Privacy Policy
This policy explains what personal data we collect when you visit Atrio Magazine or contact us, why we collect it, and the rights you have over it.
Last updated: 6 October 2026
Who is responsible
Atrio Magazine is published by Matoma OÜ (registry code 17459866), Ahtri tn 12, Kesklinna linnaosa, 15551 Tallinn, Harju maakond, Estonia. Matoma OÜ is the controller of your personal data under the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.
For any question about your data, write to info@atriocommunications.com.
What we collect and why
When you read the magazine
Like every website, our server receives technical information when you visit: your IP address, browser and device type, the page requested, the referring page, and the date and time. This is kept in server logs to deliver the site, keep it secure and investigate misuse. Our legal basis is our legitimate interest in operating a safe, working website (Article 6(1)(f) GDPR). Logs are kept for a short period, normally no longer than 90 days, unless needed to investigate a security incident.
We host our fonts ourselves, so reading the magazine does not send your data to font providers. We do not currently use analytics tools, and we do not offer reader accounts or comments.
When you contact us or submit a project
If you email us or use the contact form on our website, for example to submit a project, propose a partnership or ask a question, we process your name, email address, the content of your message and anything you attach, such as photographs and project information. Messages sent through the contact form are delivered to our email inbox and are not stored on the website. We use this information to reply, to assess and, where agreed, publish your project, and to credit the people involved. Our legal basis is taking steps at your request before entering into an agreement and our legitimate interest in running the magazine (Article 6(1)(b) and (f) GDPR).
We keep correspondence for up to two years after our last contact. If your project is published, we keep the information needed to maintain the article and its credits for as long as the article remains online.
People named in our stories
Our articles name architects, designers, photographers, writers and occasionally homeowners. We publish this information for journalistic purposes and on the basis of our legitimate interest in crediting creative work, usually with the agreement of the people concerned. If you are named in an article and have a concern, please contact us.
Advertising
We fund the magazine partly through advertising, including Google AdSense. Advertising cookies and similar technologies are only used with your consent, which you give or refuse through the cookie banner and can change at any time. When you consent, Google and its partners may process identifiers, your IP address and information about your browsing to show and measure ads, including personalised ads. Our legal basis is your consent (Article 6(1)(a) GDPR). You can learn how Google uses data at policies.google.com/technologies/partner-sites. Details are in our Cookie Policy.
Business partners and advertisers
When we work with brands and partners, we process the business contact details of the people we deal with to manage the relationship, and keep invoices and related records for seven years, as required by the Estonian Accounting Act (Article 6(1)(b) and (c) GDPR).
Embedded content and links
Some articles may include embedded videos or posts from services such as YouTube, Vimeo or Instagram. These services may collect data about you when the embedded content loads. Our pages also link to our Instagram and Facebook profiles; once you follow such a link, the privacy policy of that service applies.
Who we share data with
We do not sell your personal data. We share it only with service providers that help us run the magazine, under contracts that oblige them to protect it:
- our website hosting provider, which stores the website and server logs;
- our email provider, which stores our correspondence;
- Google Ireland Limited, for advertising, only where you have consented;
- our accountants and professional advisers, where necessary.
We may also disclose data where required by law or to protect our legal rights.
Transfers outside the EU
Some providers, such as Google, may process data outside the European Economic Area, including in the United States. Where this happens, transfers are protected by the EU–US Data Privacy Framework or by the European Commission’s Standard Contractual Clauses.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, where there is no reason for us to keep it;
- restrict or object to our processing, including processing based on legitimate interest;
- receive your data in a portable format;
- withdraw your consent at any time, without affecting processing that took place before.
To exercise any of these rights, email info@atriocommunications.com. We will respond within one month.
You also have the right to complain to a data protection authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, www.aki.ee. You may also complain to the authority in the EU country where you live.
Children
Atrio Magazine is not directed at children under 16, and we do not knowingly collect their personal data.
Security
The website is served over an encrypted connection (HTTPS), and access to our systems is limited to the people who need it. No method of transmission over the internet is completely secure, but we take appropriate measures to protect your data.
Changes to this policy
We may update this policy as the magazine evolves, for example if we introduce a newsletter or analytics. The date at the top shows when it was last changed.
