
Privacy Policy and Personal Data Processing
This Privacy Policy describes how https://hygge.software (hereinafter referred to as the Website, Service, Platform, “HyggeSoftware OÜ,” “we,” “us,” “our”) collects, uses, and transfers information gathered by us or provided by you during your visit to the Website hosted at https://hygge.software and/or in the course of providing services to you and/or interacting with our service, including any electronic correspondence containing your personal data.
This Privacy Policy also explains your rights and options regarding your personal data and how you can contact us to make changes to your personal data or to address any questions you may have about our privacy practices. The provisions of this Privacy Policy may be updated in the future. Whenever we make changes to this Privacy Policy, we will publish the updated version on this page and indicate the date of the new edition.
We act as the controller of your personal data, as we independently determine the purposes for which we need it and select the services and tools for its processing.
Please read the provisions of this Privacy Policy carefully and contact us via the email address provided in this document if you have any questions. Where we rely on your consent, we ask for it separately, for example through the cookie banner or the checkbox on our contact forms, and you can withdraw it at any time.
If you wish to stop receiving marketing materials from HyggeSoftware OÜ, click the “Unsubscribe” button in the marketing email you received from us.
Who We Are
The Website
The website https://hygge.software belongs to a company that provides custom software development services and acts as a reliable IT service provider for clients in Europe, the USA, Canada, and Australia
Data Controller
HyggeSoftware OÜ
Harju maakond, Tallinn, Lasnamäe linnaosa, Kivimurru tn 11-58, 11411
Data Protection Officer
Artem Petrov
+48 889 041 233
Definition of Terms
Personal Data - information or a set of information about an individual who is identified or can be specifically identified.
Non-Personal Data - information and details that, on their own, do not allow for the direct identification of a specific individual.
Information - both Personal and Non-Personal Data.
User - an individual who accesses the Website https://hygge.software or the Service in general, uses it, and/or places an order for the relevant services.
Processing - any actions performed on personal data, including but not limited to access, provision, distribution, collection, systematization, storage, accumulation, recording, transfer, blocking, deletion, clarification, updating and/or modification, anonymization, and other uses of personal data carried out by the Service.
GDPR - General Data Protection Regulation.
1. General Provisions
We process your personal data in accordance with the law, solely for the purpose of processing your request, instructions, and providing necessary information about its status, participating in promotional activities of our Service, when you contact customer support, as well as when you subscribe to our newsletters, participate in surveys, or leave feedback about our services.
The information provided by you is confidential and will not be shared with third parties, except when necessary to fulfill your request, instructions, or in other cases as required by law.
The provisions of this Privacy Policy apply only to the Website https://hygge.software. The Service does not control and is not responsible for third-party websites that the User may visit through links available on the Website.
Please note that the Service does not verify the accuracy of the information provided by the User.
Your information is processed from the moment you access the website and begin using the Site, as well as from the moment our company’s employee receives your personal data sent via email, through the website, or provided through other means of communication.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. If you allow marketing cookies, LinkedIn and Meta use information about your visits to our website to show you our ads, which involves profiling of your interests (see “Cookies and similar technologies” below).
2. Information We May Collect Or Receive
When you visit our web pages, the following data is collected:
- IP address
- The hostname of the computer accessing the site
- Location and time of visit
- The resource from which you accessed this website
- A list of websites providing third-party services based on your preferences
- Date and duration of your visit
- Notification of whether the visit was successful
- Data transfer size
- Information about browser identification data and the operating system you are using.
The temporary storage of this data is necessary during your visit to the website to provide you with access. Further storage in log files is carried out to ensure the website’s functionality and our IT systems’ security. Therefore, the legal basis for processing the aforementioned categories of data is Article 6(1)(f) of the EU General Data Protection Regulation (GDPR). We have a legitimate interest in processing this data in relation to these purposes, particularly to ensure security and seamless connection establishment.
The Service collects and uses only the personal data of users that are necessary for the preliminary order of the service. For the User, this includes your full name, email address, and phone number.
Data such as city and postal address are considered personal data, and the legal basis for their processing by us is the existing contract (Article 6(1)(b) GDPR) and our legitimate interest in presenting our offer as accurately as possible (Article 6(1)(f) GDPR).
Other information may be provided by the user solely at their discretion (unless such information is required to ensure the performance of the contract or its provision is mandated by law).
