Privacy, terms and cookies
Last updated: 5 October 2026
Three short documents on one page: how 2RUN OÜ handles personal data, the terms on which we work with agencies, and what this website stores in your browser. Where a signed agreement with you, such as an NDA or a project quote, says something different, the signed agreement applies.
Company details
The company behind 2run.dev, and the controller of any personal data described on this page, is:
| Legal name | 2RUN OÜ (private limited company under Estonian law) |
|---|---|
| Registry code | 17290315 (Estonian Commercial Register) |
| VAT number | EE102937615 |
| Registered office | Paavli tn 5a/1, 10412 Tallinn, Estonia |
| [email protected] | |
| Supervisory authority | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee |
1. Privacy Policy
2RUN OÜ ("2RUN", "we") is the controller of the personal data described in this policy. It applies to 2run.dev and to the data we handle when an agency contacts us or works with us. We collect as little as we can, we never sell personal data, and we never contact your clients.
1.1 What we collect and why
We only process the personal data we need for one of the purposes below.
Enquiries. When you use the brief form or email us, we receive your name, agency name, work email, the subject you chose, your message and whether you asked for an NDA. We use this to reply, to send you our NDA and to prepare a quote. Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to business enquiries (Art. 6(1)(f) GDPR).
Form protection. The brief form is protected by Cloudflare Turnstile, which checks that the submission comes from a person and not a bot. Turnstile processes technical data such as your IP address and browser characteristics for that purpose only. Submissions are then processed by a serverless function on Cloudflare and delivered to us by email through Resend. Legal basis: our legitimate interest in preventing spam and abuse (Art. 6(1)(f) GDPR).
Projects. During a project we process the business contact details of the people we work with on your side, the briefs, designs, access credentials and code you share, and our communication in your Slack, email and repositories. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR). Where a project involves personal data belonging to your clients, for example user accounts in a database we migrate, we process it only on your instructions as your processor and sign a data processing agreement on request.
Invoicing and accounting. Names, addresses, VAT numbers, bank details and invoices. Legal basis: our legal obligations under Estonian accounting and tax law (Art. 6(1)(c) GDPR).
Website visits. When you open 2run.dev, our hosting provider (Cloudflare) records technical data such as your IP address, browser type, the page requested and the time of the request in its logs, in order to deliver the site and keep it secure. We also use Google Analytics 4 in a privacy-preserving configuration (Google Consent Mode v2 with all advertising storage denied, IP addresses not stored by Google, loading deferred until you interact with the page) to understand, in aggregate, how the site is used. Legal basis: our legitimate interest in running a secure, useful website (Art. 6(1)(f) GDPR). Details of the cookies involved are in the Cookie Policy below.
Fonts and images. All fonts, scripts and images are served from our own domain. Opening this website does not trigger requests to third-party font or image servers.
1.2 Who we share data with
Service providers that act on our instructions under data processing agreements (Art. 28 GDPR): Cloudflare (hosting, form processing and Turnstile), Resend (delivery of form submissions by email), Google (aggregated analytics), and the providers that run our email, file storage, code repositories and accounting.
Where a provider processes data outside the European Economic Area, we rely on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework) or on the Commission's Standard Contractual Clauses.
Public authorities, only where the law requires it.
Nobody else. We do not sell personal data, and project information is shared only with the people working on that project.
1.3 How long we keep it
Enquiries that do not lead to a project: up to 24 months after our last contact.
Quotes, contracts and project correspondence: for the duration of the project and for up to three years after it ends, which is the general limitation period for contractual claims under Estonian law.
Invoices and accounting records: seven years, as required by the Estonian Accounting Act.
Designs, code and other project files you share with us: deleted or returned at your request once the project and its 30-day fix period are over. Access credentials you give us are deleted when the project ends.
Hosting logs: kept by Cloudflare for a short period for security purposes only. Analytics data: Google Analytics event data is retained for 14 months and reported only in aggregate.
1.4 Your rights
Under the GDPR you can ask us at any time to see the personal data we hold about you, to correct or delete it, to restrict or object to its processing, and to receive it in a portable format (Articles 15 to 21 GDPR). Where processing is based on consent, you can withdraw that consent at any time. Write to [email protected] and we will answer within one month.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or with the data protection authority in your own country.
1.5 Security
We use encrypted connections, limit access to the people working on your project and prefer to work inside your own repositories and tools, so that as little of your data as possible is stored with us. Everything you share during a project is also covered by the confidentiality obligations in the Terms of Service and in any NDA we sign with you.
