about the collection and use of your personal data. | All information about our collection and use of your personal data is described in this Privacy Policy and the Cookies Policy. |
| Right of access (Art. 15) | You have the right to confirm whether your personal data is being processed by us and access such data, along with specific information. | You can submit a request. |
| Right to rectification (Art. 16) | You have the right to correct inaccurate personal data about you and to have incomplete personal data completed. | You can submit a request. |
| Right to erasure (“right to be forgotten”) (Art.17) | You have the right to have your personal data deleted without undue delay where one of the following grounds applies: the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the personal data have to be erased for compliance with a legal obligation in the European Union or an EU Member State law; the personal data have been collected in relation to the offer of information society services referred to in Article 8(1); the personal data have been unlawfully processed. | You can submit a request. |
| Right to restriction of processing (Art. 18) | You can limit the way in which we use your data where one of the following applies: you contest the accuracy of the personal data; processing is unlawful, but you oppose erasure; we no longer need the personal data for the purposes of our processing, but you require personal data for the establishment, exercise, or defence of legal claims; you have objected to processing, pending the verification of that objection. | You can submit a request. Where processing has been restricted on this basis, we may continue to store your personal data. However, we will only otherwise process it: with your consent; for the establishment, exercise, or defence of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public. |
| Right to data portability (Art. 20) | You have the right to receive your personal data in a structured, commonly accepted, and machine-readable format and have the right to request that we transmit this data directly to another controller to the extent that the legal basis for our processing of your personal data is your consent or performance of a contract and the processing is carried out by automated means. | You can submit a request. |
| Right to object (Art. 21) | You have the right to object to our processing of your personal data at any time to the extent that the processing is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. Also, you have the right to object to our processing of your personal data for direct marketing purposes (including profiling). | You can submit a request. |
| Right not to be subject to a decision based solely on automated processing, including profiling (Art. 22) | This right restricts us from making solely automated decisions, including those based on profiling, which produce legal or other significant effects for data subjects. | We DO NOT use automated decision-making and profiling. |
| Right to lodge a complaint (Art. 77) | You have the right to lodge a complaint with the supervisory authority if you believe that the processing of your personal data violates the requirements of the GDPR. | You can submit the complaint in the EU member state of your place of habitual residence or to the data protection authority stated in this Privacy Policy. |
| Right to compensation (Art. 82) | Any person who has suffered material or moral damage as a result of a violation of GDPR requirements has the right to receive compensation from the controller or processor for the caused damage. | Court proceedings for exercising the right to receive compensation shall be brought before the courts competent under the law of the EU Member State referred to in Article 79(2). |
Rights under the US Privacy Laws
US privacy laws and regulations
The table below provides general descriptions of the US residents' privacy rights established by:
the California Consumer Privacy Act (the “CCPA” ) amended with the California Privacy Rights Act (the “CPRA”);
the Virginia Consumer Data Protection Act (the “VCDPA”);
the Colorado Privacy Act (the “CPA”);
the Connecticut Data Privacy Act (the “CTDPA”);
the Minnesota Consumer Data Privacy Act (the “MCDPA”);
the Tennessee Information Privacy Act (the “TIPA” ).
Please note some states do not have their own privacy laws. The rights of residents of such states are governed by other state laws and U.S. federal law.
The terms used in this section of the Policy are taken from the GDPR, considering the definitions established in the CCPA, VCDPA, CPA, CTDPA, MCDPA, TIPA.
You may exercise the following rights by submitting a request at info@leetio.org .
Please note that we may need to confirm your identity to process your requests to exercise your rights. Thus, we may not be able to satisfy your request if you do not provide us with sufficient detail to allow us to verify your identity and respond to your request.
| Right | Description | US laws |
|---|---|---|
| Right to know | You can request information about what personal information we collect about you and how it is used and shared. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to access | You can request access to the collected personal information. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to correct | You can request us to correct the inaccurate personal information about you. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to delete | You can request us to delete the personal information that we have collected from you. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to data portability | You can request obtaining a copy of your personal data that you previously provided to us in a portable and, to the extent technically feasible, readily usable format. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to opt out of the sale | You can request opting out of the processing of personal data for the sale of personal information. We neither sell your personal information to anyone nor use your data as a business model. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to opt out of sharing | You may request to stop sharing your personal information. | California (CCPA) |
| Right to opt out of targeting ads | You can request opting out of the processing of personal data for targeted advertising. | Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to opt out of profiling | You can request opting out of the processing of personal data for profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to initiate a private cause of action for data breaches | The right to bring an individual cause of action or a class action if nonencrypted or nonredacted personal information is subject to unauthorized access and exfiltration, theft or disclosure as a result of the business’s violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information. | California (CCPA) |
| Right to non-discrimination | Right to be free from discrimination relating to the exercise of any of your privacy rights. | California (CCPA) Virginia (VCDPA) Colorado (CPA) Connecticut (CTDPA) Minnesota (MCDPA) Tennessee (TIPA) |
| Right to limit the use and disclosure of sensitive personal information | This right allows you to limit the use and disclosure of your sensitive personal information by the company. We don’t intentionally collect any sensitive personal information about you. | California (CCPA) |
We may collect various categories of personal information under this Privacy Policy. In particular, depending on actual circumstances, we may collect and disclose the following categories of personal information specified in the CCPA when you use our Website or otherwise provide any personal information to us:
Category A – Identifiers;
Category B – Personal information categories listed in the Cal. Civ. Code § 1798.80(e);
Category D – Commercial information;
Category F – Internet or other similar network activity;
Category I – Professional or employment-related information.
You can find a detailed description of the personal information that we may collect from you above in the “TYPES OF PERSONAL DATA WE COLLECT” section of this Policy.
The purposes of the collection and/or use of personal information are stated in the “HOW WE USE YOUR DATA” section of this Policy.
You can review the categories of third parties with whom we may share your personal information in the “SHARING YOUR DATA WITH OTHER ENTITIES” section of this Policy.
Complaints
We encourage you to reach out to us initially with any concerns you may have regarding the processing of your personal data. You may use the following email to address your inquiries: info@leetio.org .
You have the right to lodge a complaint about our use of your personal data with a data protection authority. For more information, please contact your national data protection authority. We will cooperate with the appropriate governmental authorities to resolve any privacy-related complaints that cannot be amicably resolved between you and us. You can find a full list of EU supervisory authorities through this link .
Amendments to the policy
We may periodically update this Policy to reflect new updates, technologies, legal requirements, or for other reasons. Any changes will be communicated by posting an updated version of the Privacy Policy on our Website.
We encourage you to review this Policy periodically. If possible, we always give advance notice of upcoming changes by indicating when the new version of the Privacy Policy will take effect. If you continue to use our Website and services or otherwise provide us with your personal data after the new version of the Privacy Policy goes into effect, we assume that you agree to the changes.
How to contact us
If you have a question related to this Policy, our data processing activities, or your data subject rights under the GDPR and other applicable data protection laws, you can use the following details to contact us:
Our company: Leetio OÜ
Our address: Kaupmehe 7-120, 10114 Tallinn, Estonia
C/ d'Aragó 562, Barcelona, SpainOur email: info@leetio.org
Our phone: +380991991324