Version 1 · effective from 10 August 2026
1. Controller
Eesti Endodontia Selts MTÜ (registry code 80417487), L. Puusepa tn 1a, 50406 Tartu, Estonia. For privacy matters, email info@endodontiaselts.ee. The Society has not appointed a data protection officer; requests are handled by the EES management board.
2. What we use and why
Account and security
Name, email, securely hashed password, email verification and password-recovery records, sessions, IP address and browser information. We need these to create and operate accounts and prevent misuse.
Legal basis: performance of a contract or steps before entering into one, and the Society’s legitimate interest in service security.
Membership applications and membership
Name and contact details, practitioner code, clinic, member type, billing details, application and membership status, and necessary review history. We use these to review applications, manage membership and provide member services.
Legal basis: steps taken at your request, administration of the membership relationship, legal obligations and the Society’s legitimate interest in managing its membership.
Event registration
Participant name and contact details, organisation, ticket and session selections, eligibility basis, registration and attendance status, and necessary organisational notes. We use these to fulfil the registration, communicate with participants and organise the event.
Legal basis: performance of a contract or pre-contractual steps taken at your request.
Invoices and payments
Billing recipient, address and registry code, invoice number, amount, payment status and related dates. We use these for invoicing, payment reconciliation and accounting.
Legal basis: performance of a contract and statutory accounting obligations.
Service messages, support and audit
Transactional-message details and delivery outcome, support correspondence, and a limited history of administrative and security events. We use these to evidence service delivery, resolve errors and protect the system.
Legal basis: the basis applicable to the related service and the Society’s legitimate interest in reliability, accountability and legal claims.
Fields marked as required are needed to process an account, membership application, registration or invoice. Without them, we may be unable to provide the relevant service. Do not enter health data or other sensitive information in free-text fields. EES does not make decisions about you based solely on automated processing or profiling.
3. Sources and recipients
We obtain data mainly from you, your use of the account, and membership, registration and payment actions performed by the EES management board. Where necessary, we verify membership against the existing membership register.
- EES management-board members and authorised organisers, within their assigned duties;
- providers of application, database and private-file hosting, email delivery and backups;
- banking and accounting service providers, to the necessary extent;
- auditors, advisers or public authorities where there is a lawful need.
Service providers may change over time; you can ask the EES contact address for information about the recipients currently in use. If data must be transferred outside the European Economic Area, we will use a GDPR-compliant safeguard and provide further information where required.
4. How long we keep data
- Accounting documents
- 7 years from the end of the relevant financial year.
- Ended membership and paid or cancelled registration
- Up to 3 years after the relationship or event ends, except for accounting data.
- Rejected or abandoned membership application
- 12 months after the decision or last activity.
- Waiting list
- 30 days after the event ends or withdrawal.
- Unpaid or abandoned event registration
- 90 days after the event ends or cancellation if no accounting document was created.
- Closed account
- Usually 30 days after a verified closure request; required financial evidence remains separately until its own deadline.
- Session and authentication data
- A session lasts up to 7 days or until logout/revocation; a reset link lasts 1 hour and a verification link 24 hours.
- Transactional-message content
- 30 days after successful delivery and 90 days after final failure; expired authentication links are removed earlier.
- General administrative and security audit
- Up to 3 years, with only the necessary information.
- Ticket QR files
- 30 days after the event ends.
- Technical logs
- Usually 30 days.
- Backups
- The contracted rolling period, never longer than 90 days; erased data is not returned to ordinary use.
For a specific dispute, audit or security incident, we may retain the limited information needed until the documented legal matter ends. At the end of the applicable period, data is deleted or irreversibly anonymised.
5. Your rights
Depending on the circumstances, you may have the right to:
- receive confirmation and a copy of your personal data;
- correct inaccurate information;
- request erasure or restriction of processing;
- object to processing based on legitimate interests;
- receive data you provided in a machine-readable format where portability applies;
- withdraw consent where a particular optional activity relies on consent.
Send requests to info@endodontiaselts.ee. We may ask for proportionate additional information to verify identity. We respond without undue delay and ordinarily within one month.
You may also complain to the Estonian Data Protection Inspectorate.
6. Cookies and external links
When you sign in, we use cookies necessary for authentication and security. The website does not currently use advertising or analytics cookies. If you follow an Instagram or Facebook link, you leave the EES website and the other service’s terms govern further processing.
7. Security and changes to this notice
We use role-based access, securely hashed passwords, restricted private-file access, logging, backups and other appropriate technical and organisational safeguards. No system removes every risk; please report a suspected personal-data breach immediately to info@endodontiaselts.ee.
We update this notice when the service, a processing purpose or a legal requirement changes materially. We will publish the new version and effective date here and communicate important changes in an appropriate way.
