Your trust is part of our work. Here we explain, without unnecessary jargon, what data we collect, why, for how long we keep it, and what rights you can exercise at any time.
To register, all you need is an email address. Name, city, occupation and interests are always optional.
Card details never pass through our servers: they are handled by Mollie.
Information that could identify a source is never disclosed to third parties.
Data controller
Clarionfold Press OÜ determines the purposes and means of processing connected with running the website, subscriptions, donations, the members' area, editorial and user communications, and the journalistic activity of Silere non possum.
Scope of application
This notice applies to the processing of personal data carried out through:
- the website silerenonpossum.com and its members' area;
- subscription services and donations;
- editorial communications and messages sent by users to the Controller;
- the technical activities required to run and secure the website;
- the journalistic, editorial and publishing activities of Silere non possum.
It does not apply to third-party websites reachable via links on the site: those sites act as independent controllers and apply their own respective notices.
What personal data we process
3.1 Browsing and technical data
While browsing, data necessary for the operation, security and maintenance of the site may be processed: IP address, date and time of access, URLs requested, browser type, operating system, device type, server logs and any data relating to errors, attempted unauthorised access and abuse prevention.
3.2 Account and members' area data
When creating an account or purchasing a subscription: email address, first and last name (if provided), technical login credentials, subscription status, registration and last-access dates, and account preferences. Where a password is used, it is stored in a non-readable form; session tokens keep the session active and secure.
3.3 Optional profile data
Users may provide additional data — date of birth, city, occupation, editorial preferences. These are optional: not providing them does not prevent use of the essential services. Where a freely provided preference could reveal religious, philosophical or political beliefs (special category data, Article 9 GDPR), it is processed only with your explicit consent and strictly within the limits necessary for the function requested.
3.4 Subscriptions, payments and donations
To manage subscriptions and donations: first and last name (if provided), email, amount, currency, date and time, outcome and transaction ID, subscription status, and any data required for receipts and tax obligations.
Payments are handled by Mollie. Full card details are never stored on the Controller's servers.
3.5 Editorial and service communications
The Controller may send communications regarding account management, subscriptions, renewals, deadlines, payments, security, service changes, and editorial or fundraising initiatives. Communications that are not strictly necessary are only sent on request or with consent; you may object at any time by writing to the Controller.
3.6 Messages sent to the Controller
When you contact us by email or via forms: your contact details, the content of the message, any attachments, and technical metadata needed to reply. We ask that you avoid sending unnecessary data, irrelevant third-party data, or special category data, unless strictly indispensable.
3.7 Comments and user-submitted content
Where the site allows comments or interaction: the content published, the name or handle displayed, date and time, IP address, and technical security data. The Controller may moderate or remove content that is unlawful, offensive, defamatory, abusive or spam.
3.8 Cookies, similar technologies and local storage
Your reading history and reading progress are stored only in your browser (localStorage) and are never transmitted to our servers. Further details on cookies and tracking are in the Cookie Policy.
3.9 Data processed for journalistic purposes
In the course of editorial activity, we may process data relating to people named in articles, investigations and documents, drawn from public sources, lawfully accessible records, press releases, public statements, archives, confidential sources and tip-offs. Journalistic processing is governed by section 11.
Purposes and legal bases
The Controller processes data for the following purposes, on the legal bases indicated (Article 6 GDPR):
| Purpose | Legal basis |
|---|---|
| Running the site, browsing and technical security | Legitimate interests — Art. 6(1)(f) |
| Registration, account and members' area | Contract / pre-contractual steps — Art. 6(1)(b) |
| Subscriptions, restricted content, renewals and support | Contract — Art. 6(1)(b); accounting/tax obligations — Art. 6(1)(c) |
| Managing donations | User's request — Art. 6(1)(b); legal obligations — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
| Payments via Mollie (fraud prevention and security) | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
| Optional profile data | Consent — Art. 6(1)(a); explicit consent for special category data — Art. 9(2)(a) |
| Service communications (account, payments, security) | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
| Editorial communications and fundraising campaigns | Consent — Art. 6(1)(a) or legitimate interests — Art. 6(1)(f) |
| Responding to user requests and reports | Legitimate interests — Art. 6(1)(f); contract/legal obligation where applicable |
| Protection of rights, disputes, fraud and requests from authorities | Legitimate interests — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
| Accounting, tax and administrative compliance | Legal obligation — Art. 6(1)(c) |
| Analytics and advertising (Google Analytics, Google Ads) | Consent — Art. 6(1)(a); details in the Cookie Policy |
| Journalistic and editorial activity, and archiving | Freedom of expression and information — Art. 85 GDPR and IKS; legitimate interests — Art. 6(1)(f) |
Nature of the data provided
Providing your email address is necessary to create an account, access the members' area, manage a subscription and complete payments or donations. Data required for payment is essential for subscriptions and donations; data requested for accounting or tax purposes is mandatory where required by law.
Providing optional profile data and consenting to non-essential communications is entirely voluntary: not providing them does not prevent registration, subscribing, or using the other services.
Recipients of data and service providers
Data may be processed by authorised personnel and by external providers who, when acting on the Controller's behalf, act as data processors (Article 28 GDPR), bound by appropriate agreements:
Data is not sold to third parties or passed on for independent marketing purposes.
