Privacy Policy
Last updated: 15 June 2026 · Version 1.0
This Privacy Policy explains how GKM World OÜ, the Estonian company operating the TLM Marine website at tlm-marine.com, collects and uses your personal data. We are committed to handling your information transparently and in full compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Estonian Personal Data Protection Act.
1. Who is responsible for your data
The data controller is:
GKM World OÜ
Registry code: 14537656
VAT number: EE102160822
Registered office: Retke tee 14-24, Tallinn 13415, Estonia
Founded: 2018
Operating the TLM Marine brand since: 2025
Our representative for data-protection matters is Anton Jeremejev, founder and yacht specialist. You can reach him at info@tlm-marine.com or +372 5834 2314.
2. What personal data we collect
Information you provide directly — through the contact form on this website, when you request a private viewing, or when you correspond with us by email or telephone:
- First name and last name
- Email address
- Telephone number (with country code)
- City and country of residence
- Yacht model of interest
- Intended timeline of purchase or interest
- Free-text message content (which may include any personal information you choose to share)
- Confirmation of consent to this Privacy Policy
Information collected automatically — through our hosting infrastructure and, if you consent in our cookie banner, through analytics tools:
- IP address (anonymised to /24 after 30 days)
- Browser type, operating system, and approximate device class
- Language preference (saved locally in your browser to remember your selection)
- Cookie consent state (saved locally in your browser as required by the ePrivacy Directive)
- Pages visited, time on each page, referring source — only if you opted into analytics
We do not collect: payment information (our enquiry process never involves payment through this website), special-category data (racial, religious, health, biometric), data about minors under 16, or any data through covert tracking.
3. Why we collect it (purposes of processing)
We use your data only for these specific purposes:
- To respond to your enquiry — preparing a personalised reply, scheduling a private viewing, sending requested information about a Monachus yacht.
- To provide ongoing service if you become a client — yacht-build coordination with the Monachus shipyard in Croatia, refit and ownership support, brokerage transactions.
- To improve our website and services — only with your consent, using anonymised analytics.
- To comply with our legal obligations — accounting records under the Estonian Accounting Act (7-year retention), tax filings, and anti-money-laundering checks where commercially relevant.
- To prevent abuse and secure our systems — detecting and blocking spam form submissions, fraudulent enquiries, or attempted breaches.
We never use your data for unsolicited marketing, profile-building, automated decision-making, or sale to third parties.
4. Legal basis for processing (GDPR Article 6)
Our processing is grounded in the following legal bases:
- Consent (Art. 6(1)(a)) — when you submit our contact form, you provide explicit consent to receive a reply. You can withdraw consent at any time by emailing us.
- Performance of a contract (Art. 6(1)(b)) — once you enter a yacht-purchase or brokerage agreement with us, we process data to fulfil it.
- Legitimate interest (Art. 6(1)(f)) — operating a yacht-representation business, securing our website, and maintaining client records. We have balanced this interest against your privacy rights.
- Legal obligation (Art. 6(1)(c)) — Estonian commercial and tax law requirements.
5. Who we share your data with
We treat your data as confidential. We share it only with the following categories of recipients, and only to the extent strictly necessary:
- Monachus Yachts (Marina Kornati d.o.o., Croatia) — only if you proceed with a yacht build or brokerage transaction and the shipyard requires owner details for the contract. Croatia is in the EU and bound by GDPR.
- Our hosting provider, Zone Media OÜ (veebimajutus.ee), Estonia — for server hosting and email delivery. EU-based, GDPR-compliant.
- Bunny CDN (BunnyWay d.o.o., Slovenia) — for video content delivery. EU-based; receives only technical request data, no form submissions.
- Google LLC — Google Fonts is loaded from
fonts.googleapis.com (may log IP). If you consent to analytics, Google Analytics may also process your usage data. Transfers to the United States are covered by the EU–US Data Privacy Framework adequacy decision (July 2023).
- Professional advisors — accountants, auditors, lawyers, flag-registry agents — bound by professional confidentiality, only when relevant to your transaction.
- Public authorities — only when we are legally required to disclose (e.g., court order, tax audit, regulatory request).
We never sell, rent, or trade your data. We never share it for marketing purposes.
6. International transfers
Most processing happens within the European Union. Two limited transfers exist:
- United States — for Google Fonts delivery and optional analytics. Covered by the EU–US Data Privacy Framework adequacy decision (Commission Implementing Decision 2023/1795 of 10 July 2023).
- None other — we do not transfer data to countries outside the EU/EEA without an adequacy decision or Standard Contractual Clauses.
7. How long we keep your data
- Active enquiries — 24 months from your last contact with us, then deleted unless you become a client.
- Client records — 7 years after the end of the commercial relationship (Estonian Accounting Act §12).
- Server logs — 30 days for security purposes, then deleted.
- Analytics data (if consented) — 14 months at aggregate level, after which it is anonymised.
- Cookie consent records — 12 months in your browser, after which you are asked again.
You can ask us to delete your data earlier (see Section 8).
8. Your rights under GDPR
You have the following rights regarding your personal data. We will respond to any request within 30 days, free of charge:
- Right of access (Art. 15) — request a copy of the data we hold about you.
- Right to rectification (Art. 16) — request correction of inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your data where we no longer need it.
- Right to restrict processing (Art. 18) — request a temporary hold on processing while a dispute is resolved.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format (CSV or JSON).
- Right to object (Art. 21) — object to processing based on legitimate interest.
- Right to withdraw consent — at any time, without explanation, by emailing us. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to lodge a complaint — with the Estonian Data Protection Inspectorate (see Section 9).
To exercise any right, email info@tlm-marine.com with "GDPR request" in the subject. We may ask for identity verification before complying with sensitive requests, to protect your data from impersonation.
9. Right to lodge a complaint
If you believe we have mishandled your data, we encourage you to contact us first so we can address it. You also have the right to lodge a complaint with the supervisory authority:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee
Web: www.aki.ee
10. Cookies and similar technologies
Our website uses cookies and similar local-storage technologies. The detailed list of categories, purposes, and providers is in our separate Cookie Notice. You can manage your preferences at any time using the "Cookie preferences" link in the footer of every page.
11. Children
This website is not directed at children under 16. We do not knowingly collect data from minors. If you believe a minor has submitted personal data to us, please contact us so we can delete it.
12. Security
We protect your data with appropriate technical and organisational measures: HTTPS encryption (TLS 1.3) for all communications, server-side anti-spam filtering on form submissions, role-based access (only the data controller and necessary advisors can access enquiry data), and routine deletion of obsolete records. No system is perfectly secure, but we take reasonable steps to minimise risk.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time — for example, when we add a new service or when law changes. Updates will be reflected by the "last updated" date at the top of this page. Material changes (those affecting your rights or how we use data) will be announced more prominently — through a notice on the homepage or a re-display of our cookie banner.
14. Questions
If anything in this policy is unclear, or you want to know more about how we handle your data, please write to info@tlm-marine.com. We aim to reply within two business days.
This Privacy Policy is provided in English as the primary language of this website. Translated versions for Estonian, Finnish, Swedish, and German will follow. In case of discrepancy between language versions, the English version prevails.