1. Introduction
This Privacy Policy explains how Mr Charles OÜ (registry code: [pending registration]), a private limited company registered in the Republic of Estonia with its registered office at Tallinn, Harju maakond, Republic of Estonia ("Company", "we", "us", "our"), collects, uses, stores, shares, and protects your personal data when you use the Mr Charles platform ("Platform"), including our website, web application, and mobile applications (collectively, the "Services").
We process personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus), and other applicable data protection legislation.
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
- Company: Mr Charles OÜ
- Address: Tallinn, Harju maakond, Republic of Estonia
- Email: [email protected]
3. Personal Data We Collect
3.1 Data You Provide Directly
- Account information: name, email address, password (hashed), profile picture, date of birth, phone number (optional).
- Profile data: instruments played or taught, experience level, biography, teaching qualifications, location, and availability.
- Booking data: lesson date, time, type (online/in-person), instructor or student selected, booking status.
- Payment data: billing information, transaction history, payout details (for Instructors). We do not store credit card numbers, CVCs, or full payment card data — these are processed directly by our PCI-compliant payment processor.
- Communication data: messages sent through the Platform, support requests, feedback.
- Content: audio and video recordings, reviews, and other materials you upload.
3.2 Data Collected Automatically
- Device and browser data: IP address, browser type and version, operating system, device type, screen resolution.
- Usage data: pages visited, features used, time spent on the Platform, referral source, click patterns.
- Cookies and similar technologies: as described in our Cookie Policy.
3.3 Data from Third Parties
- Authentication providers: if you sign in using a third-party service (e.g., Google), we receive your name, email, and profile picture from that provider.
- Payment processor: transaction confirmations, payout status, and compliance data.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under Article 6 of the GDPR:
- Contract performance (Art. 6(1)(b)): processing necessary to provide the Services, manage your account, process Bookings, and handle payments.
- Legitimate interests (Art. 6(1)(f)): improving the Platform, preventing fraud, ensuring security, sending service-related communications, and conducting analytics.
- Consent (Art. 6(1)(a)): processing analytics cookies, sending marketing communications, and any other processing for which you have given explicit consent. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): compliance with Estonian and EU legal requirements, including tax reporting, anti-money laundering obligations, and responding to lawful requests from authorities.
5. How We Use Your Data
We use your personal data to:
- Create and manage your account;
- Facilitate Bookings between Students and Instructors;
- Process payments and Instructor payouts;
- Provide customer support;
- Send service-related notifications (booking confirmations, reminders, updates);
- Improve and personalise the Platform experience;
- Analyse usage patterns and trends (with anonymised or aggregated data where possible);
- Prevent fraud, abuse, and unauthorised access;
- Comply with legal obligations;
- Send marketing communications (only with your explicit consent).
6. Data Sharing and Recipients
We may share your personal data with the following categories of recipients:
- Other Users: Students can see Instructor profiles (name, bio, qualifications, reviews, rates). Instructors can see Student names and booking details for their confirmed lessons.
- Payment processor: to process payments and payouts securely.
- Hosting and infrastructure providers: cloud computing services that host the Platform (data processed within the EU/EEA or under adequate safeguards).
- Analytics providers: anonymised usage data, only with your consent.
- Legal and regulatory authorities: when required by law, court order, or to protect our rights.
We do not sell your personal data to third parties. We do not share your data with advertisers for targeted advertising purposes.
7. International Data Transfers
Your data is primarily stored and processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:
- European Commission adequacy decisions;
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules, where applicable.
8. Data Retention
We retain your personal data only as long as necessary for the purposes described in this Policy:
- Account data: retained while your account is active and for up to 3 years after account deletion, to handle disputes and comply with legal obligations.
- Booking and transaction data: retained for up to 7 years after the transaction date, as required by Estonian accounting and tax law (Raamatupidamise seadus).
- Communication data: retained for up to 2 years after the last interaction.
- Analytics data: anonymised and aggregated data may be retained indefinitely.
When data is no longer needed, it is securely deleted or anonymised so that it can no longer be associated with you.
9. Your Rights Under the GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
- Right to restriction (Art. 18): request restriction of processing in certain circumstances.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee or with the supervisory authority in your EU member state of residence.
To exercise your rights, contact us at [email protected]. We will respond within 30 days in accordance with the GDPR.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS);
- Encryption of sensitive data at rest;
- Access controls and authentication mechanisms;
- Regular security assessments and monitoring;
- Incident response procedures for data breaches.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate within 72 hours and inform affected individuals without undue delay, in accordance with Articles 33 and 34 of the GDPR.
11. Children's Data
The Platform is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16 without verifiable parental consent. Users aged 16-17 may use the Platform with parental or guardian consent. If we become aware that we have collected data from a child under 16 without appropriate consent, we will take steps to delete that data promptly.
12. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. Search results and recommendations on the Platform are based on general criteria (instrument, location, price, ratings) and do not constitute automated individual decision-making under Article 22 of the GDPR.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered Users via email or through a notice on the Platform at least thirty (30) days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
- Mr Charles OÜ
- Email: [email protected]
- Address: Tallinn, Harju maakond, Republic of Estonia
You may also contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):
- Website: www.aki.ee
- Email: [email protected]
- Address: Tatari 39, 10134 Tallinn, Estonia