Last updated: 10 September 2026
This Privacy Notice explains how KÄHARI Advokaadibüroo OÜ (KÄHARI, we or us) processes personal data when you use kahari.ee, contact us or receive legal services. It covers clients, prospective clients, their representatives and contact persons, website visitors and other people whose data relate to a matter or proceedings on which we advise.
1. Controller and contact details
KÄHARI Advokaadibüroo OÜ
Registry code: 16526709
Registered address: Lille tn 12-5, 51010 Tartu, Estonia
Email: info@kahari.ee
Telephone: +372 508 4777
For data protection enquiries and to exercise your rights, contact Viljar Kähari at viljar@kahari.ee or use the firm’s general email address. KÄHARI determines the purposes and means of the processing described here. Where we act as a processor on behalf of a client for a particular service, a separate agreement governs that processing.
2. What data do we receive, and from where?
- Enquiry and contact details: name, organisation, position or authority to represent, email address, telephone number, matter type, message and subsequent correspondence. Mandatory website form fields are marked with an asterisk.
- Client due diligence information: evidence of identity and authority, date of birth or personal identification code, nationality, residence, identity document details, ownership and beneficial ownership, and, where relevant, information about the source of wealth and funds, politically exposed person status, sanctions and other relevant risks.
- Legal service and matter records: agreements, transactions, evidence, procedural documents, legal positions, correspondence and information about clients, counterparties and other people involved. Depending on the matter, these may contain financial, employment, family or other personal data.
- Billing information: service and time records, invoices, payment details and information needed to administer fees and claims.
- Technical website data: IP address, request time, requested page, technical browser and device information, and error and security logs. Section 8 describes website technologies.
We receive data from you, your representative or organisation, our clients and their advisers, counterparties, courts and authorities, and public registers, official sanctions lists and other relevant public sources. We may also use specialist databases and providers for due diligence. We process only information needed for the particular purpose.
Please keep your initial website enquiry to a brief description. Send copies of identity documents and other sensitive materials after we have agreed an appropriate method of transmission.
3. Purposes and legal bases
- Responding to enquiries and preparing an engagement. If you seek services for yourself, we process data to take steps at your request before entering into a contract (Article 6(1)(b) of the General Data Protection Regulation, or GDPR). For an organisation’s representative or another contact person, we rely on our legitimate interest in professional communication and assessing a prospective engagement (Article 6(1)(f)).
- Providing legal services and managing client relationships. We process an individual client’s data to perform the contract (Article 6(1)(b)). For representatives of corporate clients and other people involved, we rely on our and our client’s legitimate interests in providing and obtaining legal services, protecting rights and resolving disputes (Article 6(1)(f)), and, where applicable, a legal obligation (Article 6(1)(c)).
- Due diligence, anti-money laundering, sanctions and professional duties. We comply with applicable legal obligations (Article 6(1)(c)). Where conflict or risk checks do not arise from a specific legal obligation, we rely on our legitimate interest in providing independent and reliable legal services (Article 6(1)(f)).
- Billing, accounting and protecting claims. As applicable, we rely on contractual performance, legal obligations or our legitimate interests in receiving payment, evidencing our actions and establishing, exercising or defending legal claims (Article 6(1)(b), (c) and (f)).
- Operating and securing our website and information systems. We rely on our legitimate interests in providing a functioning website, preventing abuse and protecting information (Article 6(1)(f)). Optional processing which requires consent is based on your consent (Article 6(1)(a)).
- Marketing communications. If you request updates or give separate consent, we use your contact details for the stated purpose (Article 6(1)(a)). Submitting a legal enquiry is not consent to marketing. You can opt out at any time.
When relying on legitimate interests, we consider your rights and reasonable expectations and limit processing to what is necessary. You may withdraw consent at any time without affecting the lawfulness of earlier processing. Acknowledging that you have read this Notice is not consent to all processing described in it.
4. Sensitive data and confidentiality
Where a matter requires special category data, such as health information, we need both a general legal basis and a condition under Article 9(2) GDPR, particularly necessity for establishing, exercising or defending legal claims. We process criminal offence data only as permitted by Article 10 GDPR and applicable law. We take account of the powers conferred by the Estonian Bar Association Act and our duties of professional secrecy.
We apply organisational and technical safeguards appropriate to the data and risks, and restrict access to people who need the information for their work.
