Last updated
September 17, 2026

Privacy policy

1. Introduction and scope

1.1 This Privacy Policy explains how the Goodface group collects, uses, shares and protects personal data when you visit our website, contact us, download our materials, book a call with us, apply for a role with us, or engage us as a service provider.

1.2 "Goodface", "we" and "us" in this Policy mean Goodface company OÜ and LLC "GOODFACE" together. The two companies operate under a single brand, share the systems on which personal data is held, and are joint controllers within the meaning of Article 26 GDPR in respect of the processing described in section 2.

1.3 Goodface is a full-cycle digital agency. We provide product strategy and positioning, UX/UI and brand identity design, web and mobile development, and related marketing and consulting services, with a particular focus on financial technology clients. Our clients are businesses. We do not offer consumer financial products and we are not a regulated financial institution.

1.4 This Policy applies to our processing as a controller — that is, where we decide why and how personal data is processed. Section 14 separately explains our role as a processor, which is how we act in relation to personal data contained in our clients' systems and datasets during a delivery engagement.

1.5 This Policy does not apply to third-party websites, platforms or tools that we link to. Their own privacy notices govern your interaction with them.

1.6 Because we target clients in both the EEA and the United Kingdom, this Policy is written to satisfy Regulation (EU) 2016/679 ("EU GDPR") and the UK GDPR together with the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025 ("UK GDPR"). Where the two regimes differ in a way that affects you, we say so.

2. Who we are, and who is responsible for what

2.1 The joint controllers

Goodface is a group operating under a single brand. Two companies are involved in the processing described in this Policy:

Item
Goodface company OÜ
LLC "GOODFACE"
Role
Operator of the Website; contracting entity for clients in the EEA and the United Kingdom
Contracting entity for clients outside the EEA and the United Kingdom; holder of the historic project portfolio
Legal form and jurisdiction
Osaühing under the law of Estonia
Limited liability company under the law of Ukraine
Registration
Estonian Commercial Register, code 17411090, entered 13 January 2026
Unified State Register of Ukraine, EDRPOU code 44804902, registered 14 February 2022; registration number 1000741020000100437
VAT number
EE102946088
Not registered for VAT
Registered address
Vesivärava tn 50-201, Kesklinna linnaosa, Tallinn, 10152, Estonia
Maidan Nezalezhnosti 2, Kyiv, 01001, Ukraine
Representation
Maksym Yakubovych, management board member
Yana Hrynchuk, director

2.2 The essence of our joint controller arrangement

2.2.1 The two companies share the systems on which personal data is held, including customer relationship management, email, file storage and project management, and jointly determine the purposes and means of the processing carried out through those systems. They have therefore entered into an arrangement under Article 26 GDPR. This section publishes the essence of that arrangement, as Article 26(2) requires.

Responsibility
Allocated to
Providing this Policy and other transparency information
Goodface company OÜ
Operating the Website, the consent tool and the cookie inventory
Goodface company OÜ
Receiving and handling requests to exercise data subject rights, wherever the request is received
Goodface company OÜ, as single point of contact, with the assistance of LLC "GOODFACE"
Security of the shared systems
Both companies jointly
Assessing and notifying personal data breaches
Goodface company OÜ leads; both companies cooperate
Maintaining the record of processing under Art. 30
Each company for its own processing, on a common template
Engaging and contracting processors, including contractors in Ukraine
Goodface company OÜ
Client engagements and delivery
The company that contracts with the client concerned

2.2.2 Regardless of that allocation, Article 26(3) GDPR entitles you to exercise your rights against either company. Whichever you contact, we will handle your request through the single point of contact below.

2.2.3 You may request further information about the arrangement by writing to the contact address below. We may redact commercially confidential terms.

2.3 Single point of contact

Item
Detail
Point of contact for all privacy matters
Goodface company OÜ, Vesivärava tn 50-201, 10152 Tallinn, Estonia
General email
fintech@goodface.agency
Privacy email
fintech@goodface.agency — privacy requests are logged separately on receipt
Data Protection Officer
We have assessed Article 37 EU GDPR / UK GDPR and consider that neither company is required to appoint a Data Protection Officer, because our core activities do not consist of large-scale regular and systematic monitoring of data subjects or large-scale processing of special category data. Privacy matters are handled by Maksym Yakubovych, management board member of Goodface company OÜ.

