Privacy Policy

CGI Horizon OÜ

Last updated: 6 August 2026


1. Who we are

CGI Horizon OÜ (“CGI Horizon”, “we”, “us”) is an architectural visualization studio registered in Estonia. We are the controller of the personal data described in this policy within the meaning of Regulation (EU) 2016/679 (the GDPR).

   
Legal name CGI Horizon OÜ
Registry code 16893112
VAT number EE102694712
Registered address Orumetsa tn 5/1-15, Maardu, Harju maakond, 74111, Estonia
Email [email protected]
Website https://cgi-horizon.com

We are not required to appoint a Data Protection Officer. All privacy questions and requests should be sent to [email protected].

2. Scope

This policy covers personal data we process through our website (cgi-horizon.com), our email and messaging channels, our social media pages, and in the course of providing 3D visualization services to our clients.

We provide services on a business-to-business basis. Most of the personal data we handle relates to individuals acting in a professional capacity — architects, developers, project managers, and other representatives of our clients and suppliers.

3. What personal data we collect

3.1 Website visitors

  • Contact form submissions — your email address, the content of your message, and any project information, files, or reference materials you choose to include.
  • Technical and log data — IP address, browser type and version, device and operating system, referring page, pages viewed, date and time of access. This is generated automatically by our hosting infrastructure and by our content delivery and security provider (Cloudflare).
  • Cookie and similar identifiers — see Section 6.

3.2 Clients and prospective clients

  • Name, job title, employer, business email address, telephone number.
  • Project briefs, drawings, CAD/BIM files, reference images, feedback, and correspondence relating to a project.
  • Contract, invoicing, and payment details.
  • Records of meetings, calls, and messages relating to the engagement.

3.3 Suppliers, freelancers, and contractors

  • Name, contact details, company or sole-trader registration details, bank details, invoices, and contract terms.

3.4 Social media

If you follow, message, comment on, or otherwise interact with our profiles on Instagram, Facebook, or X, we receive the information those platforms make available to us, including your public profile name and the content of your interaction. The platforms themselves process your data as independent or joint controllers under their own terms; we have no control over their processing.

3.5 Applicants and collaborators

If you contact us about work or collaboration, we process the CV, portfolio, and contact details you send us.

We do not knowingly collect special categories of personal data (Article 9 GDPR). Please do not send us health, biometric, political, religious, or similar sensitive information.

4. Why we process it, and on what legal basis

Purpose Personal data Legal basis
Responding to enquiries and preparing quotations Contact form data, correspondence Steps at your request prior to entering a contract — Art. 6(1)(b); or our legitimate interest in responding to a business enquiry made on behalf of a company — Art. 6(1)(f)
Delivering visualization services, managing the project, and communicating with you Client contact details, project materials, correspondence Performance of a contract — Art. 6(1)(b); legitimate interest where you are a representative of a corporate client — Art. 6(1)(f)
Invoicing, accounting, tax and VAT compliance Billing and payment data Legal obligation — Art. 6(1)(c)
Managing supplier and freelancer relationships Supplier data Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
Operating, securing, and maintaining the website; preventing abuse and fraud Technical and log data Legitimate interest in the security and availability of our services — Art. 6(1)(f)
Measuring website traffic and improving our content Analytics identifiers Your consent — Art. 6(1)(a)
Sending occasional updates or offers to existing business clients Business email address Legitimate interest in direct marketing to existing clients — Art. 6(1)(f), with an opt-out in every message
Sending marketing to people who are not existing clients Business email address Your consent — Art. 6(1)(a)
Displaying completed work in our portfolio, website, and social media Project imagery, and where applicable the client’s name Contract or your consent, depending on what the engagement terms provide — Art. 6(1)(b) or 6(1)(a)
Establishing, exercising, or defending legal claims Any relevant data Legitimate interest — Art. 6(1)(f)
Considering applications for work or collaboration CV, portfolio, contact details Steps at your request prior to a contract — Art. 6(1)(b); consent for retention beyond the immediate role — Art. 6(1)(a)

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You can ask us for details of that assessment, and you can object at any time (Section 10).

Providing your data is not a statutory requirement, but without contact details and project information we cannot respond to an enquiry or deliver a project.

5. Where the data comes from

Almost all of the data we hold comes directly from you. We may also receive your details from your employer or from a colleague who introduces you to a project, and we may consult publicly available sources such as company registers, company websites, and professional networks to verify a business contact.