5. Who may receive data?
Where necessary and legally permitted, recipients may include:
- lawyers, staff and agreed cooperation partners involved in our work;
- providers of hosting, email, document and practice management, IT support, accounting, due diligence and other working tools, including cloud services and, where relevant, AI-assisted tools;
- other advisers, experts, translators, notaries, banks, counterparties and their representatives involved in a client’s matter;
- courts, enforcement agents, competent authorities, the Estonian Bar Association and, where relevant, insurers and auditors.
Providers processing data on our behalf must follow our instructions and appropriate contractual data protection obligations. Recipients performing their own statutory or independent professional functions may be separate controllers. Disclosures remain subject to professional secrecy and other legal restrictions. Using an AI tool does not itself authorise disclosure of client data or replace a lawyer’s judgement.
6. Transfers outside the EEA
An international matter or service provider may involve transferring data, or allowing access to it, outside the European Economic Area. Such a transfer requires a basis under Chapter V GDPR: an applicable European Commission adequacy decision, appropriate safeguards such as standard contractual clauses with any necessary supplementary measures, or, exceptionally, a specific legally permitted derogation. Contact us for details of a particular transfer, its safeguards and how to obtain a copy. We may redact other people’s information or confidential material where necessary.
7. How long do we retain data?
We retain data for as long as needed for its purpose and applicable legal and professional duties. We consider the duration of the matter, the significance of the document, limitation periods and ongoing proceedings.
- Enquiries which do not lead to an engagement: for the time needed to address the enquiry and reasonable follow-up; limited information may remain necessary for conflict checks or a potential dispute.
- Client and matter records: throughout the engagement and afterwards for as long as required by professional duties, the protection of rights and evidence of claims, having regard to the particular matter and document.
- Accounting source documents: seven years from the end of the financial year in which the transaction was entered in the accounts on the basis of the document.
- Data collected under anti-money laundering legislation: generally five years after the business relationship ends or, as prescribed by law, after the transaction; longer retention requires an applicable legal basis.
- Technical logs: for as long as needed for operation, troubleshooting and security; extracts concerning an incident or dispute may be retained until it is resolved and for the period needed to protect claims.
Once there is no basis for retention, data are deleted or anonymised. Data in backups are removed through the normal replacement cycle. You may ask us for the retention period, or the criteria used to determine it, for particular data.
8. Cookies and external website services
Hosting and the enquiry form. Zone hosts the website. Technical request information is used to deliver and secure the site. Form data are used to handle your enquiry on the bases described in section 3.
Language selection and machine translation. Estonian and English content is available on separate pages. The machine translation feature for additional languages uses GTranslate and Google’s translation service. Using it may disclose your IP address, browser information and the content to be translated to the provider. The googtrans cookie remembers the language selection; depending on how the selection is made, it lasts for the session or up to one year. You do not need to select machine translation to read the Estonian or English pages. You can remove the language preference in your browser’s site data settings.
Google Fonts. The website loads some fonts from Google’s servers. Your browser sends Google your IP address and technical request information to retrieve them. This is a separate data transfer even if no cookie is stored. Google’s processing is described in Google’s Privacy Policy.
Administration cookies. WordPress login and settings cookies relate to administrators’ authentication and preferences. Ordinary visitors do not need an account to read the site.
Analytics or advertising cookies that require consent must not be used before you give voluntary consent. This Notice and continued browsing do not replace that consent. Your browser lets you inspect, restrict and delete cookies; restrictions may affect optional features. If you follow an external link, such as a LinkedIn link, that service’s privacy notice also applies.
9. Your rights
Subject to applicable conditions, you may obtain information and a copy of your data, request correction, erasure or restriction, and receive data you have provided in a portable format where processing is automated and based on consent or a contract.
You may object to processing based on legitimate interests on grounds relating to your particular situation. You may object to direct marketing at any time without giving a reason. You may also withdraw consent.
These rights are not absolute: we may need to retain data because of a legal obligation or legal claim, and disclosure may be restricted by other people’s rights and professional secrecy. Where necessary, we request proportionate additional information to verify your identity. We normally respond within one month of receipt. If requests are complex or numerous, we may extend this by up to two further months, explaining the extension and its reasons within the first month.
If required data are not provided, we may be unable to respond substantively, complete due diligence or provide the service. We do not make decisions about you based solely on automated processing which have legal or similarly significant effects in the services covered by this Notice.
You may complain to the Estonian Data Protection Inspectorate (info@aki.ee) or the competent supervisory authority in the country of your habitual residence, place of work or the alleged infringement, and seek a judicial remedy.
10. Updates
We update this Notice when our processing or applicable requirements change. The current version and update date are published here. We provide additional notice of material changes where their nature requires it. Updating this Notice does not replace consent where new processing requires consent.