Privacy policy
Last updated: 12 May 2026
This privacy policy explains how Greentick Oy ("we", "us", "Greentick") collects, uses, and protects personal data when you use our website at greentick.fi or contact us. We follow the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.
1. Controller
Greentick Oy
Y-tunnus: 3450134-8
Kirsitie 12 B, 00760 Helsinki, Finland
Email: hello@greentick.fi
2. What personal data we collect
From our contact form
- Your name
- Your email address
- Your company name (optional)
- Your preferred language
- The content of the message you send us
From third-party services we use
- Google Fonts — when you load a page, your browser fetches our typeface from Google's servers. This means your IP address may be processed by Google in the United States.
- Form delivery service — submissions to our contact form are routed via Formspree (or equivalent) for delivery to our inbox. Their privacy policy applies in addition to this one.
- Cloudflare — we use Cloudflare as a CDN and DNS provider, which processes connection metadata (IP, request headers) to serve the site securely.
We do not currently use analytics, advertising trackers, or third-party cookies on this site.
3. Why we process your data
- To respond to your enquiry (legal basis: Article 6(1)(f) legitimate interest, or 6(1)(b) where we enter a service agreement with you)
- To provide our accounting services when you become a client (legal basis: 6(1)(b) contract, and 6(1)(c) legal obligation under Finnish accounting and tax law)
- To operate and secure the website (legal basis: 6(1)(f) legitimate interest)
4. How long we keep your data
Enquiry messages: up to 12 months from your last contact with us, unless you become a client.
Client records: for as long as required by Finnish accounting and tax law (typically 10 years for accounting material under the Finnish Accounting Act / Kirjanpitolaki).
5. Sharing your data
We share personal data only with the processors needed to deliver our services and operate this website (form delivery, email, CDN, accounting systems where applicable). We do not sell personal data, and we do not share it with marketers or advertisers.
Where data is transferred outside the EU/EEA (for example to Google or our form provider in the US), we rely on the EU Commission's Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable.
6. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Have it corrected or completed
- Have it erased (where there's no overriding legal obligation, e.g. accounting law)
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time, where consent is the basis for processing
- Lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi)
To exercise any of these rights, email hello@greentick.fi. We respond within 30 days.
7. Security
We use HTTPS across the website, encrypt data in transit, and follow the principle of least privilege internally. Access to client data is limited to the partner(s) handling the engagement.
8. Cookies
This website does not set marketing or analytics cookies. The only cookies that may be set are strictly necessary cookies from Cloudflare for security (bot mitigation and rate limiting). These do not require consent under GDPR / ePrivacy.
9. Changes to this policy
We may update this policy as our services evolve. The current version is always available at this URL, with the "Last updated" date at the top.