We have assessed Article 37 EU GDPR / UK GDPR and consider that neither company is required to appoint a Data Protection Officer, because our core activities do not consist of large-scale regular and systematic monitoring of data subjects or large-scale processing of special category data. Privacy matters are handled by Maksym Yakubovych, management board member of Goodface company OÜ.

2.4 Representatives

2.4.1 United Kingdom. Neither company is established in the United Kingdom. Because we offer services to individuals in the UK, we have appointed a representative under Article 27 UK GDPR. You may contact the representative on any matter relating to our processing of personal data, in addition to or instead of contacting us:

Item
Detail
UK representative
Maksym Yakubovych
Address
41 Nichol Lane, Bromley, BR1 4DE, United Kingdom
Contact
fintech@goodface.agency

2.4.2 European Economic Area. LLC "GOODFACE" is not established in the EEA and processes personal data of individuals in the EEA. It has appointed Goodface company OÜ as its representative under Article 27 EU GDPR, at the Tallinn address above.

2.5 You can contact us about anything in this Policy, including to exercise your rights, by email at the privacy contact above, or by post to the Tallinn address.

3. Definitions

We use the terms defined in the EU GDPR and UK GDPR. The following short-hand is used throughout:

  • "personal data" means any information relating to an identified or identifiable living individual;
  • "processing" means anything done with personal data, including collecting, storing, using, disclosing and deleting it;
  • "controller" means the party that decides the purposes and means of processing; "processor" means a party that processes personal data on a controller's instructions;
  • "Services" means the strategy, design, development, marketing and consulting services we provide to our business clients;
  • "Website" means https://goodface.agency, including the fintech service pages and any sub-domains we operate.

4. The personal data we collect

We group the data we collect by the situation in which we collect it.

4.1 Website visitors

When you visit the Website, our servers and our analytics and tag management tools may receive:

  • IP address (which we and our providers may truncate or shorten where the tool supports it);
  • device, browser type and version, operating system, screen and language settings;
  • pages viewed, referring URL, time and date of visit, time spent on each page, scroll and click interactions;
  • approximate location derived from IP address, at city or country level;
  • identifiers stored in or read from cookies and similar technologies, where you have consented or where an exception applies.

Cookies and similar technologies are described in detail in our Cookie Policy, which forms part of this Policy.

4.2 Business enquiries and project briefs

When you complete the "Let's talk" or contact form, or the project brief form, we collect:

  • name, work email address and, optionally, company website, LinkedIn profile URL and how you found us;
  • the content of your project description and any file you attach;
  • the fact and content of subsequent correspondence with you.

4.3 Gated content (fintech eBook and similar downloads)

When you request our fintech eBook or other gated material we collect your work email address and LinkedIn profile URL, and we record that you requested that item and when.

4.4 Booking a call

When you book an introductory meeting through our scheduling tool, we collect your name, email address, the time slot you select, your time zone and anything you write in the booking notes. Calendar invitations and, if a meeting is recorded or transcribed, meeting content are also processed. Calls are recorded and transcribed using Fathom (AI notetaker). Participants are informed at the start of the call that it is being recorded; consent is given by that notice and anyone may object, in which case the call proceeds without recording. See the AI Transparency Note (Fathom is listed).

4.5 Marketing communications

If you subscribe to our newsletter or agree to receive marketing, we collect your email address, your preferences, and engagement data such as whether an email was opened and which links were clicked. No third-party email marketing platform is used and we do not send tracked marketing emails; business correspondence is sent from our own mailbox.

4.6 Client and supplier contacts

Where you are a contact person at a client, prospect, partner or supplier, we process your name, job title, business contact details, correspondence, meeting notes, project communications, and billing and payment information relating to your organisation.

4.7 Candidates

If you apply for a role with us, we process the data in your application, CV and portfolio, your interview notes, and assessment or test results. Recruitment is handled through an external applicant tracking system. ATS is Cleverstaff (Cleverstaff LLC, Kyiv, Ukraine). We keep application data for two years after your last activity in that system, and we do not maintain a talent pool.

