SurnuaiapühaLegal
Privacy Policy
Version 2026-09-12 · Effective 12 September 2026
1. Who we are
Surnuaiapüha is operated by Digitalsurfing Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, which is the data controller for the personal data described in this policy. You can reach us about anything in this policy, including data protection requests, at support@balticmemorials.com. We handle data protection enquiries ourselves; we have not appointed a Data Protection Officer because we are not required to.
Most of the people who use Surnuaiapüha are in Estonia and elsewhere in the European Union, so we apply the EU General Data Protection Regulation (GDPR) to everyone, along with the UK GDPR for our own establishment. If you would like the contact details of our representative for the European Union under Article 27 GDPR, write to the address above and we will provide them.
2. Information we collect
We only collect what the Service needs in order to work.
- Your account. Email address, display name, password (stored only as a secure hash), sign-in times and the language you prefer.
- Memorial Profiles. The name, dates, life story, cemetery and grave details of the person remembered, and the family tree entries you add. Family tree entries can include the names, places of birth and personal identity codes of relatives, some of whom may be living.
- Photographs. Portrait, grave and gallery photographs stored in your Account gallery, together with any technical details embedded in the image file by your camera or phone.
- Grave location. The map pin coordinates you place, the cemetery name and the categories chosen for the pin.
- Account documents store. Files you upload to the 10 GB Account repository, their file names and sizes, and which Profiles each file is linked to. These files may contain sensitive material such as records relating to health or family origins; you decide what to upload.
- QR stickers. The delivery name and postal address you give when ordering a sticker, and the Profile the code points to.
- Downloads of public documents. When somebody downloads a document from a public Profile we record the name and email they enter, the time, and a one-way hashed form of their network address and browser, so we can spot and block misuse.
- Collaborators. The email address of anyone you invite, their role, when they accepted the Collaborator Agreement, when they were last active, and a log of who changed what on shared Profiles.
- Gifts. The buyer's email address, the recipient's email address, the message written on the gift and the verification codes used to redeem it.
- Payments. Payment amount, currency, date, the payment method type (card, SEPA Direct Debit or bank transfer), the last digits and country of the instrument, and the payment reference. Full card and bank account numbers are handled by Stripe and never reach our servers.
- Agreement records. Each time you agree to a legal document — at sign-up, at every payment, and when a collaborator accepts an invitation — we record which document and version, the date and time, your network address, your browser, and a receipt number.
- Technical records. Server logs and security records needed to keep the Service running and safe.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating and hosting your Profiles, photographs and documents | Performance of a contract with you (Art. 6(1)(b)) |
| Publishing a Profile publicly, including the map pin and QR code | Your consent, given by choosing to publish, which you can withdraw by making the Profile private (Art. 6(1)(a)) |
| Taking payment, issuing receipts and handling reversals | Performance of a contract and our legal obligation to keep accounting records (Art. 6(1)(b) and (c)) |
| Recording your agreement to these documents | Legal obligation to demonstrate consent and agreement (Art. 6(1)(c) and Art. 7(1)) |
| Sending service emails: invitations, reminders, receipts, payment problems | Performance of a contract and our legitimate interest in running the Service (Art. 6(1)(b) and (f)) |
| Checking who downloads documents from public Profiles | Our legitimate interest, and yours, in preventing misuse of memorial records (Art. 6(1)(f)) |
| Keeping the Service secure and investigating abuse | Legitimate interest (Art. 6(1)(f)) |
We do not use your information for advertising, we do not sell it, and we do not use it to make automated decisions that produce legal effects for you. There is no profiling.
4. Information about people who have died, and living relatives
The GDPR does not apply to people who have died, but we treat memorial content with the same care. Family tree entries, photographs and documents often contain information about living people. Before you add such information — especially a personal identity code or a date of birth — you must have that person's agreement, and you are responsible for it as described in the Terms of Service. Anyone who believes a Profile contains information about them that should not be published can email support@balticmemorials.com and we will review it, contact the Account Holder, and remove or hide the information where required.
