SUNIO COMPANIES’ PRIVACY POLICY
Add a Title
Add paragraph text. Click “Edit Text” to update the font, size and more. To change and reuse text themes, go to Site Styles.
Effective date: 1st of September 2026
1. Introduction
Sunio Group OÜ and its group companies, including Sunio OÜ, Sunio IT OÜ, Galandrex Tõlkebüroo OÜ and E-Resident Store OÜ (collectively “Sunio Companies”), process personal data in connection with their business activities, websites, services and digital systems.
This Privacy Policy explains how personal data is collected, used, stored and shared in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
This Policy applies to:
-
Sunio websites, including sunio.ee and e-resident.store;
-
the Sunio Client Portal, currently available through app.sunio.ee;
-
accounting, document-management and other software used in providing Sunio services;
-
communication and customer support systems;
-
payment and billing systems;
-
identity, KYC, KYB and compliance systems;
-
cloud services, databases and integrations used by Sunio; and
-
other business processes in which Sunio Companies process personal data.
2. Data Subjects and Processing Roles
2.1. Whose Data Do We Process?
We may process personal data relating to:
-
Clients and prospective clients;
-
directors, shareholders and beneficial owners of client companies;
-
applicants and persons involved in company formation;
-
authorised representatives and contact persons;
-
users of Sunio websites and the Client Portal;
-
employees and job applicants;
-
suppliers, subcontractors and business partners;
-
customers, employees or counterparties of our Clients where their data appears in accounting or other documents processed by Sunio; and
-
other persons whose data is relevant to services provided by Sunio.
2.2. Controller Role
As a general rule, the Sunio company providing the relevant service acts as the controller in relation to personal data processed for:
-
managing the customer relationship;
-
onboarding and compliance;
-
account and Client Portal administration;
-
billing;
-
service administration;
-
legal obligations; and
-
Sunio’s own business operations.
Certain systems and administrative functions may be operated centrally within the Sunio group. Personal data may therefore be processed by another Sunio group company on behalf of or in support of the company providing the service.
Depending on the particular processing activity, Sunio group companies may act as separate controllers or processors.
2.3. Processor Role
Where a Sunio company processes personal data solely on behalf of a Client – for example, personal data contained in accounting documents, payroll information or certain tax-reporting material – the Client may act as controller and the relevant Sunio company as processor.
Where required, such processing is governed by appropriate data-processing terms.
3. Legal Bases and Purposes of Processing
We process personal data only where there is an applicable legal basis.
3.1. Performance of a Contract
We process data where necessary to:
-
provide purchased services;
-
administer the Client Portal;
-
manage the customer relationship;
-
process service orders;
-
provide accounting, tax, company or other services;
-
issue invoices and manage subscriptions;
-
communicate with Clients; and
-
process service-related requests.
3.2. Legal Obligations
We process personal data where required to comply with applicable legal obligations, including:
-
accounting and tax requirements;
-
anti-money laundering and counter-terrorist financing obligations;
-
sanctions requirements;
-
statutory record-keeping requirements; and
-
lawful requests from competent authorities.
3.3. Legitimate Interests
Where appropriate, we process personal data based on legitimate interests, including:
-
securing Sunio systems and the Client Portal;
-
preventing fraud and misuse;
-
maintaining audit and system logs;
-
improving internal business processes;
-
protecting and enforcing legal rights;
-
ensuring service quality; and
-
managing business relationships.
Where processing is based on legitimate interests, we take account of the rights and interests of affected individuals.
3.4. Consent
Consent may be used where required, including for:
-
optional marketing activities;
-
non-essential cookies and tracking technologies; and
-
other optional processing activities where consent is the appropriate legal basis.
Consent may be withdrawn at any time without affecting processing lawfully performed before withdrawal.
4. How We Collect Personal Data
We may collect personal data:
-
directly from the individual;
-
from a Client or its authorised representative;
-
through the Client Portal;
-
through Sunio websites and forms;
-
through email or other communications;
-
from identity and verification providers;
-
from banks, payment providers and accounting systems;
-
from public registers and databases;
-
from government authorities;
-
from sanctions, PEP and compliance databases;
-
from publicly available sources; and
-
from contractual partners and service providers.
5. Categories of Personal Data
Depending on the relevant service, we may process the following categories.
5.1. Contact and Account Data
This may include:
-
name;
-
email address;
-
telephone number;
-
postal or residential address;
-
customer number;
-
Client Portal account identifier; and
-
preferred communication details.
5.2. Authentication and Security Data
When you use the Client Portal or other Sunio digital services, we may process:
-
login email;
-
authentication and verification records;
-
login times;
-
IP address;
-
browser and device information;
-
session information;
-
account changes;
-
security logs; and
-
records relating to suspected unauthorised access.
