Ticto Logo
  • Responsabilities
  • What is MoR
  • Global Compliance
  • Support
  • Terms
Back to home

Privacy Policy

Last updated: February 2026

1. Who We Are

This Privacy Policy applies to Ticto OÜ, a private limited company incorporated under the laws of Estonia, with registered office in Harju maakond, Tallinn, Republic of Estonia (“Ticto”, “We”, “Us”, “Our”).

Ticto OÜ acts as the Data Controller for personal data processed in connection with international transactions.

2. Scope

This Policy explains how we collect, use, store, and protect personal data in accordance with:

  • the EU General Data Protection Regulation (GDPR);
  • applicable Estonian data protection laws; and
  • other mandatory international regulations where applicable.

3. Data We Collect

We may collect the following categories of personal data:

  • identification data (name, email, billing address);
  • transaction data (payment method, transaction ID, taxes);
  • technical data (IP address, device information, logs);
  • customer support communications.

4. Legal Bases for Processing

We process personal data based on:

  • performance of a contract (Art. 6(1)(b) GDPR);
  • compliance with legal obligations (Art. 6(1)(c));
  • legitimate interests (Art. 6(1)(f));
  • consent, where required (Art. 6(1)(a)).

5. Purposes of Processing

Personal data is processed to:

  • execute and manage transactions;
  • provide customer support;
  • comply with tax, accounting, and regulatory obligations;
  • prevent fraud and ensure platform security.

6. Data Sharing

Personal data may be shared with:

  • payment service providers and acquiring banks;
  • tax and regulatory authorities, where legally required;
  • operational service providers acting as data processors under GDPR-compliant agreements.

7. International Data Transfers

Where data is transferred outside the European Economic Area, Ticto OÜ ensures appropriate safeguards, including Standard Contractual Clauses (SCCs).

8. Data Retention

Personal data is retained only for as long as necessary to fulfill legal and contractual obligations.

Financial and transaction records are retained for at least 5 years, or longer if required by law.

9. Data Subject Rights

You have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • request erasure or restriction;
  • object to processing;
  • request data portability;
  • lodge a complaint with a supervisory authority.

10. Security Measures

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse.

11. Contact

For privacy-related requests, contact:

Ticto OÜ

Harju maakond, Tallinn, Estonia

Email: help@ticto.me

You may also lodge a complaint with the Estonian Data Protection Inspectorate.