USUN MTÜ
Privacy Policy
How personal data is handled on the public Usun.ee site, donation form and payment flow.
Last updated: 25/06/2026
Controller and contact
The controller is USUN MTÜ, registry code 80672305. Questions about privacy, donations and payments can be sent to usun@usun.ee. The public site is used to introduce the portal, collect cooperation interest, enable support and share information related to support.
- public contact and complaint channel: usun@usun.ee;
- a phone number is not published as a separate public support channel; we use written support so payment and privacy requests remain traceable;
- official registry data can be checked in the Estonian Business Register.
What data we process
When you contact us by email, contact form, cooperation request, donation form or the recurring-support self-service, the processed data may include name, email address, phone number, message content, consent/timestamp, donation amount, frequency, selected recurring-payment duration, verification-code timestamp and payment technical status. To prevent abuse, we may also process keyed hashes of the IP address and user agent.
- visiting the public site does not create a user account;
- contact-form messages are stored and handled only in a secure admin environment;
- payment-card data is entered on a hosted payment page of LHV/SumUp or another payment service provider; USUN MTÜ does not store or see the full card number, CVC code or 3DS authentication data;
- for recurring payments, the application stores only the payment provider’s tokenized reference status/fingerprint and never exposes raw card tokens in public or admin responses;
- stored contact messages, donation records and payment-status events are visible only in restricted admin views according to role.
Purposes, legal basis and retention
Data is used to respond to requests, organize cooperation, handle support and fulfil legal obligations. Contact-form messages are retained by default for up to 365 days, after which they are reviewed and deleted. Accounting data is retained for the period required by law.
- responding to requests and legitimate interest in maintaining necessary communication;
- legal obligation for support payments and accounting;
- consent-based cookie preferences only when the user allows them.
Payment intermediaries and recipients
For card, wallet and bank payments, the donor may be redirected to the payment service provider’s environment. The payment intermediaries named on the website are AS LHV Pank / LHV Paytech payment environment and, where needed, SumUp EU Payments UAB. The payment provider processes payment data under its own terms and privacy rules; USUN MTÜ uses the payment status, reference and limited audit information received from the provider to manage the donation.
- card security checks, 3DS/SCA and wallet authentication take place in the payment provider’s environment;
- the website does not ask for or store full card numbers, CVC codes or internet-bank passwords;
- handling a payment dispute, refund or accounting document may require retaining the payment reference, amount, currency, time and provider status.
Rights and requests
You have the right to request access to your data, ask for inaccurate data to be corrected, object to processing, request an exportable copy or request deletion where the law does not require retention. Questions and deletion/export requests can be sent to usun@usun.ee. If you believe data is processed incorrectly, you may contact the Estonian Data Protection Inspectorate.