Cookies and similar technologies
Cookies are small files that a website, or a service it uses, stores in your browser. Similar technologies, such as your browser’s local storage and tracking pixels, work in the same way. We store or read such information on your device only when the website needs it to work, or when you have allowed it.
Strictly necessary. We remember your cookie choice and, if you switch it, your light or dark theme preference, both in your browser’s local storage. Members of our team who sign in to the site’s administration area receive a session cookie. This storage needs no consent. The legal basis for the related processing is our legitimate interest in running the website (Article 6(1)(f) GDPR).
Analytics. With your consent, we use Google Analytics 4 and Hotjar to understand how visitors find and use the website, such as which pages they visit and how they move between them.
Marketing. With your consent, we use the LinkedIn Insight Tag and the Meta Pixel to measure the results of our advertising on LinkedIn, Facebook and Instagram, and to show our ads to people who have visited the website.
The legal basis for analytics and marketing is your consent (Article 6(1)(a) GDPR and the national rules implementing Article 5(3) of the ePrivacy Directive). These tools do not load until you allow them in the cookie banner, and each runs only for the category you allowed.
The tools we use
- Google Tag Manager (Google Ireland Limited, Dublin, Ireland) loads the tools you allowed. It is not loaded at all until you allow analytics or marketing.
- Google Analytics 4 (Google Ireland Limited, Dublin, Ireland) sets the cookies _ga and _ga_<ID>, which tell visitors and their sessions apart, for up to two years. Event-level and user-level data is kept for the retention period set in our account, at most 14 months; a returning visitor can restart that period for their identifier, and Google deletes expired data once a month. Aggregated reports, which do not identify visitors, are not affected by that period. See Google’s cookie documentation and retention documentation.
- Hotjar (Hotjar Ltd, St Julian’s, Malta) sets _hjSessionUser_<ID>, which recognises a returning visitor for 365 days, and _hjSession_<ID>, which holds the current visit for 30 minutes. Hotjar keeps recordings and heatmap data for 365 days. See Hotjar’s cookie list.
- LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Dublin, Ireland) sets li_fat_id on our website for 30 days, and further cookies on LinkedIn’s own domains, listed in LinkedIn’s cookie table. LinkedIn removes direct identifiers from the visit data within 7 days and deletes the rest within 180 days. See LinkedIn’s Insight Tag FAQ.
- Meta Pixel (Meta Platforms Ireland Limited, Dublin, Ireland) sets _fbp and, when you arrive from a Meta ad, _fbc, each for 90 days. See Meta’s documentation. Meta keeps the data it receives under its own privacy policy.
Google, LinkedIn and Meta may transfer data to their parent companies in the United States. Google LLC, LinkedIn Corporation and Meta Platforms, Inc. take part in the EU-U.S. Data Privacy Framework, which the European Commission recognises as providing adequate protection.
For the LinkedIn Insight Tag and the Meta Pixel, we and the provider are joint controllers for collecting data on our website and passing it to the provider (Article 26 GDPR). We are responsible for telling you about this collection and for asking your consent before either tool loads. The provider is responsible for the data once it receives it, and for what it then does with it. You can exercise your rights with us or with the provider; we pass on requests that concern the provider’s part. For Meta, the arrangement is set out in the Meta Controller Addendum.
Changing your choice
You can change or withdraw your consent at any time with the “Cookie settings” link at the bottom of every page. Withdrawing consent deletes the cookies these tools stored on our domain and stops them from loading again. Cookies stored on the providers’ own domains can be deleted in your browser’s settings. We keep your choice in your browser for six months, and ask again after that, or sooner if what the cookie banner asks for changes.
We do not collect and ask you not to provide any information that is subject to specific restrictions and requirements under the law, namely: information about racial or ethnic origin, political, religious, or philosophical beliefs, membership in political parties or trade unions, criminal convictions or suspicions of criminal offenses, as well as data related to health, sexual life, biometric and genetic data.
3. How We May Use Personal Data
We may use the information we collect, as described above, for the following purposes:
Contractual relations.
We may process your personal data to fulfill contractual obligations — for reviewing and/or processing your application, order, and preparing a commercial offer, or contract. The legal basis is Article 6(1)(b) GDPR. Additionally, you voluntarily provide data to communicate with us, so your consent is another legal basis, Article 6(1)(a) GDPR.
Inquiries and other communications.
If you have contacted us through our contact forms and/or via email/phone/messenger, we may process the information you provided to be able to respond to your question, complaint, or request.
Marketing.
