Your Data Rights

Under EU GDPR and Polish RODO, you have powerful rights over your personal data.

Last updated: 14 February 2026

Your Rights Under Data Protection Law

Right of Access

Article 15

Obtain confirmation that we process your data and access to that data.

How to exercise: Download in account settings or contact us

Right to Rectification

Article 16

Have inaccurate data corrected and incomplete data completed.

How to exercise: Edit in profile settings or contact us

Right to Erasure

Article 17

Request deletion of your data in certain circumstances.

How to exercise: Delete account in settings or submit request

Right to Restrict Processing

Article 18

Request we limit how we use your data.

How to exercise: Submit request through Help Centre

Right to Data Portability

Article 20

Receive your data in machine-readable format.

How to exercise: Download JSON/CSV from account settings

Right to Object

Article 21

Object to processing based on legitimate interests.

How to exercise: Use marketing preferences or contact us

Automated Decision-Making

Article 22

Rights regarding automated decisions that affect you.

How to exercise: We do not make such automated decisions

Withdraw Consent

Article 7(3)

Withdraw consent at any time where we rely on it.

How to exercise: Manage in privacy settings

Limitations on Rights — Tax Compliance Data

If you are a Provider on LocaYo, certain data rights may be limited in respect of tax compliance data that we are legally required to collect and retain under EU DAC7 (Council Directive 2021/514) as implemented in Estonian law.

Specifically, your right to erasure and right to restrict processing may not apply to tax compliance data (including your Tax Identification Number, date of birth, address, and tax residence) where we are required by law to retain this data for at least 5 years after the last reportable period.

Your right of access, right to rectification, and right to data portability continue to apply in full. If you wish to exercise any right in respect of tax compliance data, please contact us at privacy@locayo.app and we will explain any limitations that apply.

Response Times

We respond to requests within one month. Complex cases may take up to three months with notification. We will inform you of any extension within the first month, including the reasons for the delay.

How to Make a Request

Self-Service

  • Download your data
  • Edit your profile
  • Manage tax compliance data
  • Delete your account

Contact Us

For any data protection request:

Supervisory Authorities

You have the right to lodge a complaint with a supervisory authority if you are concerned about how we handle your personal data.

Estonia (lead supervisory authority): Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) — aki.ee
Poland: Urząd Ochrony Danych Osobowych (UODO) — uodo.gov.pl
Lithuania: Valstybinė duomenų apsaugos inspekcija (VDAI) — vdai.lrv.lt
Latvia: Datu valsts inspekcija (DVI) — dvi.gov.lv
Germany: Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI) or your relevant Landesdatenschutzbehörde
United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
EU: Your local data protection authority

Data Controller

Next Orbit OÜ, trading as LocaYo

Private limited company (osaühing) registered in the Republic of Estonia, registry code [TO BE ADDED], registered address [TO BE ADDED UPON REGISTRATION].

Data protection contact: privacy@locayo.app

Legal Framework

  • EU GDPR (2016/679) — General Data Protection Regulation (directly applicable in Estonia and all EU/EEA member states; primary framework for LocaYo as an Estonian company)
  • Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) — Estonian implementation legislation supplementing GDPR
  • Polish RODO — Polish implementation of GDPR (applicable to Polish users)
  • Lithuanian Personal Data Protection Law (Asmens duomenų teisinės apsaugos įstatymas) — applicable to Lithuanian users
  • Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums) — applicable to Latvian users
  • UK GDPR & Data Protection Act 2018 — applicable to United Kingdom users
  • ePrivacy Directive (2002/58/EC) — Rules for electronic communications and cookies, as implemented in national laws
  • EU DAC7 (Council Directive 2021/514) — EU tax reporting obligations for digital platforms, as implemented in Estonian law

Related Documents

© 2026 LocaYo. All rights reserved.