WiSec OÜ operates Tormine, an AI-assisted cyber compliance, risk and security-testing workspace, available at tormine.com (this site) and my.tormine.com (the application). This Privacy Policy explains what personal data we process, why, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR) and Estonian law.
Who we are
| Company | WiSec OÜ |
| Registry code | 14878500 |
| VAT | EE102379134 |
| Address | Piiri 4a, Kopli küla, Rae vald, 75321 Harjumaa, Estonia |
| info@wisec.ee | |
| Website | tormine.com |
For the account and personal data we process to run the service, WiSec OÜ is the data controller. For the organisational data you upload into Tormine — which may include personal data about your own staff, customers or third parties — WiSec OÜ acts as a data processor on your behalf, processing it only to provide the service and on your instructions. We have no separate Data Protection Officer; questions can be sent to the email above.
What data we collect
We only collect the data we genuinely need to provide the service. There is no marketing-tracking step.
When you request access or create an account:
- Company name, registry code and VAT number
- Contact person's full name, role, work email and phone
- Company billing address (where invoicing applies)
When you use the platform:
- The content you create or upload — compliance assessments, policies, evidence, risk and supplier registers, pentest findings and the documents and messages you submit
- Support tickets, contact-form and early-access requests and the messages you send
- Login history (timestamp + IP address) for security audit
- A session identifier so you stay logged in
We do not collect:
- Special categories of personal data for our own purposes (any such data you choose to upload is processed only as your processor)
- Payment-card numbers — invoices are settled by bank transfer; we never see your card data
- Location data beyond the IP address of your logins
- Behavioural / advertising profiles
Why we process it (legal basis)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Operating your account and providing the platform | Contract performance — Art. 6(1)(b) |
| Issuing invoices and keeping accounting records | Legal obligation — Art. 6(1)(c), Estonian Accounting Act § 12 |
| Login history and security audit | Legitimate interest in securing the platform — Art. 6(1)(f) |
| Replying to your support tickets and contact-form messages | Contract performance / legitimate interest — Art. 6(1)(b)/(f) |
We do not use your data for advertising or profiling. We do not sell your data to anyone.
Cookies
The platform uses only strictly necessary functional cookies:
- A session cookie (
tormine_session) that keeps you logged in. The cookie carries only an opaque session ID; all session data is stored on our server. - A CSRF-protection cookie (
XSRF-TOKEN) that prevents cross-site request forgery on form submissions.
No tracking cookies, no analytics cookies, no third-party advertising scripts. Because we only use strictly necessary cookies, no cookie-consent banner is legally required.
Who has access to your data
Inside WiSec OÜ, only authorised staff with a business reason can access your data. Outside the company, your data may be shared with:
- Our accountant — invoices and supporting documents, as required by the Estonian Accounting Act
- The Estonian Tax and Customs Board (Maksu- ja Tolliamet) — when legally compelled, e.g. tax audits
- Sub-processors strictly necessary to run the service (e.g. transactional email, cloud/hosting infrastructure) — bound by data-processing agreements and located within the European Economic Area
The platform is hosted on infrastructure inside the EU/EEA. We do not transfer your data to recipients in third countries without an adequate level of data protection or appropriate safeguards under GDPR Chapter V.
How long we keep it
- Invoice and accounting records: 7 years from the end of the relevant accounting year, as required by § 12 of the Estonian Accounting Act (Raamatupidamise seadus). This is a legal obligation and applies regardless of any account-deletion request.
- Account and the content you upload: for the life of your account; when you close your account, deleted or returned within 30 days — except records that fall under the 7-year accounting retention above.
- Login history / audit logs: 24 months from the event, then deleted.
- Contact-form / early-access messages without an account: 24 months, then deleted.
Your rights under GDPR
You have the right to:
- Access — request a copy of the personal data we hold about you (Art. 15)
- Rectification — correct inaccurate or incomplete data (Art. 16)
- Erasure ("right to be forgotten") — have your data deleted (Art. 17), subject to the legal-retention limits above
- Restriction — limit how we process your data while a dispute is resolved (Art. 18)
- Portability — receive your data in a machine-readable format (Art. 20)
- Object — to any processing based on legitimate interest (Art. 21)
- Lodge a complaint with the supervisory authority — in Estonia that is the Andmekaitse Inspektsioon (aki.ee)
To exercise any of these rights, email info@wisec.ee from the address registered to your account, or contact your account manager. We reply within one month of receiving a valid request. Where you are acting on behalf of an organisation whose data you uploaded, we will support that organisation as the controller in meeting these requests.
Important — right to erasure has limits. When you delete your account, we will:
- Delete or return your account profile, uploaded content, support messages and login history
- Keep invoices and accounting records for the remaining time required by the Estonian Accounting Act (up to 7 years). On these records, your name and contact details remain visible because they are part of a legally-required document. After the retention period expires, those records are deleted as well.
Data security
We protect your data with industry-standard measures:
- TLS / HTTPS for all platform traffic
- Strong password hashing (bcrypt); passwords are never stored in plain text
- Two-factor authentication (TOTP) available for all accounts
- Access logging for staff accounts; audit trail for administrative changes
- Regular backups, encrypted at rest
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the Andmekaitse Inspektsioon within 72 hours and inform affected individuals as required by Art. 33–34 GDPR.
Changes to this policy
We may update this policy when our processing activities change or when the law requires. Material changes will be announced in the platform at least 30 days before they take effect. The "last updated" date shown on this page always reflects the current version.
Contact
For any privacy question or to exercise your GDPR rights, write to:
WiSec OÜ Piiri 4a, Kopli küla, Rae vald, 75321 Harjumaa, Estonia Email: info@wisec.ee
Supervisory authority: Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee, aki.ee