Skip to content
NodoSolar

Updated on July 29, 2026

Personal data processing policy

This policy explains what personal data we collect on NodoSolar, what we use it for, who we share it with and how you can exercise your rights over it.

1. Data controller

NodoSolar is a trade name operated by Thinktier OÜ, a company incorporated in Estonia, which acts as the data controller for the personal data collected through this website.

Legal name
Thinktier OÜ
Legal form
Osaühing (private limited company)
Registry code
17249293 — Estonian Business Register (e-Äriregister)
EU VAT number
EE102949399
Registered office
Lõõtsa tn 5, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia
Trade name
NodoSolar, operated by Thinktier OÜ
Contact email
info@nodosolar.co

For any matter relating to your personal data you can write to us through the contact form or at info@nodosolar.co. Enquiries and complaints about personal data are handled by the Data Protection area of Thinktier OÜ.

2. Applicable legal framework

NodoSolar is aimed at the Colombian public and its controller is established in the European Union. We therefore apply two legal frameworks cumulatively:

  • Colombia: Ley 1581 de 2012 (the general personal data protection regime and the right of habeas data), Decreto 1377 de 2013 and any rules developing or replacing them.
  • European Union: Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).

Where the two frameworks recognise a right or a safeguard in different terms, we will apply whichever standard protects you more.

3. What personal data we process

We only process data you give us voluntarily and the technical data your browsing generates. We do not collect sensitive data in the sense of article 5 of Ley 1581 de 2012 (racial or ethnic origin, political opinions, religious beliefs, health, sex life or biometric data), and we do not need it to provide the service.

3.1. Data you give us in the forms

  • Identification and contact: full name, mobile number and email address.
  • Project data: type of property (house, apartment, business or farm), the range of your monthly electricity bill, department and municipality, the estimated timeframe in which you are considering installing, and any comments you choose to add.
  • Solar calculator data, if you send us your result: monthly consumption in kWh, tariff per kWh, zone, estimated system capacity in kWp, coverage percentage and estimated monthly saving.
  • Record of your authorisation: the record that you accepted this policy when submitting the form.

3.2. Technical and browsing data

  • Connection data: IP address, browser identifier (user agent), device type, operating system, browser and preferred language.
  • Approximate location derived from the IP address (country, region and city). We do not access your device’s precise geolocation.
  • Visit origin data: the page you arrived from (referrer), the first page viewed, the page from which you submitted the form, and any advertising campaign parameters present in the address (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid and fbclid).
  • Anti-fraud data: the moment the form was loaded, to distinguish automated submissions from real people.

4. Where we obtain the data

All the data comes from you: what you type into the quote form, the solar calculator or the contact form, and what your browser transmits automatically when visiting the site. We do not buy databases and we do not obtain your data from third parties.

5. What we use your data for

  1. Handling your quote request: understanding your project and selecting verified solar installers who operate in your area and can take it on.
  2. Sharing your request with those installers so they can prepare and send you their proposals.
  3. Contacting you by phone, WhatsApp, email or messaging, to confirm the details of your project, answer questions and follow up on the quotes received.
  4. Preventing duplicates and fraud: detecting automated submissions, limiting repeated submissions from the same connection and identifying duplicate requests.
  5. Measuring and improving the service: analysing in aggregate which content and channels prove useful, in order to improve the site and our campaigns.
  6. Complying with legal obligations and responding to requests from competent authorities.

We do not sell your personal data and we do not pass it to third parties for those third parties’ own advertising purposes.

Under Ley 1581 de 2012, the basis for processing is your prior, express and informed authorisation, given by ticking the acceptance box before submitting the form. Under the GDPR, the legal bases are:

  • Consent (art. 6(1)(a)) to handle your request and share it with the installers.
  • Pre-contractual measures (art. 6(1)(b)) to deal with your request before any contract is entered into.
  • Legitimate interest (art. 6(1)(f)) in the security of the platform, fraud prevention and aggregate measurement of the service.
  • Legal obligation (art. 6(1)(c)) to keep records and respond to requests from authorities.

You can withdraw your authorisation at any time, without affecting the lawfulness of processing carried out before the withdrawal.

7. Who we share your data with

  • Verified solar installers. This is the main purpose of the service: without sharing your request we cannot get you quotes. We share only the data needed for them to prepare a proposal. From that moment each installer acts as an independent controller in respect of the data it receives and answers for its own processing under its own privacy policy.
  • Technology infrastructure providers (site hosting, database and email services), which process the data on our behalf as processors, under contract and only on our instructions.
  • Web measurement tools, when enabled, on the terms described in the cookies section.
  • Public authorities, where there is a legal obligation or a valid request.

Shared management system

Requests are stored in a customer management system (CRM) operated by Thinktier OÜ that also serves other lead-generation platforms in the same group. Each request is tagged with its originating site and form, and access is restricted to the staff who need to handle it.

8. International data transfers

Your data is transferred from Colombia to Estonia (European Union), where the controller is established, and may be processed on servers located in the European Economic Area or in the United States by our infrastructure providers.

