PRIVACY NOTICE

EU General Data Protection Regulation (EU) 2016/679, Articles 13 and 14, and the Finnish Data Protection Act (1050/2018)

Corporate Customer Register / Ziirto Oy

Created: 21 January 2025 · Last updated: 2 September 2026

1. Controller

Ziirto Oy (Business ID 3155114-7)

Lentäjäntie 3, FI-01530 Vantaa, Finland

Ziirto Oy acts as the controller for the processing described in this notice. Personal data may also be processed within companies belonging to the same group as Ziirto (including 2mm Performance Oy, JustLogi Oy) as described in Section 7 below.

2. Contact person for data protection matters

Harri Hirvonen

Email: harri.hirvonen@2mm.fi

Requests concerning data subject rights (Section 10) should be addressed to the email address above.

3. Whose data we process

This notice describes how Ziirto Oy processes the personal data of the contact persons of its corporate customers and prospective corporate customers (prospects). The data subjects are decision-makers and contact persons of customer and prospect companies, acting in their professional roles.

The data subjects also include visitors to our website, with respect to the collection of visitor data described below.

4. Purposes and legal bases of processing

We process personal data for the following purposes. The legal basis under Article 6(1) of the GDPR is indicated for each purpose.

Purpose of processing

Legal basis

Clarification

Managing customer relationships, providing services and delivering assignments

Contract (Art. 6(1)(b))

Performance of a contract or pre-contractual measures where the data subject represents a customer company.

     

Invoicing, receivables management and accounting

Legal obligation (Art. 6(1)(c))

The Finnish Accounting Act (1336/1997) and other mandatory legislation.

B2B direct marketing, new customer acquisition, customer communications, and the development and analysis of our business, services and customer experience, as well as market and opinion surveys

Legitimate interest (Art. 6(1)(f))

Our legitimate interest is to market and develop our services to business decision-makers on the basis of their professional role. Communications always relate to the data subject’s position and responsibilities in their organisation. The data subject has the right to object to direct marketing at any time (Section 10).

Newsletters and other communications subscribed to by the data subject

Consent (Art. 6(1)(a))

Consent may be withdrawn at any time, e.g. via the unsubscribe link in each message; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Collection of website visitor data: identifying organisations interested in our services and detecting misuse directed at the website

Legitimate interest (Art. 6(1)(f))

We collect visitors’ IP address, time of visit, pages viewed and referring address, and use the IP address to identify the organisation or network operator to which the address is registered. The data is not linked to individual persons and no cookies are used for this collection. A balancing test has been carried out. The data subject has the right to object to the processing (Section 10).

We do not make decisions concerning data subjects based solely on automated processing, within the meaning of Article 22 of the GDPR, that would produce legal effects or similarly significant effects.

5. Categories of personal data

  • Identification and contact details: name, workplace contact details (postal address, telephone number, email address), title, role and area of responsibility in the organisation
  • Information concerning the employer company: company name, industry, size
  • Information relating to the customer relationship and communications: offer, contract and assignment details, contacts, meetings, feedback and customer service records
  • Marketing-related information: areas of interest, newsletter subscriptions, direct marketing opt-outs and consents, message open and click data

  • Website visitor data: IP address, time of visit, pages viewed, referring address, and the organisation or network operator identified on the basis of the IP address

Change history of the above data

We do not process special categories of personal data within the meaning of Article 9 of the GDPR in this register.

6. Sources of personal data

Personal data is obtained from the following sources:

  • From the data subjects themselves: contacts, meetings, forms on our website, newsletter subscriptions and other marketing activities
  • From other contact persons of the customer company as part of managing the customer relationship
  • From the registers of companies belonging to the same group
  • From public and commercial sources: the Finnish Trade Register and other public registers, company websites, and business and decision-maker information services. In our customer relationship management system, we use a data enrichment service that supplements information relating to contact persons’ professional roles (e.g. title, contact details, company information) from a commercial database maintained by the system provider.
  • From website visitors, from the website’s log data

Where personal data has been obtained from sources other than the data subject, this notice also serves as the information to be provided under Article 14 of the GDPR.