5.3. Identification and Personal Data
This may include:
-
date of birth;
-
personal identification number;
-
citizenship;
-
country of residence;
-
tax residency;
-
residential address;
-
identity-document details;
-
copies of identity documents; and
-
proof-of-address documents.
5.4. Company, KYC and KYB Data
For onboarding and compliance purposes we may process:
-
company name and registry information;
-
company activity and business model;
-
management and representation information;
-
shareholders and ownership percentages;
-
beneficial owners;
-
source-of-funds or transaction-related information where required;
-
countries of operation;
-
customers and suppliers;
-
expected transaction activity;
-
questionnaire responses;
-
verification status;
-
sanctions and PEP screening results;
-
relevant adverse-media information; and
-
other information required for compliance purposes.
5.5. Financial and Billing Data
We may process:
-
invoices;
-
payment status;
-
transaction history;
-
subscription and service-plan information;
-
billing address;
-
payment-provider identifiers;
-
payment method metadata; and
-
information required for reconciliation of payments.
Full payment-card data may be processed directly by payment providers such as Stripe rather than by Sunio.
5.6. Accounting and Tax Data
Where Sunio provides accounting or tax services, we may process:
-
purchase and sales invoices;
-
receipts;
-
bank statements;
-
payment account and transaction information;
-
payroll information;
-
employee and contractor information;
-
customer and supplier information;
-
contracts;
-
payment gateway reports;
-
sales reports;
-
spreadsheets;
-
accounting records;
-
tax information; and
-
other documents uploaded or otherwise provided for accounting purposes.
These documents may contain personal data relating to persons other than the Client or Client Portal user.
5.7. Communication Data
We may process:
-
emails;
-
customer-support correspondence;
-
Client Portal notifications;
-
service requests;
-
complaints;
-
communications with accountants and support staff; and
-
other records of interactions with Sunio.
5.8. Publicly Available Information
Where relevant to services, onboarding or compliance, we may use information contained in:
-
public registers;
-
company databases;
-
sanctions and PEP databases;
-
professional websites;
-
public media sources; and
-
other publicly available sources.
6. Sunio Client Portal
6.1. Purpose
The Client Portal is used to administer the relationship between Sunio and its Clients and may be used for:
-
onboarding;
-
KYC/KYB;
-
displaying and maintaining company information;
-
document submission;
-
accounting-document collection;
-
service and compliance reminders;
-
billing information;
-
subscription administration;
-
ordering additional services;
-
providing company documents; and
-
other service-related functions.
6.2. Data Synchronisation
Information changed in the Client Portal may be synchronised with other systems used to provide Sunio services.
For example, changes to a Client’s login or contact email may be synchronised with:
-
Sunio’s customer records;
-
billing systems;
-
payment-service-provider records;
-
communication systems; and
-
other systems where the same contact information is needed to provide the service.
6.3. Logs and Security
For security, evidence and system-administration purposes, Sunio may retain logs showing:
-
logins;
-
document uploads;
-
changes to account or company information;
-
orders;
-
submissions;
-
status changes; and
-
other material actions in the Client Portal.
Such records may be used to investigate technical incidents, unauthorised access, disputes and compliance matters.
7. Cookies and Similar Technologies
Sunio websites and the Client Portal may use cookies and similar technologies.
7.1. Strictly Necessary Technologies
Strictly necessary cookies or similar technologies may be used where necessary to:
-
keep users signed in;
-
maintain sessions;
-
provide security functions;
-
prevent fraud or abuse;
-
remember essential preferences; and
-
provide functionality expressly requested by the user.
Where such technologies are strictly necessary for providing the requested service, they may be used without separate consent where permitted by applicable law.
7.2. Optional Cookies
Analytics, advertising or other non-essential tracking technologies are used only where the required legal basis, including consent where applicable, has been obtained.
Users may change or withdraw cookie consent through the cookie-preference functionality made available on the relevant website.
Further details may be provided in Sunio’s Cookie Policy.
8. Sharing Personal Data
8.1. Within the Sunio Group
Personal data may be shared between Sunio group companies where necessary for:
-
service delivery;
-
administration of the Client Portal;
-
accounting and tax work;
-
customer support;
-
IT administration;
-
compliance;
-
billing; or
-
other legitimate internal purposes.
Access is limited according to role and business need.
