top of page

Dedsis Privacy Policy

 

Effective Date: August 21, 2026

This Privacy Policy explains how Dedsis OÜ (“Dedsis”, “we”, “our”, “us”) collects, uses, stores, shares, and protects personal data in connection with our website, products, mobile applications, software, customer support, sales, and related services.

Dedsis processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian data protection legislation.

This Privacy Policy is intended to provide transparent information about our processing of personal data. Where consent is required by applicable law, consent will be requested separately.

1. Data Controller

The controller responsible for the processing of personal data described in this Privacy Policy is:

Company: Dedsis OÜ
Registration No.: 16710092
VAT ID: EE102685323
Registered Address: Madara tn 31, 10613 Tallinn, Estonia
Email: info@dedsis.com
Website: www.dedsis.com

2. Personal Data We May Process

Depending on how you interact with Dedsis, we may process the following categories of personal data:

Contact Information

  • Name and surname;

  • Email address;

  • Telephone number;

  • Billing and delivery contact information;

  • Other information voluntarily provided when communicating with us.

Order and Transaction Information

  • Products or services ordered;

  • Billing and shipping address;

  • Invoice and transaction information;

  • Payment status and payment reference information;

  • Delivery, courier, and tracking information;

  • Information necessary to process returns, warranty requests, or other after-sales services.

Where payments are processed through banks or independent payment service providers, Dedsis does not necessarily receive or store complete payment-card or banking credentials.

Customer Service and Communications

  • Emails, messages, inquiries, support requests, feedback, and other communications;

  • Information reasonably necessary to investigate technical, warranty, delivery, payment, or customer-service matters.

Technical and Website Information

Depending on website configuration, services used, and your cookie choices, this may include:

  • IP address;

  • Browser and device information;

  • Operating system;

  • Website usage and interaction information;

  • Cookie and similar technology identifiers;

  • Security, diagnostic, and technical logs.

Product, Application, and Service Information

When Dedsis products, applications, software, or digital services are used, certain technical information may be processed where necessary to provide the relevant functionality.

This may include:

  • Device-related technical information;

  • Application-generated information;

  • Measurement or scan-related technical data;

  • Analysis requests and results;

  • License and activation information;

  • Diagnostic and error information;

  • Technical metadata associated with the use of the relevant service.

Not all technical or measurement information constitutes personal data. This Privacy Policy applies to such information only to the extent that it constitutes personal data under applicable law.

3. Mobile Applications and Device Permissions

Certain Dedsis mobile applications may require access to device functions or permissions necessary for the operation of the relevant product or application functionality.

Depending on the device, operating system, application version, and features used, permissions may include:

  • Bluetooth / Nearby Devices – to discover, connect to, and communicate with compatible Dedsis products;

  • Location – where required by the operating system or necessary for particular application functionality;

  • Camera – where required for visualization, augmented reality, or other supported functionality;

  • Device storage or files – where necessary to save, open, export, import, or process user-generated information, measurements, images, or reports.

Dedsis uses device permissions only for purposes reasonably connected with providing the relevant functionality.

Users may generally control application permissions through their device settings. Restricting or disabling permissions may cause certain application or product features to become unavailable or function incorrectly.

Dedsis does not use Bluetooth, location, or camera permissions for unrelated behavioural advertising or user profiling.

4. Purposes of Processing

We may process personal data for purposes including:

  • Responding to inquiries and pre-contractual requests;

  • Processing and fulfilling orders;

  • Issuing invoices and administering payments;

  • Arranging shipping and delivery;

  • Providing products, applications, software, licenses, and digital services;

  • Activating and administering software or product licenses;

  • Providing requested analysis or other product functionality;

  • Providing customer and technical support;

  • Diagnosing technical issues;

  • Managing returns, warranties, complaints, and conformity matters;

  • Maintaining the security, reliability, and functionality of our products, applications, website, and services;

  • Preventing fraud, misuse, unauthorized access, or security incidents;

  • Improving products and services where permitted by applicable law;

  • Maintaining appropriate business, accounting, tax, and transaction records;

  • Establishing, exercising, or defending legal claims;

  • Complying with applicable legal and regulatory obligations;

  • Providing marketing communications where permitted by law.

5. Legal Bases for Processing

Depending on the circumstances, Dedsis processes personal data on one or more of the following legal bases under Article 6 GDPR:

Performance of a Contract or Pre-Contractual Measures

This includes processing necessary to:

  • Respond to purchase requests;

  • Process orders;

  • Receive and administer payments;

  • Arrange delivery;

  • Provide purchased products, software, licenses, or services;

  • Provide customer support and after-sales services.

Compliance with Legal Obligations

We may process information where necessary to comply with accounting, taxation, regulatory, record-keeping, or other legal requirements.

Legitimate Interests

Where appropriate, Dedsis may process personal data where necessary for legitimate business interests, including:

  • Protecting our products, website, software, systems, and business;

  • Preventing fraud, misuse, and security incidents;

  • Diagnosing technical problems;

  • Providing and improving customer support;

  • Maintaining service reliability;

  • Protecting intellectual property and other legal rights;

  • Establishing, exercising, or defending legal claims.