4.8 Social media and review platforms

If you interact with our pages on professional and social networks or leave a review on a business directory, we see the information those platforms make available to us. We do not control those platforms and they act as separate or joint controllers in respect of their own processing.

4.9 Special category data

We do not seek to collect special category personal data (such as health data, biometric data, or data revealing racial or ethnic origin, political opinions, religious beliefs or trade union membership) through the Website. Please do not include such data in enquiry forms or attachments.

5. Where we get personal data from

  • directly from you, when you fill in a form, email us, book a call or apply for a role;
  • automatically, from your device and browser when you use the Website;
  • from our client organisations, where they give us the contact details of their team members for a project;
  • from publicly available business sources for business development purposes, such as company websites, professional networks and business directories. No sales intelligence, contact enrichment or lead generation tool is used. Where we obtain your business contact details from a public source, we will tell you that we hold them, and why, at the latest when we first contact you, as Article 14 GDPR requires.

6. Why we process personal data and on what legal basis

We only process personal data where we have a lawful basis for doing so. The table below sets out each purpose, the data involved, and the basis we rely on.

Purpose
Data
Legal basis
Responding to your enquiry, preparing a proposal and negotiating an engagement
Enquiry form data, brief content, attachments, correspondence
Steps at your request prior to entering into a contract (Art. 6(1)(b)); or our legitimate interest in responding to business enquiries where you contact us on behalf of an organisation (Art. 6(1)(f))
Delivering the Services and managing the client relationship
Client contact data, project communications, deliverables, access credentials
Performance of a contract (Art. 6(1)(b)); legitimate interest in administering a relationship with a corporate client (Art. 6(1)(f))
Sending you gated content you asked for
Work email, LinkedIn URL
Consent (Art. 6(1)(a)) — given by ticking the box on the download form
Marketing our services by email
Email address, engagement data
Consent (Art. 6(1)(a)), or legitimate interest in marketing to existing and prospective business customers where permitted by the applicable electronic marketing rules (Art. 6(1)(f)) — see section 8
Operating, securing and improving the Website
Log data, device data, analytics identifiers
Legitimate interest in keeping the Website available, safe and effective (Art. 6(1)(f)); consent where required for the underlying cookie or storage technology
Advertising and measuring campaign performance
Advertising and analytics identifiers, conversion events
Consent (Art. 6(1)(a)) for the placing and reading of the relevant identifiers, and for the resulting processing
Recruitment
Application data, interview notes, assessments
Steps at your request prior to entering into a contract (Art. 6(1)(b)); legitimate interest in assessing suitability (Art. 6(1)(f))
Invoicing, accounting and tax
Billing contact data, invoices, payment records
Legal obligation under Estonian accounting and tax law (Art. 6(1)(c))
Establishing, exercising or defending legal claims, and responding to regulators
Any relevant data
Legal obligation (Art. 6(1)(c)); legitimate interest in protecting our legal position (Art. 6(1)(f))
Publishing case studies and portfolio material
Client organisation name and logo, project description, and any individual's name, image, role or quotation included in the case study
Consent of the individual concerned for their name, image or quotation (Art. 6(1)(a)); contractual permission from the client organisation; legitimate interest in describing our own work (Art. 6(1)(f)) — see section 15

6.1 Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interest against your rights and freedoms. You can ask us for a summary of that assessment using the contact details in section 2.

6.2 Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

7. Cookies and similar technologies

7.1 We use cookies, pixels, local storage and similar storage and access technologies. Full details, including the categories we use, the specific technologies deployed and how to change your choices, are in our Cookie Policy.

7.2 Non-essential technologies are not placed or read until you have given consent through our consent banner, except where an exception under the applicable law applies. Because the UK and EEA rules now differ on this point, our consent tool applies different rules depending on where you are located. This is explained in the Cookie Policy.

7.3 You can withdraw or change your consent at any time through the "Cookie settings" link in the Website footer.

8. Electronic marketing

8.1 We market to businesses. Whether we need your consent before sending you a marketing email depends on where you are and whether you are a corporate or individual subscriber.