8.2. Service Providers
Sunio may use third-party providers for, among other things:
-
payment processing, including Stripe;
-
identity and compliance verification, including Veriff where used;
-
website and e-commerce services;
-
Client Portal hosting, database, authentication and infrastructure;
-
cloud hosting and cybersecurity;
-
transactional and business email;
-
document storage and document processing;
-
accounting and expense-management systems, including SmartAccounts, Directo and Envoice where used;
-
Microsoft 365 and SharePoint services where used;
-
payroll systems;
-
electronic signatures;
-
customer support and communication systems; and
-
other technical services required to provide Sunio services.
We provide service providers only with the information necessary for the relevant purpose and require appropriate confidentiality and data-protection safeguards.
8.3. Authorities
Personal data may be disclosed to:
-
courts;
-
police;
-
the Estonian Tax and Customs Board;
-
the Financial Intelligence Unit;
-
business registers;
-
other supervisory or government authorities; or
-
other recipients,
where required or permitted by law.
8.4. Professional Advisers and Legal Claims
Personal data may also be provided to auditors, legal advisers, insurers, accountants or other professional advisers where reasonably necessary to obtain advice, comply with obligations, or establish, exercise or defend legal claims.
9. International Data Transfers
Sunio aims to use data-processing arrangements that provide appropriate protection for personal data.
Some service providers or their subprocessors may process personal data outside Estonia or the European Economic Area.
Where personal data is transferred to a country outside the European Economic Area and that country is not covered by an applicable European Commission adequacy decision, Sunio will use an appropriate transfer mechanism required by applicable data-protection law, such as the European Commission’s Standard Contractual Clauses, where applicable.
Further information about relevant safeguards may be requested from support@sunio.ee.
10. Data Security
Sunio applies technical and organisational measures appropriate to the nature and risk of processing, including, where appropriate:
-
access controls;
-
role-based permissions;
-
authentication measures;
-
encryption in transit or at rest where appropriate;
-
system and security logging;
-
backups;
-
security updates;
-
access restrictions for staff and service providers; and
-
incident-management procedures.
No information system can be guaranteed to be completely secure, but Sunio takes reasonable measures to protect data against unauthorised access, disclosure, loss, alteration or destruction.
11. Data Retention
Personal data is retained only for as long as required for the purposes for which it was collected and for applicable legal, contractual or legitimate business requirements.
Different categories of data may therefore have different retention periods.
11.1. Client Portal and Account Data
Client Portal account and customer-administration data may be retained for the duration of the customer relationship and afterwards for the period reasonably required for legal, accounting, compliance, security or dispute-resolution purposes.
11.2. Accounting Data
Accounting records subject to statutory retention requirements are retained for the period required by applicable law.
Working copies of documents held in Client Portal or document-processing environments may be removed earlier where they are no longer required, including following transfer into the relevant accounting or document-storage system.
11.3. KYC and Compliance Data
Identity, KYC/KYB, sanctions and other compliance records are retained for the periods required by applicable anti-money laundering, sanctions and other legal obligations.
11.4. Billing Data
Invoices, payment and transaction records are retained for the periods required under accounting, tax and other applicable legal requirements.
11.5. Security Logs
Security and audit logs are retained for a period proportionate to their security, evidence and fraud-prevention purpose.
When data is no longer required, it is deleted, anonymised or otherwise securely disposed of unless continued retention is required by law.
12. Data Subject Rights
Subject to the conditions and limitations provided by the GDPR, individuals may have the right to:
-
access their personal data;
-
correct inaccurate or incomplete data;
-
request deletion of data;
-
request restriction of processing;
-
object to processing based on legitimate interests;
-
receive applicable data in a portable format;
-
withdraw consent where processing is based on consent; and
-
lodge a complaint with a competent supervisory authority.
Requests may be sent to:
We may need to verify the identity of the person making a request before acting on it.
13. Sunio as Processor
Where Sunio acts as a processor on behalf of a Client, Sunio:
-
processes personal data on documented instructions from the Client, except where otherwise required by law;
-
applies appropriate security measures;
-
uses subprocessors subject to appropriate data-protection obligations; and
-
assists the Client as reasonably required under applicable data-protection law.
Clients requiring further information about Sunio’s processor role may contact us.
14. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time to reflect:
-
changes to Sunio services or the Client Portal;
-
changes in service providers or technology;
-
legal or regulatory developments; or
-
improvements to privacy and security practices.
Material changes may be communicated by email, through the Client Portal or on a Sunio website.
The date of the latest version will be displayed at the beginning of this Policy.
15. Contact Information
Privacy-related inquiries may be sent to:
Järvevana tee 9-40, Tallinn 11314, Estonia
Contact Information
For any privacy-related inquiries, you can contact us at:
📩 support@sunio.ee
📍 Järvevana tee 9-40, Tallinn 11314, Estonia
