Privacy Policy & Data Protection
2RUN OÜ is committed to protecting your personal data in strict compliance with the European Union General Data Protection Regulation (GDPR). We operate on the principle of data minimization and never sell client data.
Company Name: 2RUN OÜ
Registered Legal Address: Paavli tn 5a/1, Põhja-Tallinn, 10412 Tallinn, Harju maakond, Estonia
Commercial Register: Registered in the Estonian Commercial Register (Äriregister)
Direct Contact: hello@2run.dev
2. Core Principles of Data Governance
This Privacy Policy governs how 2RUN OÜ collects, manages, and safeguards personal data obtained through our website (https://2run.dev), client communications, software development contracts, and white-label agency partnerships.
We adhere strictly to the foundational principles articulated in Article 5 of the European Union General Data Protection Regulation (Regulation (EU) 2016/679):
- Lawfulness, Fairness, and Transparency: Personal data is processed lawfully and transparently with clear notice to data subjects.
- Purpose Limitation: Collected solely to scope, execute, and deliver web engineering services and agency partnerships.
- Data Minimization: We never collect extraneous personal data or run intrusive behavioral advertising scripts.
- Integrity and Confidentiality: All data is encrypted in transit and at rest in accordance with modern European cybersecurity standards.
3. Categories of Data We Process
We process only the information required to evaluate briefs, provide technical proposals, and deliver high-performance web systems:
- B2B Contact & Inquiry Data: Your name, work email address, company or agency name, website URL, and project brief details submitted via our contact forms or direct email correspondence.
- Technical Diagnostic Logs: Anonymized server logs generated when requesting resources from our edge network (including hashed IP address, user-agent, and HTTP request headers) solely for intrusion detection and infrastructure defense.
- No Third-Party Advertising Trackers: We do not deploy Meta Pixels, invasive cross-site ad networks, or data broker beacons on
2run.dev.
4. Legal Grounds for Processing (GDPR Art. 6)
We collect and process your information under the following statutory grounds:
- Performance of a Contract (Art. 6(1)(b)): Necessary to enter into or perform software development agreements, agency white-label partnerships, or Statement of Work (SOW) deliverables.
- Legitimate Interests (Art. 6(1)(f)): Necessary to protect our digital infrastructure against DDoS attacks and respond to commercial B2B inquiries.
- Legal Compliance (Art. 6(1)(c)): Processing mandated by statutory Estonian tax, corporate governance, and financial accounting laws.
5. Data Retention & Security Standards
We retain commercial inquiry data only as long as necessary to fulfill project requirements or comply with mandatory statutory retention periods under Estonian commercial law (typically 7 years for financial and contractual records).
All customer data is secured with TLS 1.3 encryption in transit and AES-256 encryption at rest. Internal access to repository credentials, staging links, and client briefing documents is restricted to vetted senior engineers via multi-factor authentication.
6. Your Statutory Rights Under EU Law
Under GDPR (Articles 15 through 22), you maintain the following non-waivable statutory rights regarding your personal data:
- Right of Access (Art. 15): Request confirmation of whether your data is being processed and obtain a copy.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete records.
- Right to Erasure ("Right to be Forgotten", Art. 17): Request permanent deletion where no overriding statutory obligation compels retention.
- Right to Restriction of Processing (Art. 18): Request temporary freezing of data processing under certain dispute conditions.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
7. Inquiries & Supervisory Authority
To exercise any statutory rights, or if you have questions regarding our data handling protocols, contact our team directly at:
2RUN OÜ — Data Protection Desk
Email: hello@2run.dev
Address: Paavli tn 5a/1, Tallinn, 10412, Estonia
You also possess the statutory right to lodge a formal complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local European data protection authority.