ISMO / Privacy policy
Privacy policy
Draft for legal review — replace before launch.
Last updated: 2026-09-28
Who we are
This website, ismopartners.com, and the ISMO service (Internal Security Management Office) are operated by Leguard OÜ, a private limited company (osaühing) duly registered and existing under the laws of the Republic of Estonia, registered in the Estonian Commercial Register under registration number 17469327, with its registered address at Harju maakond, Tallinn, Kesklinna linnaosa, Vesivärava tn 50-201, 10152, Estonia (“ISMO”, “we”, “us”).
Leguard OÜ is the controller of the personal data described in this policy. For any question about privacy or your data, write to vi@ismo.group or to our Telegram account @ISMOpartners.
What this policy covers
It covers visits to this website, the contact form, the confidential concern form, and messages you send us by email or Telegram after finding us here.
It does not cover the work we do for clients under a contract. That work is governed by the contract, a non-disclosure agreement and, where required, a separate data processing agreement.
What we collect
Contact form: your name, company, role, work email or Telegram username, and team size. The role is optional; everything else is required so that we can answer and scope the first conversation.
Confidential concern form: the text of your message and any contact details you choose to add. You can send it without identifying yourself. We do not record the IP address of anyone who uses this form.
Email and Telegram: your address or username and whatever you write to us. If you leave a Telegram username in the form, we reply there.
Technical data: when you load a page, our hosting provider processes your IP address, browser type and the time of the request so that the site can be delivered and protected from attacks. When you send a form, a bot-protection check (Cloudflare Turnstile) looks at technical signals from your browser to tell people from automated abuse.
Visit statistics: we count page views and a few site events (for example, that a form was sent or a section was used) without cookies and without identifying you. Country and device type are recorded only in aggregate.
We do not collect special categories of data through this website and ask you not to send them. We do not knowingly collect data from children.
Why we use it and on what basis
To answer your request and discuss a possible engagement: steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)).
To handle a confidential concern according to the procedure described on that page: our legitimate interest in preventing and investigating misconduct, and legal obligations where they apply (Art. 6(1)(f) and 6(1)(c)).
To keep the site and forms secure, prevent spam and understand, in aggregate, how the site is used: our legitimate interest (Art. 6(1)(f)).
Where the law of your country requires consent for any of this, we rely on the consent you give when you tick the box in the form. You can withdraw it at any time by writing to us; this does not affect processing that took place before.
Cookies and browser storage
This website sets no advertising or tracking cookies. It stores two small preferences in your own browser: the language you chose, and a note that the one-time touch hint in the premises section has already been shown. Neither is sent to us.
The bot-protection check may use technical storage that is strictly necessary for it to work. More detail is in the cookie policy.
Who receives your data
Only the ISMO team members who need it to answer you or to handle your concern.
Service providers that process data on our behalf, under data processing terms: Cloudflare, Inc. (hosting, security, bot protection and cookie-less statistics), Resend (email delivery, when a request is delivered or answered by email), and Telegram (when a request is delivered to our team’s Telegram account).
Authorities or courts, only where the law requires it or where it is needed to establish, exercise or defend legal claims.
We do not sell personal data and do not share it for advertising.
International transfers
Our providers may process data outside the European Economic Area, including in the United States. Where that happens, the transfer relies on an adequacy decision of the European Commission (including the EU–U.S. Data Privacy Framework, where the provider is certified) or on the Commission’s standard contractual clauses, together with the provider’s additional safeguards.
How long we keep it
Contact requests and related correspondence: up to 24 months after our last contact, unless a contract follows, in which case the contract’s retention terms apply.
Confidential concerns: for as long as needed to review the concern and any follow-up, and no longer than 12 months after the matter is closed, unless the law requires a longer period or the data is needed for legal claims.
Technical logs and security data: for the shortest period our providers allow, as a rule no more than a few days. Aggregated statistics contain no personal data.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction of processing and a copy in a portable format, and you can object to processing based on our legitimate interest.
To use any of these rights, write to vi@ismo.group. We answer within one month and may ask you to confirm your identity first. For a concern sent anonymously, we can only act on a request we are able to link to that concern.
You have the right to lodge a complaint with our lead supervisory authority, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, www.aki.ee), or with the data protection authority of the country where you live or work.
How we protect it
The site is served over HTTPS only, with strict security headers and a content security policy. Form submissions are delivered directly to our team and are not stored on this website.
Access to requests and concerns is limited to the people who handle them. Client material is kept encrypted and every access to it is logged.
Changes to this policy
When we change this policy, we publish the new version on this page with a new date. If a change is significant, we say so clearly on the site.