Transfers to third countries
Data is processed mainly within the European Economic Area or by providers based in Europe, such as Mollie B.V. (Netherlands). Some providers (e.g. Google) or the sub-processors of our processors may also process data outside the EEA. In such cases, transfers only take place under one of the safeguards provided for by the GDPR:
- an adequacy decision of the European Commission;
- the EU–US Data Privacy Framework, where the provider validly adheres to it;
- Standard Contractual Clauses approved by the European Commission, together with any supplementary measures where needed;
- another basis provided for under Articles 44 et seq. of the GDPR.
Retention periods
Data is kept for as long as necessary for the purposes described, subject to any legal obligations or the need to protect the Controller's rights.
| Category | Retention period |
|---|---|
| Account data | For the entire life of the account; upon a deletion request, erased or anonymised within 30 days, subject to legal obligations |
| Subscription data | Duration of the relationship, plus the period needed to meet accounting/tax obligations and protect the Controller's rights |
| Payments and donations | 7 years from the end of the financial year (under Estonian accounting rules) |
| Accounting and tax records | 7 years from the end of the financial year in which they were recorded |
| Non-essential editorial communications | Until withdrawal/objection; then for a limited period to document the request and prevent unwanted future contact |
| Messages sent to the Controller | The time needed to respond and, typically, up to 24 months, subject to legal obligations or disputes |
| Technical and security logs | A limited period, typically up to 180 days, unless there is an incident or a request from the authorities |
| Reading history (localStorage) | Remains on the user's own device until they choose to delete it |
| Data processed for journalistic purposes | Kept in editorial archives for as long as needed for journalistic, documentary and archival purposes |
Rights of the data subject
Within the limits and conditions set out in the GDPR, you may exercise the right to:
- access your data and obtain a copy (Art. 15);
- rectify inaccurate data (Art. 16);
- erasure (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand;
- not be subject to a decision based solely on automated processing, in the cases set out in Art. 22.
Requests should be sent to [email protected] (subject line: "PRIVACY"). For security reasons, the Controller may ask you to provide information to verify your identity.
Restrictions on rights
The exercise of these rights may be restricted where necessary and proportionate to protect freedom of expression and information, journalistic activity, the confidentiality of sources, the security of the site, fraud prevention, legal obligations, and the rights of the Controller or of third parties.
For data relating to accounts, payments, subscriptions, donations and editorial communications, rights remain exercisable under the ordinary rules of the GDPR, subject to any restrictions arising from legal obligations.
Processing for journalistic purposes
Silere non possum is an independent international online daily (ISSN 3125-5205) published by Clarionfold Press OÜ. In the course of its journalistic activity, the Controller may collect, verify, process, store and publish personal data where necessary to inform the public about facts, acts, statements, documents and matters of public interest.
Processing is carried out in accordance with the GDPR, Article 85 GDPR and Estonian law (the Personal Data Protection Act, IKS), which balance data protection with freedom of expression and freedom of information. Certain information (Articles 13-14) and certain rights may be restricted where providing them would compromise the journalistic purpose, fact-checking, the confidentiality of sources, or the public's right to be informed.
Requests for correction, right of reply or an update to published content should be sent in accordance with the procedure set out in the Impressum, indicating: the URL of the content, the identity of the requester, the reason for the request, the parts being disputed, any supporting documentation, and proposed wording.
Protection of sources
Protecting journalistic sources is a fundamental principle of Silere non possum's editorial work. Information capable of identifying a source is handled with enhanced confidentiality safeguards and is never disclosed to third parties.
The Controller may restrict access to, disclosure, rectification, erasure or other operations on such data where necessary to protect the confidentiality of sources and journalistic activity.
Minors
The site is not specifically aimed at minors. In Estonia, for information society services, a minor's consent is valid from the age of 13; below that age, authorisation from a holder of parental responsibility is required. The Controller does not knowingly collect data from children under 13 without authorisation and, if it becomes aware of such data, takes reasonable steps to delete it, unless a legal obligation or an overriding public journalistic interest requires otherwise.
Data security
The Controller adopts appropriate technical and organisational measures against unauthorised access, loss, destruction, alteration or disclosure. These measures include:
- HTTPS connections and access control;
- individual credentials and secure password storage;
- protected session tokens, backups and technical updates;
- security monitoring and access restricted to authorised personnel only;
- agreements with providers and confidentiality measures for editorial data and sources.
No system can guarantee absolute security. In the event of a breach, the Controller carries out the relevant assessments and, where necessary, makes the notifications required under the GDPR.
Automated decision-making and profiling
The Controller does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals (Article 22 GDPR). The site uses statistical cookies (Google Analytics) and advertising cookies (Google Ads): both are activated only with prior consent and are described in detail in the Cookie Policy, which also links to Google's relevant notices. Interest-based advertising does not produce legal effects or similarly significant effects on users.
Lodging a complaint with the supervisory authority
If you believe your rights have been infringed, you may lodge a complaint with the competent supervisory authority. For Clarionfold Press OÜ, the lead authority is:
You also retain the right to contact the authority of your own State of residence, place of work, or the place where the alleged infringement occurred, in the cases provided for by the GDPR.
Changes to this notice
The Controller may update this notice to reflect regulatory, technical, organisational or editorial changes. The current version is always published on this page, along with the date it was last updated. In the event of substantial changes affecting the rights of registered users, the Controller will inform them by email or via a notice on the site.