We may use the information received from you (e.g., your email address) for marketing purposes. For example, by subscribing to our newsletter, you will receive posts and announcements directly to your email. We may send you promotional materials regarding our services, special offers, or other information that we believe may be of interest to you.
You can opt out of receiving our marketing emails (either fully or partially) by clicking the “unsubscribe” link in the emails you receive from us. Additionally, to unsubscribe, you can contact us at any time by sending a message to the email address provided in this Privacy Policy – gdpr@hygge.software.
We may also use the information obtained through analytics and marketing cookies to understand how visitors use the website, measure the effectiveness of our advertising and plan future marketing campaigns. We do this only with the cookies you allowed, so the legal basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time under “Cookie settings”.
Information sharing.
HyggeSoftware OÜ may disclose your personal information to the following categories of recipients:
- To companies/contractors within its group, professional advisors, third-party service providers, and partners who provide data processing services for HyggeSoftware OÜ (e.g., for supporting delivery, providing functionality, or assisting in enhancing the security of the HyggeSoftware OÜ website), or who otherwise process personal data for purposes described in this Privacy Policy or as communicated to you when we collect your personal data. A list of current companies/contractors of HyggeSoftware OÜ is available upon request.
- To any competent law enforcement authority, regulatory authority, government agency, court, or other third party, if HyggeSoftware OÜ believes that disclosure of information is necessary (a) in accordance with applicable law or regulation, (b) for the establishment, exercise, or defense of its legal rights, or (c) to protect your vital interests or the vital interests of any other person.
- To any other person with your consent for disclosure.
Protection of our interests and security.
We may use your personal data when we deem it necessary to take measures to prevent potential liability, for conducting investigations and defending the Service against any claims or accusations from third parties, investigating and protecting the Service from fraud, ensuring the security or integrity of the Website, and protecting the property rights of our Service, users, and/or partners. The legal basis for this is our legitimate interest in protecting our business, our users and the Website (Article 6(1)(f) GDPR).
Compliance with Legal Requirements.
We may also use/disclose the information we collect to comply with legal requirements, industry standards, and our policies. We may disclose your information in situations that we believe:
(1) involve emergencies related to a potential threat to the physical safety of any person or property, if we believe your information is related to such a threat;
(2) are related to illegal or inappropriate use of the Website and/or services, in our opinion. The legal basis is Article 6(1)(c) GDPR.
Processing of information includes:
The collection, accumulation, storage, adaptation, verification, modification, restoration, use, anonymization, and destruction of personal data, including through information (automated) systems.
The collection of personal data may occur orally, in writing, and/or electronically, through requests or self-provision of the necessary information and documents by you. Personal data is accumulated and stored in written and/or electronic form.
4. How We May Transfer Personal Data
We pay special attention to the confidentiality and protection of your personal data. The information you provide is confidential and will not be shared with third parties, except as necessary to fulfill or provide services, and in cases required by law.
We share personal data with third-party contractors only when they need it to provide the relevant service.
Third-party contractors-processors: who process data and are contractually obligated to maintain strict confidentiality in accordance with Article 28 of the GDPR.
We may disclose your personal data if required by law or to fulfill a legal obligation, or if we are confident that such actions are necessary for:
- Investigating, responding to, and defending against claims; if necessary in legal proceedings (including court subpoenas) to protect the rights and property of the Service or third parties; to prevent potential liability;
- Public safety or the safety of individuals;
- To prevent or stop any illegal, unethical, fraudulent, offensive, or other activities that could result in negative legal consequences;
- For the integrity and security of the website, our services, or any equipment used to operate the website and provide services; to comply with applicable laws and regulations.
5. How We Store And Protect Your Personal Data
The protection of your personal data is extremely important to us, and we take all necessary measures to ensure it. We store users’ personal data in secure conditions. Your personal data is protected from unauthorized access, disclosure, use, alteration, or destruction.
The service continuously monitors the measures taken to ensure security.
We will retain your personal data for as long as necessary to provide you with access to the site and/or to fulfill our legal obligations (such as processing your requests and providing services, tax and/or financial reporting), resolving disputes, and ensuring compliance with our policy.
The retention period is determined based on the type of information collected and the purpose for which it was collected, depending on the situation and the need to delete outdated or unnecessary information as quickly as possible. Analytics and marketing data is kept for the periods listed under “The tools we use” in section 2, and your cookie choice for six months.