8.2 EEA. We will send marketing email only where you have consented, or where you are an existing customer and we are marketing our own similar services to you and gave you the opportunity to object when we collected your address. National rules within the EEA vary, and in Estonia direct marketing by email requires the recipient's prior consent unless the existing-customer exception applies.

8.3 United Kingdom. Under the Privacy and Electronic Communications Regulations 2003, marketing email to a corporate subscriber — for example a named individual at a company or limited liability partnership — does not require prior consent, although we must identify ourselves and give you a way to opt out. Marketing email to an individual subscriber, including a sole trader or an unincorporated partnership, requires consent or the existing-customer exception.

8.4 Every marketing message we send includes an unsubscribe link. You can also opt out at any time by writing to us.

8.5 Opting out of marketing does not stop us from sending you service and transactional messages relating to an engagement, such as project updates or invoices.

9. Automated decision-making, profiling and artificial intelligence

9.1 We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.

9.2 We carry out limited profiling for marketing purposes, such as segmenting our audience by industry or by engagement with our content. This does not have legal or similarly significant effects, and you can object to it at any time.

9.3 We use artificial intelligence tools in the course of running our business and delivering the Services. Our AI Transparency Note explains where we use AI, how human oversight is applied, and how AI-assisted content is labelled. We do not permit our AI vendors to use personal data we submit to train their models. The AI tools we have approved for use, currently Claude and Fathom, are configured on enterprise or zero retention terms, with model training opted out.

10. Who we share personal data with

10.1 We do not sell personal data. We share it only as described below.

Category of recipient
Purpose
Named providers
Cloud hosting, CDN and infrastructure
Running and delivering the Website
Webflow, Inc. (United States, default hosting region) for hosting and CDN; jsDelivr (cdn.jsdelivr.net) for the consent library; GitHub (raw.githubusercontent.com) for showreel and media. Analytics storage: Google Cloud / BigQuery, EU region.
Analytics and tag management
Understanding and improving Website performance
Google Tag Manager and Google Analytics 4 (separate container and property per domain, agency and fintech), Google Search Console, and Google Cloud / BigQuery (EU region) for analytics storage. These tags load only after you accept the analytics category in our consent banner.
Advertising and social platforms
Campaign delivery and measurement
LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company), Google Ads (Google Ireland Limited) and Meta Pixel (Meta Platforms Ireland Limited), for conversion measurement, audience building and retargeting. All are blocked until you accept the marketing category.
Scheduling tools
Collecting briefs and booking calls
Cal.com (EU instance, app.cal.eu) for call booking. Forms are native to the Website; no third-party form or survey tool is used.
Email, productivity and collaboration
Correspondence, file storage, project management
Google Workspace, Slack, Notion, Jira, Figma
Applicant tracking
Recruitment
Cleverstaff (Cleverstaff LLC, Kyiv, Ukraine). Physical hosting country not disclosed by the vendor; controller jurisdiction is Ukraine.
Accounting, banking and payment providers
Invoicing, payments, statutory accounting
Wise US Inc. (payments) and JSC CB "PRIVATBANK" (banking), plus statutory accounting providers as engaged.
Professional advisers
Legal, tax and audit advice
Advisers engaged from time to time
Group companies
Joint controller processing in shared systems; delivery of engagements
LLC "GOODFACE", joint controller — see section 2
Independent contractors in Ukraine
Design, development and delivery work
Individual contractors engaged by Goodface company OÜ
Public authorities
Where required by law or to defend legal claims
Courts, regulators, tax authorities

10.2 Every processor we engage is bound by a written data processing agreement meeting Article 28 EU GDPR / UK GDPR. We do not authorise them to use your personal data for their own purposes.

10.3 If our business or any part of it is sold, merged or reorganised, personal data may be transferred to the acquiring party as part of that transaction, subject to appropriate confidentiality protections.

11. International transfers

11.1 We are established in Estonia and personal data is primarily processed within the EEA. Some of our providers, delivery partners and personnel are located outside the EEA, so personal data may be transferred to third countries.

11.2 United Kingdom. Transfers between the EEA and the UK are covered by the European Commission's adequacy decision for the UK, renewed in December 2025 and currently valid until December 2031. No additional safeguard is required.

