Nordlet

← Docs / Legal

X-tee Data Broker Policy

How Nordlet sends data to Estonian authorities over X-tee on behalf of its customers, how customers are authenticated and authorised, and what is logged.

Last updated: 2026-10-06

Nordlet OÜ (registry code 17593783, Pärnu mnt. 139b - 14, Tallinn, 11317, Estonia) is a member of X-tee, the Estonian data exchange layer, and acts as a data broker: it sends tax returns and register entries to X-tee services of the Estonian Tax and Customs Board (Maksu- ja Tolliamet, "EMTA") on behalf of the businesses that use Nordlet ("customers"). This policy states the conditions on which customers get that access.

Nordlet's X-tee subsystems are EE/COM/17593783/nordlet (production) and ee-test/COM/17593783/nordlet (testing).

1. Services Nordlet uses on behalf of customers

EMTA service What Nordlet sends or reads
mkrliides/uploadMime/v1 The VAT return (KMD) with its annex KMD INF, and the TSD declaration files
mkrliides/downloadMime/v1 The acceptance or rejection message for a file sent with uploadMime
tor/TOOTREG/v2 Entries to the employment register
apa-tsd/payments/v1 The data-based TSD annex 1, from the taxation period 10.2026, and its feedback report
apa-tsd/declarations/v1 The confirmation of the TSD of a month, sealed with the customer's e-seal, and the confirmation outcome

Every message Nordlet sends for a customer names that customer as the represented party, following the X-Road third party representation extension, so the receiving service sees both Nordlet and the customer.

2. Authorisation by the customer

Nordlet sends data for a business only when both of these are true:

  1. The business has authorised Nordlet in e-MTA. A representative of the business grants the access right for each service to Nordlet's registry code 17593783 in e-MTA (Settings → Access rights → Representative access rights). For the VAT return this is the right "Käibedeklaratsiooni (KMD) andmete saatmine masin-masin liidese vahendusel" (XT_MM_KMD). The business can withdraw the right in e-MTA at any time.
  2. A user of that business's Nordlet company submits the filing, or has switched on automatic filing. See sections 3 and 4.

3. Authentication of customers

  • Users sign in to app.nordlet.com with a one-time link sent to their email address. The link is valid for 15 minutes and works once. A session lasts 30 days and is not extended. Nordlet stores sign-in links and session tokens only as SHA-256 hashes.
  • API clients authenticate with an API key. Each key belongs to exactly one company, carries a fixed set of permissions, can have an expiry date, and can be revoked. Nordlet stores only the SHA-256 hash of the key.

4. Authorisation of customers inside Nordlet

  • A user acts for a company only through a membership in that company. A user or API key of one company cannot submit a filing for another company: the company is taken from the signed-in session or the API key, never from the request.
  • Sending a filing requires the permission declarations:write. Among user roles, only Owner, Admin and Accountant have it; Manager, Developer and Viewer do not. An API key has it only if it was created with it, and only by a user who has it.
  • Automatic filing sends filings on the schedule the company set. It can be switched on or off only by a user or API key with declarations:write, and each automatic submission is recorded as made by the system.

5. Logs

Record What it contains Who can see it How long it is kept
Submission record The filing, period, status, the authority's reference and answer, the time of sending, acceptance or rejection, the SHA-256 hash of the file sent, and who sent it (user, API key or system) The customer, in Declarations in the application and through the API While the company exists; deleted 10 days after the company is deleted
The file sent The exact file that was sent The customer, from the submission record As above
Audit log Each send, its outcome, each manual status change, changes to filing settings (which fields changed, not their values), certificate uploads and deletions, and automatic filing switched on or off, with the user or API key that did it and the time The customer, in Settings → Audit log and through the API (/v1/audit/list) As above
Sign-in log Sign-ins and refused sign-in attempts, with IP address and browser Nordlet only Deleted when the user account is deleted
X-tee message log The signed messages exchanged through Nordlet's security server, kept by the security server as X-tee requires Nordlet; a customer can request copies of the messages sent on its behalf As configured on the security server

6. Customer access to the X-tee message log

A customer can ask for copies of the X-tee messages Nordlet sent or received on its behalf by writing to info@nordlet.com from an email address of a user of that company. Nordlet answers with the messages that name that customer as the represented party and that are still held in the message log.

7. Problems and contact

Nordlet handles questions about its X-tee membership and about sending and receiving data through it. Contact: info@nordlet.com.

The processing of personal data contained in these messages is governed by the Data Processing Agreement and the Privacy Policy.