2026-06-27 (v0 draft)
v0 status (effective 2026-06-27): This document is published in v0 pending review by Estonian legal counsel. Final terms may differ after review. Existing data subject rights under this version are preserved per the GDPR provisions cited below. Review note: the §7 position on the free
/kidsand/discovertracks is to be confirmed by counsel.
Effective date: 2026-06-27 (v0 draft)
Last updated: 2026-10-09
Operator: A2est OÜ, the operator identified in the Terms (/terms §1)
Data Protection Officer: not appointed (operator below the §37
threshold at v0; DPO appointment deferred to v1 if processing scope
expands)
Lead supervisory authority: Andmekaitse Inspektsioon (AKI),
aki.ee
Contact for data requests: privacy@a2est.ee
This is the GDPR-specific legal-basis notice for A2est. It is
separate from the operational Privacy Policy at /privacy because
EU convention (and Estonian AKI practice) treats GDPR rights and lawful
basis as a distinct artifact from operational data-handling rules.
Where to read what:
/gdpr (this document) - your legal rights under GDPR, our
lawful basis for each processing activity, and how to exercise those
rights or complain./privacy - operational details: what we collect, retention,
third-party processors, security, international transfers./terms - service terms, subscriptions/refunds, reward programs.Under GDPR Article 6, each processing activity must have a lawful basis. A2est processes personal data under the following bases:
| Processing purpose | Lawful basis (GDPR Art. 6) | Notes |
|---|---|---|
| Account creation + authentication | (b) Contract | Required to provide the service you signed up for. |
| Lesson progress tracking | (b) Contract | Required to deliver personalised lesson state. |
| A2est AI tutor conversations | (b) Contract | Required to deliver the AI tutor service. |
| Payment processing | (b) Contract + (c) Legal obligation | Contract performance + 7-year retention under Estonian accounting law (Raamatupidamise seadus). |
| Expiry / renewal email | (b) Contract | Transactional, part of service delivery. |
| Marketing email | (a) Consent | Opt-in only. Withdrawable at any time. |
| Aggregated, anonymised analytics | (f) Legitimate interest | Cannot identify individuals. Opt-out via /account/data. |
| Security + fraud prevention | (f) Legitimate interest | Server-side rate limits, IP-based anti-abuse. |
| Legal compliance / law enforcement response | (c) Legal obligation | Only on valid legal request. |
Special-category data (Art. 9): A2est does not knowingly process special-category personal data (health, biometric, ethnic origin, political opinions, etc.). Estonian-language-learning conversation content may incidentally touch cultural or biographical topics but is not profiled on sensitive attributes.
Under GDPR, you have the following rights. Each is exercisable via
/account/data or by emailing privacy@a2est.ee.
| Right | What it means | How to exercise |
|---|---|---|
| Access (Art. 15) | Request a copy of all personal data we hold on you. | /account/data → Export. |
| Rectification (Art. 16) | Correct inaccurate personal data. | /account/data → Edit profile. |
| Erasure (Art. 17) - "right to be forgotten" | Delete your account and associated data. | /account/data → Delete account. 7-day deletion grace applies - you can cancel within 7 days. |
| Restriction of processing (Art. 18) | Pause our use of your data while a dispute is resolved. | Email privacy@a2est.ee. |
| Data portability (Art. 20) | Export your data in machine-readable format. | Lesson export (JSON, Anki, CSV) from /account/data. Full export at /account/data. |
| Object to processing (Art. 21) | For processing based on legitimate interest. | Email privacy@a2est.ee with the specific processing you object to. |
| Withdraw consent (Art. 7(3)) | For any processing based on consent (e.g. marketing email). | Email unsubscribe link, or /account/data. |
| Lodge a complaint (Art. 77) | File a complaint with the supervisory authority. | Andmekaitse Inspektsioon (AKI), aki.ee. |
We respond to data requests within 30 days. If a request is complex, we may extend to 60 days and notify you of the reason for the delay.
Accounts and paid courses are for adults (18+). We do not knowingly collect data from children under 16 (GDPR Art. 8 default). If we discover we have collected data from a child under 16, we delete it within 7 days.
If a parent or guardian believes a child has created an account, contact privacy@a2est.ee for immediate deletion.
A2est is operated in Estonia. Data is stored in EU regions of our cloud providers. No personal data is transferred outside the EU/EEA without your explicit consent or a GDPR Chapter V mechanism (e.g. Standard Contractual Clauses, adequacy decision).
Third-party processors that may process data on our behalf, and what
each one receives, are listed in /privacy §4. Where a processor
handles personal data outside the EU/EEA (for example Google for the AI
tutor or Stripe for card payments), the transfer relies on a GDPR
Chapter V mechanism such as Standard Contractual Clauses or the EU-US
Data Privacy Framework.
A2est does not make automated decisions about you that produce legal effects or similarly significantly affect you (GDPR Art. 22). The A2est AI tutor AI Tutor's pedagogical suggestions are recommendations, not decisions, and you can override them at any time.
Under GDPR Art. 35, a DPIA is required where processing is "likely to result in a high risk to the rights and freedoms of natural persons." We have assessed A2est at v0 and concluded that a full DPIA is not required at current scope, for the following reasons:
The free /kids and /discover tracks are anonymous public content:
they need no account, and using them stores no personal data on our
servers (see /privacy §2.5). They are therefore not a minors'
program in the sense of the list below.
If processing scope expands (e.g. minors' program, biometric voice biometrics for HARNO exam proctoring, large-scale B2B school district data), a DPIA must be conducted before that scope ships. This is a binding precondition, not a discretionary review.
GDPR Art. 32 requires "appropriate technical and organisational measures." A2est implements:
We will notify you by email at least 30 days before any material change takes effect. Continued use of the service after the effective date constitutes acceptance. If you do not accept the change, you may export your data and close your account before the effective date.
A2est OÜ (data controller), the operator identified in the Terms
(/terms §1)
Email: privacy@a2est.ee
Registered in Estonia.
Lead supervisory authority: Andmekaitse Inspektsioon (AKI) aki.ee Tatari 39, 10134 Tallinn, Estonia