Skip to main content
Begin OÜ (registry code 12100876) is an X-tee member and a data-service intermediary. Its subsystem EE/COM/12100876/begin carries Tervisekassa’s employer services for the companies that use Begin. This page is Begin’s intermediation procedure, published under §5.4.6.1 of the X-tee joining contract. It states on what basis Begin intermediates, how it authenticates and authorises the people who use the services through Begin, and how the resulting logs are archived and kept. Last updated: 4 September 2026.

The basis for intermediating

Begin intermediates two Tervisekassa services, both in the kirst subsystem: Tervisekassa has opened both to Begin’s subsystem. Each employer Begin acts for grants Begin a mandate on eesti.eeVolitused → Tervisekassa alamplokk → Tööandja X-tee teenused, to registry code 12100876. Without that mandate Begin has no right to act for the employer, and Tervisekassa returns nothing. Every employer is also Begin’s client under Begin’s terms of service, accepted when their workspace is created. The employer a request concerns travels in the request itself. Begin reads it from the employer’s own workspace record; no user of Begin can name another company, and Begin never queries for an employer that has not connected the integration.

Who may use the services through Begin

A person reaches these services only from inside their employer’s own Begin workspace, and only after passing four checks.
  1. Identity. They sign in to Begin with a verified email address or phone number, by one-time code, or with a passkey.
  2. Membership. The sign-in resolves to one workspace. A person who is not a member of that workspace has no route to its data.
  3. Permission. Their role in that workspace must carry the Manage integrations permission, checked when connecting the integration, mapping certificate types, and sending the employer’s part.
  4. Employer identity. The company a request is made for comes from the workspace’s own record, never from anything the person types.
Sending the employer’s part carries one more requirement: the personal identification code of the person sending it, in the X-tee userId header. Tervisekassa has required it since 15 September 2025. Begin refuses to send when that code is missing from the person’s profile or fails its checksum, so every submission names a real person. An employer ends the intermediation by disconnecting the integration in Begin, or by withdrawing the eesti.ee mandate. Disconnecting stops the queries — the next scheduled query and every one after it. Deleting the workspace, or removing the company registry code, stops them as well.

Logs of authentication and authorisation

Begin records every act that authorises a Tervisekassa query, in the workspace’s own audit log:
  • connecting and disconnecting the integration, and who did it;
  • recording or withdrawing the eesti.ee mandate confirmation;
  • changing which certificate type becomes which absence;
  • sending the employer’s part — naming the person, the certificate and the figures sent.
Archiving. These entries are not moved to a separate archive. They stay in the workspace’s own audit log, in Begin’s production database, where the employer reads them; the database is backed up as a whole, and a restore restores the log with everything else. There is no export step, no archive medium and no separate archive to request access to — the live log is the archive. Retention. These entries are kept for as long as the workspace exists and are removed with it. When a person’s record is erased, at their request or their employer’s, their personal data is removed from the entries their acts left behind; the entry itself survives without it, because an audit trail that can be emptied is not an audit trail. An employer reads its own audit log in Begin, subject to its plan. Begin’s application logs, which record the outcome of each scheduled query, are kept for the retention period of Begin’s hosting platform and are shorter lived. They are operational records, not the authorisation record.

Logs of X-tee queries

Every message between Begin and Tervisekassa passes through Begin’s security server, operated on Begin’s behalf by Novian Eesti OÜ. The server’s message log is the authoritative record of each query and each response, and it is signed. Begin keeps no separate copy of it. Archiving. The security server operator archives the message log on the cadence its hosting terms set — at the time of writing, once a month. Retention. The message log is archived by the security server operator, and kept for [retention period — to be confirmed with the security server operator]. Access to the archive. A request to read the archive from Tervisekassa, from RIA or from a supervisory authority is addressed to Begin at support@begin.eu; Begin obtains the records from the security server operator. An employer may ask for the records of its own queries on the same route. The operator’s own retrieval procedure is [to be confirmed with the security server operator]. Begin also holds, per certificate, the outcome of the query that fetched it: when it was last synchronised, and whether the employer’s part was sent and by whom. That record lives with the certificate and is deleted with it.

Contact

Begin keeps a register of the clients whose Tervisekassa queries it intermediates and provides it to Tervisekassa on request. For anything about this procedure, write to support@begin.eu.