After you stop using the Website and/or our services by deleting your account on the Website (if such registration is provided), your Personal Data will also be automatically deleted, except in cases where we are required to retain such data to comply with obligations established by applicable law and these Terms of Use.
6. Your Rights
Regarding your personal data, you have the right to:
- Contact the data controller at any time with any questions or complaints regarding the processing of personal data, as well as to inquire whether your personal data is being processed and the contents of such data;
- Request free access to your personal data;
- Request at any time that the data controller cancel or restrict the processing of your personal data, as well as request amendments to your personal data if there are inaccuracies or if they have become outdated;
- Request at any time that the data controller delete your personal data to the extent that it is no longer needed to achieve the purposes stated in this notice, or for other purposes for which the data controller must continue processing, or when the data controller no longer has the legal right to process it;
- Receive the personal data you gave us in a structured, commonly used and machine-readable format, and have it sent to another controller, where we process it by automated means on the basis of your consent or a contract (data portability);
- Withdraw your consent at any time, without affecting the lawfulness of processing carried out before you withdrew it. For cookies, use “Cookie settings” at the bottom of every page;
- Lodge a complaint with a data protection supervisory authority, in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or the authority of the EU country where you live, work or believe an infringement took place;
- Know the sources of collection, the location of your personal data, the purpose of its processing, the location of the data controller or data processor, or give appropriate instruction to authorized persons to obtain this information, except where otherwise required by law;
- Receive information about the conditions under which personal data is accessed, including information about third parties to whom the personal data is transferred;
- Object, on grounds relating to your particular situation, to processing based on our legitimate interests, and object at any time, without giving reasons, to the use of your personal data for direct marketing;
- Ensure protection of your personal data against unlawful processing and accidental loss, destruction, or damage, in connection with deliberate concealment, failure to provide, or untimely provision of such data, as well as protection against providing inaccurate data or data that defames the honor, dignity, and business reputation of the individual;
- Exercise legal remedies in case of a violation of personal data protection laws;
- Make reservations regarding the limitation of the right to process your personal data when giving consent;
- Know the mechanism of automated processing of personal data;
- Ensure protection from automated decisions that have legal consequences for the individual.
If you wish to exercise any of the above rights or obtain further information, please contact us using the details provided below in this Privacy Policy.
Some of these rights have limits set by law, for example where we must keep data to meet a legal obligation. Your right to object to direct marketing and your right to withdraw consent have no such limits.
To respond to your request, we must verify your identity to ensure that your information is not provided to an unauthorized person.
The service must provide you with information about the actions taken in response to your request within ten days of receiving it. The final response to your request must be provided within 10 days from the date of receipt. However, for third parties, the response time may be extended up to 30 days from the date of receiving the request.
If you learn that someone has unlawfully provided us with your personal data, please notify us as soon as possible using the contact details provided in this Privacy Policy. Upon your request, we will delete your personal data as soon as possible, but in any case, no later than one month from the date of receiving your request. We will retain only those copies of the information that may be necessary for us to comply with legal requirements in such cases.
Additionally, you can at any time modify (update, supplement, or delete) the personal data you have provided by contacting us with a relevant request.
7. Children
The Website and our services are intended for adults acting for businesses. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it as soon as possible, unless the law requires us to keep it.
8. Updating this Privacy Policy
Each time we make changes to this Privacy Policy, the new version will be available on the Website with an updated revision date.
You can access the new version of the Privacy Policy starting from the day it comes into effect, giving you time to decide whether to continue using the site and to submit any objections regarding changes to the processing of your personal data. A draft of the new Privacy Policy may be published in advance.
9. Questions and Complaints
If you have any questions, concerns, or complaints regarding our methods of collecting and processing your personal data, or if you have any suggestions or questions about this Privacy Policy, please contact us using the contact details provided in the “Who We Are” section.
10. We use the following services:
Our website is hosted on Amazon Web Services (AWS), on servers in Frankfurt, Germany, within the EU. AWS processes this data on our behalf under its data processing addendum, and the data is encrypted and protected against unauthorised access, disclosure and destruction. More details about AWS and the GDPR can be found here.
We use Google Analytics, a web analytics service provided in the EEA by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, only if you allow analytics cookies. More information can be found here.
The CRM system Pipedrive is used for storing customer personal data. Pipedrive OÜ is located at Mustamäe tee 3a, 10615 Tallinn, Harju County, Estonia, with registration number 11958539.
For more details about the Pipedrive CRM system, visit their official website https://www.pipedrive.com/en/about

