Last updated: May 10, 2026
The data controller for this service is:
[FIE_NAME]
Registration number: [FIE_REGISTRATION_NUMBER]
Address: [FIE_ADDRESS]
Email: [CONTACT_EMAIL]
Website: [DOMAIN]
We operate as an FIE (sole proprietor) registered in Estonia and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Estonian data protection law.
We collect and process the following categories of personal data:
| Data Category | Specific Data | Source |
|---|---|---|
| Email address | Provided during checkout | You (via Stripe) |
| IP address | Collected automatically by web server | Your browser |
| Payment data | Card details processed by Stripe (we never see full card numbers) | Stripe |
| localStorage data | Tour unlock tokens, cookie consent, language preference | Your browser (local only) |
| Usage analytics | Page views, device type, referrer (anonymous, no personal identifiers) | Cloudflare Web Analytics |
| Chat messages | Questions sent to AI tour guide (not stored after session) | You |
We process your personal data based on the following legal grounds:
We retain data only as long as necessary:
We share data with the following processors to provide the Service:
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Email, card details, amount | USA (SCCs) |
| Cloudflare, Inc. | Website hosting, CDN, analytics | IP address, page views | Global (SCCs) |
| Anthropic | AI chatbot responses | Chat messages (not stored) | USA (SCCs) |
| ElevenLabs (historical) | Audio narration generation (one-time, not ongoing) | Tour scripts (no personal data) | USA |
| Railway | Backend API hosting | API requests, server logs | USA (SCCs) |
We do NOT sell, rent, or share your personal data with any party for marketing purposes.
As a data subject, you have the following rights:
To exercise any of these rights, email us at: [CONTACT_EMAIL]. We will respond within 30 days.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):
Andmekaitse Inspektsioon
Tatari 39, 10134 Tallinn, Estonia
Phone: +372 627 4135
Email: info@aki.ee
Website: www.aki.ee
Our paid Service is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16 without parental consent. If you are under 16, please do not purchase tours or provide personal information. Free tour content (Stop 1) is accessible without providing any personal data.
Some of our processors (Stripe, Cloudflare, Anthropic, Railway) are based in the United States. For these transfers, we rely on the EU Standard Contractual Clauses (SCCs) as the legal mechanism under GDPR Article 46(2)(c). Each processor maintains appropriate technical and organisational measures to protect your data.
We implement the following security measures:
We may update this Privacy Policy to reflect changes in our practices or legal obligations. Material changes will be communicated by updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance.
For privacy-related inquiries:
[FIE_NAME]
Email: [CONTACT_EMAIL]
Address: [FIE_ADDRESS]
This Privacy Policy complies with the EU General Data Protection Regulation (GDPR) and Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).
© 2026 Tallinn Old Town. All rights reserved.
Made for Tallinn Old Town