Privacy Policy
This Policy explains how TopSoft OÜ processes personal data of visitors to virtualgarage.app, applicants, Customer representatives and users of the VirtualGarage application (app.virtualgarage.app). It covers account creation and administration, billing for VirtualGarage, support, analytics and security.
VirtualGarage (the “Service”) is a cloud service for managing business operations, provided by TopSoft OÜ.
Customer means a natural or legal person using VirtualGarage in the course of their professional or business activities. User means a natural or legal person authorised by the Customer to use VirtualGarage within its account. Legal persons act through their authorised representatives.
1. Controller and contact
TopSoft OÜ, registry code 12252115, registered address: Punane tn 6, Tallinn 13619, Estonia, is the controller for personal data processed to operate the website, assess applications, administer Service access, bill for VirtualGarage, provide support and maintain security. Privacy enquiries: privacy@virtualgarage.app.
The Customer uses VirtualGarage to process personal data of its customers, persons seeking services, employees, suppliers and others. The Customer determines the purposes of this processing and is responsible for its lawfulness as controller. TopSoft OÜ processes this data on the Customer’s behalf as processor under the Data Processing Agreement (DPA).
Customer Data may include orders, vehicle and equipment details, documents and files, incoming and outgoing messages with attachments, employee, supplier and other counterparty data, and settings and protected credentials required for Customer-enabled integrations.
Data may be entered by the Customer or its Users or received from persons seeking the Customer’s services through VirtualGarage public pages, forms and widgets, including those embedded on the Customer’s websites. Data may be received through price requests, responses to quotations, orders created from quotations or online bookings. These actions do not require registration or access to a VirtualGarage account.
VirtualGarage public pages, forms and widgets through which personal data is submitted display a link to the privacy policy of the person providing the relevant services, together with their name and contact details. Requests for access, correction or deletion should be sent to those contacts. This Policy does not replace the Customer’s privacy policy.
2. Data we process
- Account applications and contacts: company, country, name, role, email, phone, website, verification and assessment results.
- Account: username, contacts, language, roles, locations, authentication and security data. Passwords are stored as cryptographic hashes.
- Company and billing: registration and VAT numbers, address, plan, billable usage, invoices and payments.
- Support: messages, attachments and actions taken to diagnose an enquiry.
- Technical data: IP address, User-Agent, timestamps, logs, sessions and security events.
- Evidence of document acceptance: document version and hash, acceptance date and time, Customer details and details of the representative accepting the documents.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Assessing account applications, onboarding and providing the Service | Pre-contractual steps and performance of a contract where the applicant is a party; for Customer representatives and Users, legitimate interests in assessing applications and administering Service access |
| Authentication, abuse prevention, account data separation and security | Legitimate interests and, where applicable, legal obligations |
| Invoices, accounting and taxes | Contract and legal obligations |
| Support and service communications | Contract and legitimate interests in operating and improving the Service |
| Defending legal claims | Legitimate interest |
| Aggregate analytics on visits and interface use | Legitimate interest in evaluating and improving the website and Service while minimising data and respecting visitors’ rights; technologies requiring consent are used only after consent is obtained |
4. Sources
Data comes from you, the Customer you represent, other authorised users, system activity and public business registers where necessary to verify an application or company.
5. Recipients and providers
| Provider | Service | Location |
|---|---|---|
| OVH HOSTING LIMITED (OVHcloud, Ireland) | Hosting and data storage | Frankfurt, Germany |
| Zone Media OÜ (zone.ee) | VirtualGarage email infrastructure: service correspondence, notifications and support enquiries | Estonia / European Union |
| Think Intermedia SIA (Sendberry) | SMS transmission | Latvia; delivery routing depends on the recipient’s location and telecommunications operators involved |
Personal data may also be disclosed to:
- payment providers to receive payments, save the Customer’s chosen payment method and automatically pay subscriptions where the Customer enables that feature;
- integration providers and third-party systems enabled by the Customer to transfer selected data, including purchase and sales invoices, payment information, counterparties and related data;
- professional advisers, banks and public authorities where necessary for the relevant processing purpose or required by law.
Plausible Analytics is used for website and application usage statistics, with analytics data processed and stored in the EU. See Section 8.