11.3 United States. Where a provider is certified under the EU-US Data Privacy Framework and, for UK-origin data, its UK Extension, we rely on that certification. Where a provider is not certified, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK-origin data, and we carry out a transfer impact assessment.

11.4 Ukraine. Ukraine is our principal place of processing. Our delivery team works from Ukraine, and LLC "GOODFACE", our joint controller, is established there. Personal data held in our shared systems is therefore routinely accessed from Ukraine.

11.5 Ukraine is not covered by a European Commission adequacy decision, nor by a UK adequacy regulation. Transfers to Ukraine are made under the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum for UK-origin data, supported by a transfer impact assessment and by supplementary technical and organisational measures.

11.6 Our delivery personnel in Ukraine are engaged as independent contractors by Goodface company OÜ. Each is bound by written confidentiality obligations and by data protection terms, and acts only on our documented instructions.

11.7 Other third countries. For any other transfer we rely on an adequacy decision where one exists, and otherwise on the Standard Contractual Clauses or another mechanism permitted by Chapter V of the GDPR.

11.8 You can request a copy of the safeguards we rely on for a specific transfer by contacting us. We may redact commercially confidential terms.

12. How long we keep personal data

We keep personal data only for as long as we need it for the purpose for which it was collected, and then delete or anonymise it. Our standard periods are:

Data
Retention period
Enquiries that do not lead to an engagement
24 months from our last contact with you, after which the record is deleted
Client contract and project records
The duration of the engagement plus three years, which is the general limitation period for contractual claims under Estonian law
Accounting and tax records
Seven years from the end of the relevant financial year, as required by the Estonian Accounting Act
Gated content and marketing subscriber data
Until you unsubscribe or ask us to stop. We then keep a minimal suppression record indefinitely, containing only what is needed to make sure we do not contact you again
Candidate data
Two years from your last activity in our applicant tracking system. We do not maintain a talent pool
Website logs
12 months, unless a log is retained longer for the investigation of a security incident
Consent records for cookies and marketing
Retained for as long as the consent is relied on plus 24 months, in order to evidence compliance
Case study material
For as long as the case study is published, plus the period needed to evidence the permission relied on

13. Your rights

13.1 Subject to the conditions and exemptions in the applicable law, you have the right to:

  • be informed about how we use your personal data — which is what this Policy is for;
  • access the personal data we hold about you and receive a copy of it;
  • rectify inaccurate personal data and complete incomplete personal data;
  • erase your personal data where we no longer have a lawful reason to keep it;
  • restrict our processing in certain circumstances, for example while we verify the accuracy of data you have challenged;
  • object to processing based on legitimate interests, and to object at any time and without needing to give a reason to processing for direct marketing purposes;
  • portability — to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller, where the processing is based on consent or contract and is carried out by automated means;
  • withdraw consent at any time, where our processing is based on consent;
  • not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.

13.2 To exercise a right, contact us using the details in section 2. We may need to verify your identity before we act. We will respond within one month. If your request is complex or you have made a number of requests, we may extend that period by up to two further months and will tell you if we do.

13.3 Exercising your rights is free. We may charge a reasonable fee, or refuse to act, if a request is manifestly unfounded or excessive, and we will explain our reasoning if we do.

13.4 If you are unhappy with how we have handled your personal data, please tell us first so that we can try to put it right. We will acknowledge your complaint within 30 days and keep you informed of the outcome.

13.5 You also have the right to complain to a supervisory authority:

Where you are
Authority
Contact
EEA — our lead authority
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia; info@aki.ee; www.aki.ee
EEA — alternative
The supervisory authority of your country of residence, place of work, or the place of the alleged infringement
edpb.europa.eu lists all EEA authorities
United Kingdom
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; ico.org.uk

14. Our role as processor on client engagements

14.1 When we design or build a product for a client, we may be given access to that client's systems, test environments or datasets, which can contain personal data relating to the client's own customers and staff. In relation to that data the client is the controller and we act as processor.

14.2 In that role we process personal data only on the client's documented instructions, under a data processing agreement satisfying Article 28 EU GDPR / UK GDPR, which covers confidentiality, security measures, sub-processor authorisation, assistance with data subject rights and breach notification, and return or deletion at the end of the engagement.