1.6 Changes to this policy
We update this policy when our practices change. The date at the top of this page shows the current version.
2. Terms of Service
These terms apply to all development, migration and technical SEO services that 2RUN OÜ ("2RUN", "we") provides to agencies and other business customers ("you"). We work with businesses only, not with consumers. Each project is also covered by a written quote and, where signed, an NDA. If these documents conflict, the signed NDA applies first, then the quote, then these terms.
2.1 Quotes and scope
Every project starts with your brief. Based on it we send a fixed-price quote that describes the deliverables, our assumptions, the timeline and the payment schedule. The quote is valid for the period stated in it. A project starts when you accept the quote in writing (email is enough).
Work outside the quoted scope, including design changes after sign-off, is quoted separately before we start on it. We do not act on scope changes without your written approval, so you never receive an invoice you did not expect.
Longer engagements, for example a developer for a few months, are quoted as a monthly fee for an agreed capacity.
2.2 What we need from you
The brief, designs, content, access and approvals we need, in time for the agreed schedule. Delays on your side move the schedule by at least the same amount.
Confirmation that you hold the rights to everything you give us (designs, fonts, images, code and content) and that you are authorised by your client to commission the work.
Ownership of your client relationship. You remain responsible for your client's acceptance of the work, for their content and for the legal compliance of their website (for example cookie consent and privacy notices), unless we have been asked to deliver those items as part of the quote.
2.3 How we work
We work white-label, under your agency's name, in the tools you choose: Slack, email, repositories and project boards. We do not contact your clients unless you ask us to, and never on our own behalf. We follow your repository, branching and review rules where you have them, and sensible defaults where you do not.
2.4 Delivery, acceptance and the 30-day fix period
We deliver to your repository or staging environment. You have ten working days to review a deliverable and report any issues. If we do not hear from you within that time, the deliverable counts as accepted.
For 30 days after launch we fix bugs in our own work at no charge. A bug is work that does not function or render as agreed in the brief and quote, in the browsers and devices agreed for the project.
Changes to scope, content, hosting or third-party services, changes made by others after handover, and new features are not bugs and are quoted separately.
2.5 Payment
Fixed-price projects are invoiced as set out in the quote, typically a deposit before work starts and the balance at handover. Monthly engagements are invoiced monthly.
Invoices are due within 14 days unless the quote says otherwise. Prices exclude VAT. For business customers in other EU countries with a valid VAT number the reverse-charge mechanism applies; for customers outside the EU no Estonian VAT is charged.
If an invoice is overdue we may pause work until it is settled and charge statutory late-payment interest under Estonian law.
2.6 Ownership of the work
Until the invoice for a deliverable is paid in full, we own what we have produced. On full payment we assign to your agency the copyright and other intellectual property rights in the code, designs and other materials we created specifically for your project. You can use, change, host and pass them on to your client without any further fee.
Open-source components keep their own licences. Generic tools, snippets and know-how that we use across projects remain ours; you receive a perpetual, royalty-free licence to use them as part of your deliverables.
We do not show white-label work in our portfolio or name your clients without your written permission.
2.7 Confidentiality and non-solicitation
Everything you share with us about your agency, your clients and your projects is confidential. We use it only for the project, share it only with the people working on the project, and keep it confidential for five years after the project ends.
We will not approach, pitch to or accept work directly from a client of yours that we came to know through a project, during the project and for 24 months after it ends.
Where we sign a separate NDA with you, its terms apply in addition to this section and take precedence where they are stricter.
2.8 Liability
We carry out our work with the care expected of a professional development team. To the extent permitted by law, our total liability for a project is limited to the fees you have paid for that project, and we are not liable for indirect losses such as lost profit, lost revenue or the loss of a client. We are not liable for problems caused by hosting, third-party services, content, or changes made by others after handover. Nothing in these terms limits liability for intent or gross negligence.
2.9 Ending a project
A fixed-price project ends at handover and the end of its 30-day fix period. You can stop a project at any time by email; you pay for the work done up to that point, and ownership passes for what you have paid for.
Monthly engagements can be ended by either side with 30 days' notice.
Either side may end the work immediately if the other seriously breaches these terms and does not put it right within 14 days of being asked to.
2.10 Governing law and general terms
These terms are governed by the laws of the Republic of Estonia. Disputes that cannot be settled amicably are decided by Harju County Court (Harju Maakohus) in Tallinn. If a part of these terms turns out to be invalid, the rest remains in force. We may update these terms; the version published on this page when you accept a quote applies to that project.