4A. Optional permission for research, books, films and AI use
Choosing to publish a Profile is one decision. Whether the published material may also be referenced in research, education, books, documentaries, films, AI analysis or other commercial projects is a separate, voluntary choice made per Profile in the Profile editor. It is switched off unless the Account Holder turns it on.
Our lawful basis for that additional processing is your consent (Article 6(1)(a) GDPR). Giving it is never a condition of using Surnuaiapüha, of publishing a Profile, or of any payment. You can withdraw it at any time from the Profile editor, and it is withdrawn automatically if the Profile stops being public. Withdrawal stops all future use but does not affect the lawfulness of use before it, and material already published elsewhere by a third party cannot be recalled.
So that consent can be proven and audited, we keep a record of each grant and withdrawal: the Profile, the Account Holder, the date and time, the attribution choice and the version of the wording agreed to. We keep that record for as long as the Account exists and for six years afterwards.
Please do not include sensitive information in a published Profile — private details of living people, medical or financial information, home addresses, identity numbers, or anything told to you in confidence. Photographs and text you flag as belonging to someone else are excluded from any use under this permission. Any living person mentioned in a Profile may contact us at support@balticmemorials.com to object, and we will act on it.
5. Who we share information with
- Anyone, when you publish. A Profile you set to public — including its story, photographs, map pin and any documents you link to it — can be seen by anyone on the internet and may be indexed by search engines.
- Collaborators you invite, limited to the Profiles you name in the invitation.
- Our service providers, who act only on our instructions under written data-processing terms: hosting and database services in the European Union, Stripe for payments, Google Maps for map display, and our email delivery provider.
- Authorities, where the law requires it, or to establish or defend legal claims.
Our servers and stored files are located in the European Union. Where a provider needs to process data outside the European Economic Area, that transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision, and we provide a copy of the safeguards on request.
6. How long we keep it
| Information | Kept for |
|---|---|
| Published Profiles, photographs and grave locations | Indefinitely — a memorial is meant to be permanent — until you delete it or close your Account |
| Unpaid draft Profiles never made public | 24 months after the last edit, then deleted after a reminder email |
| Account documents store | While the Account is open; deleted 30 days after the Account is closed |
| Account details | While the Account is open, then 30 days |
| Payment and accounting records | 6 years, as required by tax and accounting law |
| Agreement and consent records | 6 years after the agreement ends, as evidence of consent |
| Document download checks | 12 months, in hashed form |
| Invitations and collaborator activity logs | 90 days for unused invitations; 24 months for activity logs |
| Security and server logs | 12 months |
7. Your rights
You have the right to ask for a copy of your personal data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw any consent you have given without affecting what we did before you withdrew it. Email support@balticmemorials.com and we will reply within one month. You can also delete Profiles, photographs and documents yourself at any time, and download your agreement receipts from your account page.
If you are not satisfied, you can complain to your national supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, Tallinn, 10134, aki.ee). In the United Kingdom it is the Information Commissioner's Office.
8. Security and data breaches
Information travels over encrypted connections and is stored on access-controlled servers in the European Union. Private documents and unpublished photographs are only reachable through short-lived signed links. Passwords are stored as hashes and never in readable form. Access to the underlying data is limited to the small number of people who need it. If a breach happens that is likely to put your rights at risk, we notify the supervisory authority within 72 hours and tell you directly without undue delay.
9. Cookies
We use only the cookies and local storage needed to keep you signed in and to remember your language and consent choices. We do not use advertising or cross-site tracking cookies. Map tiles are loaded from Google, which may set its own cookies when a map is displayed.
10. Children
Surnuaiapüha is for adults. You must be at least 18 to hold an Account or accept an invitation. We do not knowingly collect account information from children; if you believe a child has created an Account, tell us and we will remove it.
11. How your agreement is recorded
You are asked to agree to this policy and to the Terms of Service when you create an Account and again before every payment, including gifts bought without an Account. Invited collaborators additionally accept the Collaborator Agreement. Each agreement is stored with its version, the date and time, your network address and browser, and a receipt number you can download from your account page.
12. Changes to this policy
When we change this policy we publish a new version number here and ask you to agree to it the next time you pay for something. Material changes are also announced by email.
Digitalsurfing Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom · support@balticmemorials.com.