Before a specific payment service is enabled, the Customer receives provider information and a link to its privacy policy. Integration activation displays the recipient, data scope and exchange terms. The provider’s role depends on actual processing: a provider used for TopSoft OÜ’s own billing does not automatically become a Customer Data subprocessor under the DPA. Changes requiring DPA notification are notified under its procedure. We do not sell personal data. Customer-enabled integrations follow its settings and may be subject to the providers’ own terms and policies.
Zone Media OÜ operates VirtualGarage’s email infrastructure. This does not mean that it hosts the Customer’s email accounts. Customer-selected email providers depend on the Customer’s settings and contracts.
6. International transfers
Primary hosting is in Germany. VirtualGarage email infrastructure and analytics data storage are in the EU. Message routes depend on recipients and providers involved. Where processing involves transfers outside the EEA, these comply with Chapter V GDPR, relying on an applicable adequacy decision or appropriate safeguards, including standard contractual clauses, and necessary supplementary measures.
7. Retention
Retention depends on the purpose. Data processed by TopSoft OÜ for its own purposes is retained as follows:
- incomplete account applications: up to 90 days after the last interaction; rejected applications: up to 90 days after the decision. Particular information may be kept longer where necessary to investigate abuse or defend legal claims;
- Customer contact and contractual details: during the relationship and normally up to three years afterwards to defend legal claims; this does not mean retaining all account content for three years;
- TopSoft OÜ’s own accounting records, including VirtualGarage invoices and payment information: for statutory periods, normally seven years from the end of the relevant financial year;
- security logs: normally up to 12 months, longer where necessary to investigate a particular incident;
- evidence of contractual document acceptance: throughout the contract and applicable periods for defending legal claims and mandatory retention.
Data entered by the Customer is processed while the Service is provided. After termination, at the Customer’s choice, it is returned and remaining copies deleted, or deleted without return. Active-system deletion takes place within 90 days of termination, subject to the specific switching and retrieval rules in Section 11.1 of the Terms. A further period may be separately agreed in writing with a specified purpose and end date; the DPA remains applicable and data is not used for other purposes.
After deletion from active systems, residual data may remain in shared backups of several Customers until scheduled rotation, normally for no more than 30 days and, where technically justified, no more than 60 days from active-system deletion. Access is restricted to authorised persons; the data is not used for ordinary operation or other purposes except necessary recovery. Upon restoration, previously deleted data is deleted again before ordinary processing resumes. Shorter mandatory legal deletion periods prevail.
The Customer is responsible for retention of its accounting and other records and timely retrieval of copies. TopSoft OÜ’s obligation to retain its own accounting records does not require it to retain Customer documents in VirtualGarage for seven years after termination.
8. Cookies and analytics
Plausible Analytics is used on virtualgarage.app and app.virtualgarage.app to assess visits and interface use and improve VirtualGarage. We receive aggregate statistics about pages visited, referral sources, browsers, operating systems, device types and approximate visitor locations.
Plausible does not use cookies, local storage or persistent identifiers for analytics and does not track visitors across websites or days. IP addresses and User-Agent strings are processed temporarily to determine approximate location and generate a daily identifier; raw IP addresses and full User-Agent strings are not retained in analytics. Analytics data is processed and stored in the EU.
See Plausible’s data policy. This description concerns website and application analytics; VirtualGarage technical logs are processed separately under this Policy.
The application stores your chosen language in browser localStorage for subsequent visits. You can change it in the application or remove the setting by clearing browser site data.
Necessary cookies or local storage may be used for login, session maintenance and protection. Advertising cookies are not used. Optional technologies requiring consent will be enabled only after consent is obtained.
9. Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability, object to processing or withdraw consent without affecting prior lawful processing. Identity verification may be required. The applicability of each right depends on the processing basis and circumstances; legal requirements and others’ rights are considered.
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee, or another competent supervisory authority.
Requests about data processed on a Customer’s behalf are handled by that Customer. If received by us, we forward the request and assist under the DPA unless law requires otherwise.
10. Automated decisions
Account applications may be checked automatically for completeness and signs of abuse. Approval decisions producing legal or similarly significant effects are not made solely by automated means.
11. Security
Risk-proportionate measures include access control, role and account data separation, transport encryption, logging, updates, backups and incident response. No internet service can guarantee absolute security.
12. Changes
This Policy may be updated when the Service, providers or law change. The current version and date are published here. Material changes are notified through the application or by email.
Changes to TopSoft OÜ’s registered address or contact details are published in this Policy. Updating particulars while the legal entity and registry code remain unchanged does not itself alter processing purposes or conditions and does not require acceptance of the Policy.
