GDPR Compliance Statement
EAS is committed to protecting personal data and to processing it in accordance with Regulation (EU) 2016/679 (the “GDPR”). This statement explains how EAS meets its obligations as a data controller. It is a statement of compliance and does not create obligations or liabilities for any other party.
Document control
| Version | 1.0 |
|---|---|
| Status | Approved |
| Document owner | Chief Operating Officer, EAS |
| Approver | [Management — on approval] |
| Date issued | 30 July 2026 |
| Next review | July 2027 |
| Applies to | All personal data processed by EAS as a controller. |
Contents
Data controllers
The following EAS group companies act as independent data controllers for the personal data described in this statement:
| Entity | Registration and address | Role |
|---|---|---|
| Easy Access System Project OÜ | Reg. 16244595 — Mustamäe tee 50, 10621 Tallinn, Estonia | Controller; provider of the EAS Solution |
| Neman OÜ | Reg. 14592263 — Mustamäe tee 50, 10621 Tallinn, Estonia | Controller; IOSS intermediary under Directive 2006/112/EC |
Our role
EAS acts as an independent controller within the meaning of Article 4(7) GDPR. It determines the purposes and means of its processing principally by reference to its own legal obligations under Union and Estonian law. Where a merchant provides personal data to EAS, the merchant is a separate controller in its own right; EAS is not a processor acting on its instructions.
Personal data we process
- Contact details — name, email address, telephone number.
- Business information — company name, registration number, address.
- Account details — login credentials, account usage and service preferences.
- Financial data — payment and invoicing details.
- Technical data — IP address, browser type, cookies and similar information.
- Transaction and fiscal data — order and shipment details, VAT treatment, and, for customs, sender data and identifiers such as IOSS number and EORI.
Purposes and lawful bases
- Legal obligation (Art. 6(1)(c)) — VAT, IOSS and OSS reporting and filing, and statutory accounting and record-keeping.
- Performance of a contract (Art. 6(1)(b)) — providing the EAS Solution and Services requested.
- Legitimate interests (Art. 6(1)(f)) — maintaining the security of systems and improving services.
- Consent (Art. 6(1)(a)) — optional cookies, which may be withdrawn at any time.
Data sharing
EAS shares personal data only where necessary and only with recipients bound by appropriate confidentiality and data-protection obligations: tax and customs authorities where required by law; appointed fiscal representatives and customs agents; and its processors under written contracts meeting Article 28 GDPR — Hetzner (hosting, Germany) and Amazon Web Services (backup, AWS eu-central-1, Frankfurt, Germany), both within the EU.
Retention and deletion
EAS keeps personal data only as long as necessary and no longer than the law requires. Certain fiscal records are subject to mandatory statutory retention:
| Records | Retention period | Retention begins |
|---|---|---|
| IOSS and OSS records | 10 years | End of the year of the transaction |
| UK VAT records | 6 years | End of the relevant VAT period |
| Estonian accounting records | 7 years | End of the financial year |
| Other personal data | As long as necessary for the purpose | From last activity or account closure |
When a retention period ends, personal data is securely deleted or irreversibly anonymised.
International transfers
EAS processes personal data within the European Union and the United Kingdom only. EU-to-UK transfers rely on the European Commission adequacy decisions for the United Kingdom. EAS does not transfer personal data to any other third country without an adequate safeguard under Chapter V GDPR.
Security
EAS applies appropriate technical and organisational measures under Article 32 GDPR, including:
- Encryption of personal data in transit (TLS 1.2/1.3) and at rest (AES-256).
- Multi-factor authentication, role-based access control and least privilege.
- Network controls and monitoring with alerting.
- Logging of data access, modification and deletion.
- Regular data audits and security reviews.
- Confidentiality undertakings for all authorised personnel.
Your rights
Subject to the conditions in the GDPR, individuals have the right to request access to their personal data, and to request its rectification, erasure, restriction or portability, to object to certain processing, and to withdraw consent. To exercise any of these rights, contact [email protected]. EAS responds within the time limits set by the GDPR.
Complaints
Individuals may lodge a complaint with a supervisory authority. The lead supervisory authority for EAS is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. Individuals may also complain to the authority in their country of residence.
Updates
EAS keeps this statement under review and updates it to reflect changes in its processing or in the law. The version and date are shown in the document control table.
Document history
| Version | Date | Author | Description |
|---|---|---|---|
| 1.0 | 30 July 2026 | EAS | Initial issue. |