The countries of the European Economic Area are among those the Superintendencia de Industria y Comercio considers to offer an adequate level of data protection, under Circular Externa 005 de 2017. In addition, by accepting this policy you expressly and unequivocally authorise that transfer, under article 26 of Ley 1581 de 2012.

Where a provider is outside the European Economic Area, we require adequate safeguards under chapter V of the GDPR, normally through Standard Contractual Clauses approved by the European Commission.

9. How long we keep the data

  • Your request data: for as long as it is being handled and up to two (2) years after the last contact, a reasonable period for dealing with complaints about the process and for picking your project back up if you write to us again.
  • Record of your authorisation: for as long as the processing lasts and for the applicable limitation periods, since the law requires us to be able to prove that you gave it.
  • Technical and anti-fraud data: up to twelve (12) months.
  • Data subject to a legal retention obligation: for the period set by the applicable rule.

Once those periods have elapsed, the data is deleted or irreversibly anonymized. If you request deletion sooner, we will comply unless there is a legal duty to retain it.

10. Your rights as a data subject

Under Ley 1581 de 2012 you have the right to:

  • Access, update and correct your data with the controller.
  • Request proof of the authorisation you gave, except where the law does not require it.
  • Be informed, on request, about the use we have made of your data.
  • File complaints with the Superintendencia de Industria y Comercio for breaches of the regulations.
  • Withdraw your authorisation and request deletion of your data where there is no legal or contractual duty to retain it.
  • Access your personal data free of charge.

The GDPR also grants you the rights to:

  • Restrict processing and object to it.
  • Portability: receive your data in a structured, commonly used and machine-readable format.
  • Withdraw consent at any time.

11. How to exercise your rights

Send your request through the contact form or to info@nodosolar.co, stating your full name, the contact detail you wrote to us with (email or mobile), a specific description of what you are requesting and, if you consider it necessary, a document evidencing your identity or the capacity in which you are acting.

Response times in Colombia. Enquiries are answered within a maximum of ten (10) working days; if that is not possible, we will tell you why and give a date, which will not exceed the five (5) working days that follow. Complaints are answered within a maximum of fifteen (15) working days; if that is not possible, we will tell you why and give a new date, which will not exceed the eight (8) working days that follow.

Response times under the GDPR. We will respond within one (1) month, extendable by up to two (2) further months where the request is complex, informing you of the extension and its reasons.

If a complaint is incomplete, we will ask you to complete it within the five (5) working days following its receipt. Exercising these rights is free of charge.

12. Complaints to the authority

If you believe we have not dealt with your request properly, you can turn to:

  • Colombia — Superintendencia de Industria y Comercio, Personal Data Protection Delegature (sic.gov.co (opens in a new tab)). The law requires that you first exhaust the enquiry or complaint process with us.
  • Estonia — Data Protection Inspectorate, Andmekaitse Inspektsioon (aki.ee (opens in a new tab)), the controller’s supervisory authority in the European Union.

13. Information security

We apply reasonable technical and organisational measures to protect your data against unauthorised access, loss or alteration: traffic encryption via HTTPS, role-based access control to the management system, credentials kept out of the source code, validation of everything arriving from the browser and anti-automation mechanisms in the forms.

No system is completely infallible. Should a security breach occur that poses a high risk to your rights, we will inform you and notify the competent authority within the timeframes the regulations require.

14. Data of minors

NodoSolar is aimed at adults with the capacity to enter into contracts. We do not knowingly collect data from people under 18. If we detect that we have received data from a minor without the authorisation of whoever holds parental responsibility, we will delete it. If you are a parent or guardian and believe this has happened, write to us and we will resolve it.

15. Cookies and browser storage

This site stores in your browser’s session storage the first page you visited, in order to know which channel you arrived through. That data is deleted when you close the tab and cannot identify you on its own.

Web measurement tools, which may set first- or third-party cookies to build aggregate usage statistics, are only loaded if you accept them. The first time you visit the site we ask you, and until you decide no third-party script is loaded and no event is recorded. Declining is exactly as easy as accepting and the site works the same.

Your decision is stored in your browser’s local storage so we do not ask again on every visit. You can change it by clearing the site data from your browser settings, at which point we will ask again. You can also block or delete cookies from there at any time.

16. Automated decisions

We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Assigning your request to one installer or another rests on operational criteria — geographic area, type and size of project — and can always be reviewed by a person if you ask.

17. Changes to this policy

We may update this policy to reflect legal, technical or organisational changes. We will publish the version in force at this same address, with its update date. Where a change substantially affects the purpose of the processing, we will tell you and, if the law requires it, request a new authorisation.

18. Effective date

This policy has been in force since July 29, 2026. The databases we administer will remain in force for as long as is necessary to fulfil the purposes described in section 5, and for the retention periods set out in section 9.

Address for notices: Thinktier OÜ, Lõõtsa tn 5, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia.