Legitimate Interest Assessment (LIA)
Last updated: 25.04.2026
GDPR Article 6(1)(f)
Document Details
Controller: XPERT MEDIA OÜ (Evoluna)
Registry code: 12852895
Address: Kirsi tn 8-90, 10616 Tallinn, Eesti
Processing purpose: Aggregation, systematisation, and AI-based enrichment of publicly available professional data of independent specialists (mentors, coaches, consultants, advisors, therapists, wellness professionals, and others) to provide users with a comprehensive overview and personalised matching.
1. Purpose Test
Is there a legitimate interest in processing?
Business interest
To create a marketplace platform that aggregates independent specialists (coaching, mentoring, consulting, therapy, wellness, and related fields) and connects them with service seekers, improving market transparency and discoverability.
Benefit to third parties
Specialists receive additional free professional visibility and new client contacts. Service seekers get a faster, structured, and AI-assisted overview of available specialists.
Criticality
Without data aggregation, it is impossible to create a comprehensive market overview, which is the foundation of Evoluna's business model.
2. Necessity Test
Is the processing necessary to achieve the purpose?
Consideration of alternatives
A consent-only model (where specialists would have to add themselves) does not ensure sufficient data volume for the platform to provide service seekers with a comprehensive and reliable market overview.
Less invasive method
Only data that specialists have themselves publicly and deliberately disclosed for professional purposes (professional registries, industry associations, business profiles) is collected. Private data (personal addresses, bank accounts, health data) is not collected.
3. Balancing Test
Do the data subject's rights outweigh the controller's interest?
Nature of data
This involves professional contact data, not sensitive personal data.
Reasonable expectation
It is reasonable that an independent specialist who publishes their contact details and professional profile in public registries or industry association directories expects to be found by potential clients or intermediary platforms.
Impact on data subject
The impact is positive (greater visibility). Negative impact (spam risk) is mitigated by technical restrictions implemented by Evoluna (anti-scraping measures).
Safeguards
Evoluna implements immediate "Opt-out" right to erasure. Every data subject is notified within 14 days of data being added.
Conclusion
Processing is permitted on the basis of legitimate interest (GDPR Art 6(1)(f)). Evoluna's interest and the specialists' interest in additional professional visibility outweigh the privacy intrusion, as only publicly available professional data is used and extensive safeguards are in place.
Implemented Safeguards
- Art.14 notification within 14 days of data import
- Immediate "One-Click Removal" — right to erasure implementation
- "Do Not Crawl" blocklist — removed data is never re-imported
- Data minimization — only public professional contact data
- Periodic data quality review of unclaimed profiles
- Anti-scraping measures and API rate limiting
- Canary profiles for data theft detection
- AI matching uses only public professional data and voluntarily submitted user assessment results
- AI recommendations are advisory — the final decision is always made by the user (GDPR Art. 22 compliance)
- Three-tier contact protection — specialist contact information is masked by default and revealed only to logged-in users upon request
- Secure message forwarding — clients can send messages to specialists through the platform without direct access to contact information
- Automated abuse detection — automatic monitoring of platform overuse (contact reveals, messages) with temporary restrictions
- Event logging — all significant actions (views, reveals, messages) are logged for transparency and auditability
- Organization member visibility control — each member decides whether their profile is visible on the organization's public page (isPublic setting)
- Invitation-based consent — adding members to an organization is done only via email invitation, which the user must actively accept
- B2B data isolation — organization data (members, invitations, billing) is separated from personal user accounts and deletion does not affect members' personal accounts
- ePrivacy Directive compliance — only explicit opt-in consent is used for sending electronic marketing communications; non-essential cookies (analytics, Stripe) are set only upon active user consent via the cookie banner
Legal Basis
• GDPR Article 6(1)(f) — Legitimate interest
• GDPR Article 14 — Notification when data is not collected directly from data subject
• GDPR Article 17 — Right to erasure (right to be forgotten)
• Estonian Personal Data Protection Act (IKS)
• Estonian Copyright Act — database protection
• ePrivacy Directive 2002/58/EC (as amended by 2009/136/EC) — electronic communications privacy, cookie consent, and direct marketing opt-in requirement
This document has been prepared by XPERT MEDIA OÜ and is retained in internal documents in accordance with GDPR requirements. The document is available to the Data Protection Inspectorate (AKI) upon request.