Privacy Policy
How eResid collects, uses, stores, shares, and protects personal data on this website, including affiliate-link disclosures, cookies, analytics, correspondence, and visitor rights.
1. Who controls your data
This website is operated under the eResid brand by Comet Group OÜ. For applicable privacy-law purposes, Comet Group OÜ is the controller of personal data processed through this website unless a specific page, form, or third-party workflow states otherwise.
Controller details: Comet Group OÜ, Ida-Viru maakond, Narva linn, P. Kerese tn 5, 20309, Estonia. Registry code: 12568148. VAT number: EE101678030. Privacy contact: legal@eresid.com.
2. What data we may collect
- Technical and server data such as IP address, browser type, device information, referring URL, approximate geolocation, timestamps, and security logs generated by the hosting environment.
- Usage data about pages viewed, navigation paths, buttons clicked, and outbound-link interactions, but only where such measurement is enabled by the site operator or hosting stack.
- Correspondence data you submit voluntarily, such as your name, email address, message content, and any attachments you send through a contact channel.
- Commercial-referral data where you click a provider or affiliate link and a third party records the referral using its own identifiers or tracking parameters.
- Cookie and local-storage preferences where the website uses essential functionality or, if enabled later, analytics or marketing technologies.
3. Why we process personal data
- To operate, secure, maintain, and troubleshoot the website and prevent misuse.
- To respond to inquiries, legal notices, rights requests, partnership requests, and support messages.
- To improve site performance, UX, and content quality, where lawful analytics is enabled.
- To disclose and administer affiliate relationships and outbound referrals to third-party providers.
- To comply with legal obligations, enforce site terms, protect rights, and investigate fraud or abuse.
4. Legal bases
Depending on the situation, the site operator may rely on one or more of the following bases: legitimate interests in operating and securing the website; consent where non-essential cookies or analytics require it; legal obligation where records must be kept or rights requests must be handled; and steps prior to entering into a contract where you ask for business information or partnership follow-up.
If consent is used for analytics, advertising, or other non-essential technologies, those tools should not be activated until the user has given valid consent through a compliant cookie or consent mechanism.
5. Cookies, analytics, and similar technologies
The current codebase appears to use first-party site assets and does not visibly include a third-party analytics script by default. However, a compliant privacy policy must still state the live reality of the production deployment. If the operator enables analytics, ad pixels, session-replay tools, fingerprinting, or marketing cookies later, this page and the site’s consent flow must be updated before those tools go live.
- Strictly necessary cookies may be used for security, load-balancing, session integrity, accessibility, and preference storage.
- Optional analytics or marketing cookies should only be set after clear opt-in consent where required by applicable law.
- Users should be able to revisit and change cookie preferences if optional technologies are introduced.
6. Affiliate links and third-party providers
This website contains comparison content and may include affiliate or commercial links to third-party providers. If you click one of those links, the provider, affiliate network, or tracking infrastructure may collect information about that click, the referring page, or the resulting conversion under their own privacy terms.
The site operator should disclose any material commercial relationship clearly and conspicuously near the relevant recommendation, comparison, or call to action. Third-party websites are controlled by their own operators, and this website is not responsible for their privacy practices, terms, or security.
7. Sharing and processors
Personal data may be shared, where relevant, with:
- hosting, CDN, infrastructure, or security providers supporting the site;
- email or support providers handling inbound correspondence;
- analytics or consent-management providers, if later enabled lawfully;
- affiliate networks, merchant partners, or outbound referral providers where you click to a third-party offer;
- professional advisers, insurers, law enforcement, or regulators where required or reasonably necessary.
8. International transfers
Personal data may be processed inside or outside the EEA depending on the operator’s hosting, email, and service-provider stack. Where transfers to countries without an adequacy decision occur, the operator should rely on an appropriate lawful transfer mechanism such as the European Commission’s standard contractual clauses or another permitted safeguard.
9. Retention
- server and security logs should be kept only as long as reasonably necessary for stability, abuse prevention, and incident response;
- inquiry and support correspondence should be retained only for as long as needed to respond, follow up, defend claims, or meet recordkeeping duties;
- affiliate and performance records may be kept for accounting, audit, and anti-fraud purposes for the period required by the operator’s commercial arrangements or law.
Once retention is no longer necessary, data should be deleted, anonymised, or securely archived in line with the operator’s documented retention schedule.
10. Your rights
Depending on your location and the applicable law, you may have the right to request access, correction, deletion, restriction, objection, portability, and withdrawal of consent where consent is the basis relied on. You may also have the right to complain to your local supervisory authority.
To exercise those rights, the operator should publish a working privacy contact on the Contact page and respond within the timeframes required by applicable law. For this website, privacy and legal requests should be sent to legal@eresid.com.
11. Children
This website is intended for adult founders, freelancers, operators, and business users. It is not directed to children, and the operator does not knowingly collect personal data from children through this site.
12. Security
The operator should use appropriate technical and organisational safeguards proportionate to the risk, including access controls, HTTPS, software updates, least-privilege access, backup protections, and incident-response procedures. No website can guarantee absolute security.
13. Changes to this policy
This policy may be updated as the site, operator details, tracking stack, or legal requirements change. Material changes should be published on this page with a new revision date, and where legally required the operator should obtain renewed consent before introducing new optional tracking technologies.