> ## Documentation Index
> Fetch the complete documentation index at: https://docs.begin.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Tervisekassa data intermediation procedure

> How Begin intermediates Tervisekassa's X-tee data services for its customers, authenticates the people who use them, and keeps the logs.

Begin OÜ (registry code 12100876) is an X-tee member and a data-service
intermediary. Its subsystem `EE/COM/12100876/begin` carries Tervisekassa's
employer services for the companies that use Begin.

This page is Begin's intermediation procedure, published under §5.4.6.1 of the
X-tee joining contract. It states on what basis Begin intermediates, how it
authenticates and authorises the people who use the services through Begin, and
how the resulting logs are archived and kept.

Last updated: 4 September 2026.

## The basis for intermediating

Begin intermediates two Tervisekassa services, both in the `kirst` subsystem:

| Service                    | What it does                                            |
| -------------------------- | ------------------------------------------------------- |
| `kirst.tvl_loetelu_ta.v1`  | Lists an employer's certificates of incapacity for work |
| `kirst.tvl_taiendamine.v1` | Submits the employer's part of a certificate            |

Tervisekassa has opened both to Begin's subsystem. Each employer Begin acts for
grants Begin a mandate on [eesti.ee](https://www.eesti.ee) — **Volitused →
Tervisekassa alamplokk → Tööandja X-tee teenused**, to registry code
**12100876**. Without that mandate Begin has no right to act for the employer,
and Tervisekassa returns nothing.

Every employer is also Begin's client under Begin's terms of service, accepted
when their workspace is created.

The employer a request concerns travels in the request itself. Begin reads it
from the employer's own workspace record; no user of Begin can name another
company, and Begin never queries for an employer that has not connected the
integration.

## Who may use the services through Begin

A person reaches these services only from inside their employer's own Begin
workspace, and only after passing four checks.

1. **Identity.** They sign in to Begin with a verified email address or phone
   number, by one-time code, or with a passkey.
2. **Membership.** The sign-in resolves to one workspace. A person who is not a
   member of that workspace has no route to its data.
3. **Permission.** Their role in that workspace must carry the **Manage
   integrations** permission, checked when connecting the integration, mapping
   certificate types, and sending the employer's part.
4. **Employer identity.** The company a request is made for comes from the
   workspace's own record, never from anything the person types.

Sending the employer's part carries one more requirement: the personal
identification code of the person sending it, in the X-tee `userId` header.
Tervisekassa has required it since 15 September 2025. Begin refuses to send
when that code is missing from the person's profile or fails its checksum, so
every submission names a real person.

An employer ends the intermediation by disconnecting the integration in Begin,
or by withdrawing the eesti.ee mandate. Disconnecting stops the queries — the
next scheduled query and every one after it. Deleting the workspace, or removing
the company registry code, stops them as well.

## Logs of authentication and authorisation

Begin records every act that authorises a Tervisekassa query, in the workspace's
own audit log:

* connecting and disconnecting the integration, and who did it;
* recording or withdrawing the eesti.ee mandate confirmation;
* changing which certificate type becomes which absence;
* sending the employer's part — naming the person, the certificate and the
  figures sent.

**Archiving.** These entries are not moved to a separate archive. They stay in
the workspace's own audit log, in Begin's production database, where the
employer reads them; the database is backed up as a whole, and a restore
restores the log with everything else. There is no export step, no archive
medium and no separate archive to request access to — the live log is the
archive.

**Retention.** These entries are kept for as long as the workspace exists and
are removed with it. When a person's record is erased, at their request or their
employer's, their personal data is removed from the entries their acts left
behind; the entry itself survives without it, because an audit trail that can
be emptied is not an audit trail. An employer reads its own audit log in Begin,
subject to its plan.

Begin's application logs, which record the outcome of each scheduled query,
are kept for the retention period of Begin's hosting platform and are shorter
lived. They are operational records, not the authorisation record.

## Logs of X-tee queries

Every message between Begin and Tervisekassa passes through Begin's security
server, operated on Begin's behalf by Novian Eesti OÜ. The server's message log
is the authoritative record of each query and each response, and it is signed.
Begin keeps no separate copy of it.

**Archiving.** The security server operator archives the message log on the
cadence its hosting terms set — at the time of writing, once a month.

**Retention.** The message log is archived by the security server operator, and
kept for *\[retention period — to be confirmed with the security server
operator]*.

**Access to the archive.** A request to read the archive from Tervisekassa, from
RIA or from a supervisory authority is addressed to Begin at
[support@begin.eu](mailto:support@begin.eu); Begin obtains the records from the
security server operator. An employer may ask for the records of its own queries
on the same route. The operator's own retrieval procedure is *\[to be confirmed
with the security server operator]*.

Begin also holds, per certificate, the outcome of the query that fetched it:
when it was last synchronised, and whether the employer's part was sent and by
whom. That record lives with the certificate and is deleted with it.

## Contact

Begin keeps a register of the clients whose Tervisekassa queries it
intermediates and provides it to Tervisekassa on request.

For anything about this procedure, write to
[support@begin.eu](mailto:support@begin.eu).