6. Cookies and similar technologies

Our website uses cookies and similar technologies. We distinguish between:

  • Strictly necessary cookies, which are required for the site to function and to keep it secure — for example the WordPress session and security cookies and the cookies set by Cloudflare to route traffic and to detect malicious activity. These do not require your consent.
  • Preference cookies, which remember choices such as your dismissal of the cookie notice.
  • Analytics and marketing cookies, which help us understand how the site is used or which support advertising. These are only set after you give consent, and you can withdraw that consent at any time by clearing cookies in your browser or using the cookie settings on our site.

You can also block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the site from working.

Do Not Track: our website does not currently respond to browser Do Not Track signals.

7. Who we share personal data with

We do not sell personal data. We share it only with the following categories of recipient, and only as far as necessary:

  • Hosting and infrastructure providers — our web host and Cloudflare, Inc. (content delivery, DNS, DDoS protection, email address obfuscation).
  • Email, file transfer, and collaboration providers — used for correspondence and for the exchange of large project files.
  • Analytics providers — where you have consented.
  • Accounting, bookkeeping, audit, and tax advisers, and the Estonian Tax and Customs Board where the law requires it.
  • Banks and payment providers.
  • Freelance visualizers, modellers, and other subcontractors engaged on a project, bound by written confidentiality and data protection terms.
  • Legal advisers, debt collection agencies, courts, and public authorities, where necessary to comply with the law or to establish or defend legal claims.
  • Social media platforms, in respect of interactions on our profiles.

Where a recipient processes data on our behalf, we have a written data processing agreement in place under Article 28 GDPR.

8. International transfers

Some of our providers process data outside the European Economic Area, including in the United States. Where this happens, we rely on one of the following safeguards:

  • an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the recipient is certified under it; or
  • the European Commission’s Standard Contractual Clauses under Article 46(2)(c) GDPR, together with supplementary technical and organisational measures where our assessment identifies a need for them.

You can request a copy of the relevant safeguards by writing to [email protected].

9. How long we keep it

Data Retention period
Enquiries that do not result in a project 12 months from the last communication
Client contact details and project correspondence For the duration of the relationship and 3 years after the final delivery, matching the general limitation period for contractual claims under Estonian law
Project source files and rendered output 3 years after final delivery, unless the engagement terms provide otherwise or you ask us to delete them earlier
Contracts 10 years from the end of the contract
Accounting source documents and invoices 7 years from the end of the relevant financial year, as required by the Estonian Accounting Act
Web server and security logs Up to 12 months
Marketing consent records For as long as the consent is valid and 3 years after it is withdrawn, as proof of compliance
Unsuccessful applications 6 months, or longer with your consent

At the end of these periods we delete the data or irreversibly anonymise it.

10. Your rights

Under the GDPR you have the right to:

  • Access — obtain confirmation of whether we process your data and receive a copy of it (Art. 15).
  • Rectification — have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — have your data deleted where one of the grounds in Art. 17 applies.
  • Restriction — have processing limited while a dispute about accuracy or lawfulness is resolved (Art. 18).
  • Data portability — receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20).
  • Object — object at any time to processing based on our legitimate interests, on grounds relating to your particular situation, and to object to direct marketing at any time with no need to give reasons (Art. 21).
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3)).

To exercise any of these rights, write to [email protected]. We will respond within one month. If your request is complex or you have made several requests, we may extend this by up to two further months and will tell you if we do. We may ask you for information to confirm your identity.

Note that some rights are qualified. For example, we may refuse an erasure request where we are legally required to retain the data for accounting purposes, or where we need it to defend a legal claim.

11. Complaints

If you believe we have processed your personal data unlawfully, please contact us first so we can try to resolve the matter. You also have the right to lodge a complaint with the Estonian supervisory authority:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) Tatari 39, 10134 Tallinn, Estonia Phone: +372 627 4135 Email: [email protected] Website: https://www.aki.ee

If you live or work in another EU or EEA country, you may also complain to your local supervisory authority. You also have the right to an effective judicial remedy.

12. Automated decision-making

We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.

13. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit (HTTPS/TLS), access controls and role-based permissions, restricted access to project files on a need-to-know basis, confidentiality obligations for staff and subcontractors, regular software updates, and backups. No system is completely secure, but we take our obligations under Article 32 GDPR seriously and will notify you and the supervisory authority of a personal data breach where the GDPR requires it.

14. Children

Our website and services are directed at businesses and professionals and are not intended for children. We do not knowingly collect data from anyone under the age of 13. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to this policy

We may update this policy to reflect changes in our practices or in the law. The current version is always available at https://cgi-horizon.com/privacy-policy/ and the date at the top shows when it was last revised. If we make a material change, we will take reasonable steps to bring it to your attention.

16. Contact

CGI Horizon OÜ Orumetsa tn 5/1-15, Maardu, Harju maakond, 74111, Estonia [email protected]