1. Who is responsible for your data
The data controller is Azets Insight Oy, Osakeyhtiö, Business ID 0220227-1, registered office Elielinaukio 5 B, 00100 Helsinki, Finland.
For any question about this policy or about your rights, write to info@azetsinsightoy.com. We answer within one month, as Article 12(3) requires, and sooner in practice.
2. What we collect, why, and on what basis
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, company, work email, phone, and the content of your enquiry | Responding to consultation and contact requests | Steps prior to a contract, Art. 6(1)(b) | 24 months from last contact |
| Client contact details, engagement correspondence | Performing an engagement and managing the client relationship | Contract, Art. 6(1)(b) | Duration of the engagement, then 10 years |
| Accounting records and payroll data we process for you | Delivering the contracted service and meeting statutory obligations | Legal obligation, Art. 6(1)(c); contract, Art. 6(1)(b) | Statutory retention: 6 years for accounting material, 10 years for financial statements |
| Consent record: choices, timestamp, policy version | Demonstrating that consent was validly obtained | Legal obligation, Art. 7(1) | 5 years from the decision |
| Server logs: IP address, user agent, timestamps | Security, abuse prevention, diagnosing faults | Legitimate interest in operating a secure service, Art. 6(1)(f) | 90 days |
| Analytics and advertising identifiers | Measuring site usage and advertising effectiveness | Consent, Art. 6(1)(a) | See the Cookie Policy |
Where we process accounting or payroll data on your instructions, we act as a processor and you remain the controller. That relationship is governed by the data processing terms in our engagement letter, not by this policy.
3. What we do not do
- We do not sell personal data, and we never have.
- We do not share enquiry data with advertising networks or data brokers.
- We do not use your data to make automated decisions with legal effects, and we do not profile you.
- We do not send marketing email to people who have not asked for it.
4. Who else sees it
Your data is accessible to our own personnel on a need-to-know basis, and to the service providers we rely on to operate: email and hosting, and our practice management system. Each acts as a processor under a written data processing agreement meeting Article 28, and none is permitted to use the data for its own purposes.
We disclose data to authorities only where law requires it — for example to the Finnish Tax Administration in the course of filings made on your behalf.
5. Where it is stored
Personal data submitted through this website is stored on servers located within the EU/EEA. If a processor ever needs to transfer data outside the EEA, we rely on the European Commission’s standard contractual clauses together with a transfer impact assessment, and we will update this policy before doing so.
6. Your rights
Under the GDPR you may ask us to:
- confirm what data we hold about you and give you a copy (Art. 15);
- correct anything inaccurate or incomplete (Art. 16);
- erase your data where we no longer have grounds to keep it (Art. 17);
- restrict processing while a dispute is resolved (Art. 18);
- provide your data in a portable, machine-readable format (Art. 20);
- stop processing based on legitimate interest (Art. 21).
Where processing rests on consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out. Statutory retention periods for accounting material override an erasure request for that material — we will explain which parts we must keep, and for how long.
Exercise any right by emailing info@azetsinsightoy.com. If you are not satisfied with our response, you may lodge a complaint with Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) in Finland.
7. Security
The site is served over TLS. Form submissions are transmitted encrypted, stored in a database that is not publicly reachable, and access is limited to named accounts with individual credentials. We log administrative access and review it. No system is perfectly secure; if a breach ever affects your rights we will notify the supervisory authority within 72 hours and inform you where Article 34 requires it.
9. Changes to this policy
We update this policy when our processing changes. The date at the top always reflects the current version. Where a change affects the basis on which we hold data you gave us with consent, we will ask again rather than assume.