Insane Labs OÜ
Registry code: 17343365
Tallinn, Estonia
Operator of FarmyHub — farmyhub.com
Adopted: 1 August 2026
Policy owner: Management Board
Review cycle: Annually
This policy explains how Insane Labs OÜ handles requests from government bodies, law-enforcement agencies, regulators, courts, and other public authorities for the personal data of FarmyHub users.
It applies to all employees, contractors, service providers, and other authorised persons who may have access to user data.
The policy covers all personal data controlled by Insane Labs OÜ, including information obtained through third-party login providers such as Facebook Login and Meta Platform Data.
Every request must be reviewed before any information is disclosed or any response is provided.
The review will consider:
whether the requesting authority has legal jurisdiction over Insane Labs OÜ or the relevant data;
whether the request identifies a valid legal basis;
whether the request has been submitted in a legally binding and verifiable form;
whether responding would comply with the General Data Protection Regulation, including Article 6 and Chapter V;
whether the request complies with Estonian law and any other applicable legal requirements.
Insane Labs OÜ will not disclose user data based solely on an informal, verbal, unverifiable, or unsupported request.
Insane Labs OÜ may reject, question, narrow, or challenge any request that appears unlawful, unclear, excessive, disproportionate, or incompatible with the GDPR or Estonian law.
Where appropriate, the company may seek independent legal advice or use available legal procedures before disclosing any information.
Where legally permitted, Insane Labs OÜ may also notify the affected user about the request.
Where a request is determined to be valid and legally binding, Insane Labs OÜ will disclose only the minimum amount of personal data strictly necessary to comply with it.
The company will not provide complete account records when specific information is sufficient. It will also not disclose information concerning users who are not included within the lawful scope of the request.
Every request, including requests that are rejected or challenged, must be recorded in an internal register.
The record should include:
the date the request was received;
the identity of the requesting authority;
the persons involved in reviewing the request;
the legal basis provided;
the company’s assessment and reasoning;
any actions taken to challenge, clarify, or narrow the request;
the information disclosed, if any;
the date and nature of the final response.
These records will be retained for at least five years unless a longer retention period is required by law.
The Management Board of Insane Labs OÜ is responsible for implementing and maintaining this policy.
Only the Management Board, or a person formally authorised by the Management Board, may approve the disclosure of user data in response to a government or public-authority request.
Employees and contractors must immediately forward any such request to the Management Board and must not respond or disclose information independently.
As of the adoption date of this policy, Insane Labs OÜ has not received any requests from government or public authorities for the personal data of FarmyHub users.
This policy will be reviewed at least once a year and updated whenever required by changes in applicable law, regulatory guidance, company operations, or data-processing practices.