Where processing is based on legitimate interests, we consider whether those interests are overridden by the rights and freedoms of the individual.

Consent

Where required by applicable law, we may rely on consent for matters such as:

  • Certain marketing communications;

  • Non-essential cookies and similar technologies;

  • Certain optional application permissions or features.

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. Product, Measurement and Analysis Data

Certain Dedsis products and services may process technical, measurement, scan, visualization, or analysis-related information in order to provide requested functionality.

Depending on the feature used, processing may occur on the user's device or through technical infrastructure and service providers used by Dedsis.

Such information may be processed where reasonably necessary to:

  • Provide the requested functionality or analysis;

  • Generate or deliver results or reports;

  • Maintain software and service functionality;

  • Diagnose technical issues;

  • Protect against misuse or security incidents;

  • Improve reliability, performance, or service quality where permitted by applicable law.

Dedsis does not disclose confidential technical details concerning its algorithms, software architecture, processing methods, security architecture, analysis methods, models, prompts, source code, infrastructure configuration, or other proprietary technology except where disclosure is required by applicable law.

7. Automated and AI-Assisted Functionality

Certain Dedsis products or services may include automated, algorithmic, or AI-assisted functionality intended to process or analyze technical information.

Such functionality may process technical or measurement information necessary to provide a requested analysis or service.

Unless expressly stated otherwise, Dedsis does not use such functionality to make solely automated decisions concerning individuals that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR.

Technical analysis of measurement or scanning information does not, by itself, constitute automated decision-making about an individual.

Dedsis does not publicly disclose proprietary algorithms, models, prompts, processing methods, software implementation, technical architecture, or other confidential technology except where disclosure is legally required.

8. Sharing of Personal Data

Dedsis does not sell personal data.

We may disclose or make personal data available only where reasonably necessary to provide our products and services, operate our business, fulfil contractual obligations, comply with legal requirements, or protect legitimate rights.

Recipients or categories of recipients may include:

  • Banks and payment service providers;

  • Courier, shipping, fulfilment, and logistics providers;

  • Website, hosting, cloud, infrastructure, and IT service providers;

  • Software and technical service providers;

  • Security and fraud-prevention service providers;

  • Accounting, tax, legal, and other professional advisers;

  • Analytics or cookie-related service providers where lawfully enabled;

  • Business partners or contractors where necessary for a specific service;

  • Public authorities, courts, regulators, or law-enforcement bodies where disclosure is legally required.

We seek to limit disclosures to information reasonably necessary for the relevant purpose.

Where a service provider processes personal data on behalf of Dedsis, appropriate contractual and data-protection requirements are applied where required by law.

9. International Data Transfers

Dedsis operates internationally and may use service providers, contractors, logistics providers, technical infrastructure, or business partners located in different countries.

Where personal data is transferred outside the European Economic Area (EEA), Dedsis will use an appropriate lawful transfer mechanism or safeguard where required by applicable data-protection law.

Depending on the circumstances, this may include:

  • A European Commission adequacy decision;

  • Appropriate safeguards such as approved Standard Contractual Clauses;

  • Other lawful transfer mechanisms available under the GDPR.

Personal data is shared internationally only where reasonably necessary for the relevant purpose and subject to applicable legal requirements.

The specific technical routing, infrastructure, systems, service providers, or architecture used to provide Dedsis services may change from time to time and is not disclosed except where disclosure is required by applicable law.

10. Data Retention

Dedsis retains personal data only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, accounting, tax, contractual, warranty, security, and dispute-resolution requirements.

Retention periods may vary depending on the type and purpose of the information.

For example:

  • Accounting, invoice, and transaction records are retained for the period required by applicable Estonian accounting and tax legislation;

  • Order and customer-service records may be retained for the period reasonably necessary to fulfil transactions, provide after-sales support, address warranty or conformity matters, and establish or defend legal claims;

  • Marketing information based on consent may be retained until consent is withdrawn or the information is no longer required for the relevant purpose;

  • Technical, diagnostic, and security information may be retained for a period reasonably necessary for security, troubleshooting, fraud prevention, service operation, or legal purposes.

At the end of the applicable retention period, personal data will be deleted, anonymized, or otherwise handled in accordance with applicable law.

11. Cookies and Similar Technologies

Our website may use cookies and similar technologies for purposes including:

  • Essential website functionality;

  • Website and account security;

  • Remembering user preferences;

  • Analytics where enabled and permitted;

  • Other optional functionality where applicable.

Non-essential cookies and similar technologies will be used in accordance with applicable consent requirements.

For further information about cookies and available choices, please see our Cookie Policy.

12. Marketing Communications

Dedsis may send marketing communications where the recipient has provided consent or where another lawful basis permitted by applicable law applies.

Users may unsubscribe from direct electronic marketing at any time by using an available unsubscribe mechanism or by contacting:

info@dedsis.com

Withdrawal from marketing communications does not affect transactional, contractual, technical, security, or other non-marketing communications that Dedsis may need to send.

Dedsis does not use location, Bluetooth, or camera permissions for unrelated behavioural advertising or marketing profiling.

13. Data Security

Dedsis implements appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful access, use, alteration, disclosure, loss, or destruction.

Security measures are selected taking into account the nature and risks of the processing and may include appropriate access controls, authentication, secure transmission, system protections, backups, and restrictions on access to personal data.

For security and legitimate business reasons, Dedsis does not publicly disclose detailed information concerning its security architecture, authentication mechanisms, infrastructure configuration, internal systems, cybersecurity controls, or other security-sensitive information except where required by applicable law.

No electronic transmission, network, software, or storage system can guarantee absolute security. Dedsis therefore applies measures appropriate to the nature and risks of the processing but does not guarantee that unauthorized access or other security incidents can never occur.

14. Your Rights Under the GDPR

Subject to the conditions and limitations provided by applicable law, individuals may have the following rights:

  • Right of access – to obtain information about whether and how personal data is processed and to receive a copy where applicable;

  • Right to rectification – to have inaccurate or incomplete personal data corrected;

  • Right to erasure – to request deletion of personal data where the applicable legal requirements are satisfied;

  • Right to restriction of processing – to request restriction of processing in certain circumstances;

  • Right to data portability – to receive certain personal data in a structured, commonly used, machine-readable format and, where applicable, transmit it to another controller;

  • Right to object – to object to certain processing based on legitimate interests;

  • Right to object to direct marketing – to object at any time to processing for direct-marketing purposes;

  • Right to withdraw consent – where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal;

  • Rights relating to automated decision-making – where applicable under the GDPR.

These rights are not absolute and may be subject to conditions, limitations, or exceptions provided by applicable law.

15. Exercising Your Rights

To exercise data-protection rights or ask questions concerning the processing of personal data, contact:

info@dedsis.com

Dedsis may request reasonable information necessary to verify the identity of the person making a request and to protect personal data against unauthorized disclosure.

Dedsis will respond to valid requests without undue delay and, in principle, within one month, as required by the GDPR.

Where permitted by applicable law, this period may be extended, including where a request is particularly complex or where multiple requests have been received.

Dedsis may refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive where permitted by applicable law.

16. Right to Lodge a Complaint

If you believe that Dedsis has processed your personal data in violation of applicable data-protection law, you may contact Dedsis so that the matter can be investigated.

You also have the right to lodge a complaint with a competent data-protection supervisory authority.

As Dedsis OÜ is established in Estonia, the Estonian supervisory authority is:

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)

Depending on the circumstances, individuals may also have the right to contact another competent supervisory authority within the European Union.

17. Children

Dedsis products, website sales, and commercial services are not specifically directed at children.

Dedsis does not knowingly seek to collect personal data from children for marketing purposes.

If Dedsis becomes aware that personal data relating to a child has been processed without an appropriate legal basis where one is required, reasonable steps will be taken to address the matter in accordance with applicable law.

18. Third-Party Websites and Services

Our website, applications, products, or communications may contain links to or interact with websites, applications, platforms, operating systems, payment services, communication networks, or other services operated independently by third parties.

Dedsis does not control independent third parties and is not responsible for their separate privacy practices, content, terms, security, or processing activities except to the extent responsibility cannot lawfully be excluded.

Users should review the privacy information and terms provided by the relevant third party before providing personal data directly to them.

19. Legal Requirements and Protection of Rights

Dedsis may preserve, use, or disclose information where reasonably necessary and permitted or required by applicable law to:

  • Comply with legal or regulatory obligations;

  • Respond to lawful requests from courts, authorities, regulators, or law-enforcement bodies;

  • Protect the rights, property, security, systems, products, customers, or legitimate interests of Dedsis or others;

  • Investigate suspected fraud, misuse, unauthorized access, security incidents, or violations of applicable terms;

  • Establish, exercise, or defend legal claims.

Nothing in this Privacy Policy requires Dedsis to disclose confidential business information, trade secrets, proprietary technology, security-sensitive information, or other protected information except where disclosure is required by applicable law.

20. Business Transfers and Corporate Changes

If Dedsis undergoes a merger, acquisition, restructuring, financing, sale of assets, transfer of business, or similar corporate transaction, personal data may be disclosed or transferred where reasonably necessary in connection with that transaction and in accordance with applicable law.

Any recipient of personal data will be subject to applicable data-protection obligations.

21. Changes to This Privacy Policy

Dedsis may update this Privacy Policy from time to time to reflect changes in its products, services, technology, processing activities, business operations, or applicable legal requirements.

The current version will be published on the Dedsis website together with its effective date.

Where required by applicable law, material changes affecting the processing of personal data will be communicated appropriately and additional consent will be requested where consent is legally required.

Continued use of the website or services alone will not constitute consent to a new processing activity where applicable law requires specific consent.

22. Contact

For privacy and data-protection questions, requests, or concerns:

Dedsis OÜ
Registration No.: 16710092
VAT ID: EE102685323
Address: Madara tn 31, 10613 Tallinn, Estonia
Email: info@dedsis.com
Website: www.dedsis.com

Dedsis OÜ is committed to processing personal data lawfully, fairly, transparently, and securely in accordance with applicable data-protection law.

bottom of page