14.3 If you are an end customer of one of our clients and want to exercise your rights, please contact that client directly, as they control the data. If you contact us, we will forward your request to them and tell you that we have done so, unless the client has instructed us otherwise.

14.4 On some engagements, and in particular on fintech engagements, we are given access to live production data containing personal data relating to our client's own customers and staff. We do not treat that as exceptional, and this Policy does not state otherwise.

14.5 Where live production data is involved, the following controls apply in addition to the data processing agreement described in clause 14.2:

  • access to production environments is granted only to the named individuals who need it for a defined task, for a defined period, and is withdrawn when that task ends;
  • access is granted through the client's own access management wherever the client's systems allow it, so that the client retains visibility of who has access and can withdraw it at any time;
  • production data is not copied into our own environments, and is not used for development or testing, unless the client instructs it in writing;
  • where such a copy is authorised, it is limited to the fields needed, held only for as long as the task requires, and deleted or returned at the end of it;
  • access to production environments is individually attributed, never shared between people, and protected by multi-factor authentication, and where the client provides access logging in its own systems we work within it;
  • where a client makes anonymised, pseudonymised or synthetic data available for a task, we use it in preference to live data.

14.6 The controls that apply to a particular engagement are set out in the data processing agreement and security schedule for that engagement, which prevail over this clause.

15. Case studies, portfolio and group companies

15.1 We publish descriptions of work we have delivered. Where a case study identifies a client organisation, we do so with that organisation's permission. Where a case study includes an individual's name, photograph, role or quotation, we obtain that individual's consent, and they can withdraw it at any time by contacting us, in which case we will remove or anonymise the material within a reasonable period.

15.2 Case studies are published under the single Goodface brand and describe the work of the group as a whole. Projects delivered before 13 January 2026 were delivered by LLC "GOODFACE", which has traded under the Goodface brand since February 2022; projects since then may be delivered by either company. The Legal Notice identifies the companies in the group and states which of them contracts with clients in each market.

15.3 The word mark "Goodface" is registered as a European Union trade mark under no. 019339622, registered on 10 July 2026 in classes 35 and 42, and as a United Kingdom trade mark under no. UK00004365310, entered on the register on 26 June 2026 with effect from 30 March 2026, in the same classes. Both are owned by Maksym Yakubovych and are used by the companies in the group with his permission.

16. Security

16.1 We maintain technical and organisational measures appropriate to the risk. These include:

  • encryption of personal data in transit using TLS, and encryption at rest on the managed cloud services we use;
  • role-based access control applied on a least-privilege basis, with access reviewed periodically and withdrawn promptly when it is no longer needed;
  • multi-factor authentication on business-critical systems;
  • separation of client environments from one another;
  • written confidentiality obligations and documented data protection terms for everyone who works on our engagements, including independent contractors;
  • requirements for the devices used to access our systems, including full-disk encryption, current operating system and security updates, and a prohibition on storing client material in personal cloud accounts;
  • security review of a vendor before we engage it, and a written data processing agreement with every processor;
  • logging and monitoring of access to our systems;
  • security and privacy awareness training for our people.

16.2 We do not hold, and do not currently plan to obtain, ISO/IEC 27001 or SOC 2 certification.

16.3 No method of transmission or storage is completely secure. While we take the security of your personal data seriously, we cannot guarantee absolute security.

16.4 If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required, and we will notify you directly where the breach is likely to result in a high risk to you.

17. Children

The Website and our Services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

18. Changes to this Policy

18.1 We may update this Policy to reflect changes in our services, our tools or the law. The version and date are shown at the top of this Policy.

18.2 Where a change materially affects you — for example a new purpose or a new category of recipient — we will bring it to your attention before it takes effect, by email where we have your address or by a prominent notice on the Website.

18.3 We keep previous versions of this Policy and will provide an earlier version on request.

19. Contact

Questions about this Policy, or about how we handle personal data, should go to fintech@goodface.agency, or by post to Goodface company OÜ, Vesivärava tn 50-201, 10152 Tallinn, Estonia.