7. Recipients and disclosures of personal data

  • Group companies: personal data may be processed within companies belonging to the same group as Ziirto (including 2mm Performance Oy, JustLogi Oy) for internal administrative purposes and for providing our services (legitimate interest, Recital 48 of the GDPR).
  • Processors: we use service providers that process personal data on our behalf and in accordance with our instructions, under data processing agreements pursuant to Article 28 of the GDPR. The categories of processors include the provider of our customer relationship management and marketing platform, the provider of our ERP and invoicing system, the electronic signature service provider, and providers of IT and communications services. Processors have no right to process the data for their own purposes. Information on the processors currently used is available from the contact person referred to in Section 2.
  • Authorities and other third parties: personal data may be disclosed to competent authorities in order to comply with legal obligations. In connection with corporate transactions, data may be transferred to the parties involved within the limits permitted by law.

We do not sell or rent personal data to third parties.

Website visitor data is not disclosed to third parties; IP address network information is resolved locally in our server environment located in the EU, and visitor data is not transferred outside the EU.

8. Transfers of data outside the EU or EEA

Personal data is primarily processed within the EU/EEA. Some of our service providers may process data outside the EU/EEA (including in the United States). In such cases, the transfer is based on a European Commission adequacy decision (e.g. the EU–U.S. Data Privacy Framework) or on the standard contractual clauses adopted by the Commission (2021/914), supplemented with additional safeguards where necessary. Further information on transfer mechanisms is available from the contact person referred to in Section 2.

9. Retention periods

We retain personal data only for as long as necessary for the purposes described in Section 4, in accordance with the following criteria:

Data category / situation

Retention period

Data relating to the customer relationship

For the duration of the customer relationship and for a maximum of 10 years after its termination, for the purpose of establishing, exercising or defending legal claims (Finnish Act on the Limitation of Debts).

Data included in accounting records (e.g. invoicing data)

In accordance with the Finnish Accounting Act: 6 years from the end of the calendar year in which the financial period ended (accounting books 10 years).

Contact details of prospective customers (prospects)

A maximum of 36 months from the most recent active interaction with the data subject. Data with no associated interaction is deleted in regular reviews.

Data based on consent (e.g. newsletter subscriptions)

Until the consent is withdrawn or the subscription is terminated.

Direct marketing opt-outs

The opt-out record (name and contact detail on a suppression list) is retained until further notice in order to ensure compliance with the objection.

Website visitor data

A maximum of 60 days from collection, after which the data is deleted automatically

At the end of the retention period, the data is reliably deleted or anonymised.

10. Rights of the data subject

Data subjects have the following rights under the GDPR. Requests concerning these rights should be addressed to the contact person referred to in Section 2. We will respond to requests without undue delay and in any event within one month of receipt of the request.

  • Right of access (Art. 15): the data subject may request confirmation as to whether we process personal data concerning them, and a copy of the personal data undergoing processing.
  • Right to rectification (Art. 16): the data subject may require the rectification of inaccurate data and the completion of incomplete data.
  • Right to erasure (Art. 17): the data subject may require the erasure of their data, e.g. where the data is no longer necessary for the purposes of the processing, where consent is withdrawn and there is no other legal basis, or where the data subject objects to the processing and there are no overriding legitimate grounds. This right is limited by statutory retention obligations (e.g. the Accounting Act).
  • Right to restriction of processing (Art. 18): the data subject may require the restriction of processing, e.g. for the period during which the accuracy of the data is being verified.
  • Right to data portability (Art. 20): applies to data that the data subject has provided themselves and that is processed by automated means on the basis of consent or a contract.
  • Right to object (Art. 21): the data subject may object, on grounds relating to their particular situation, to processing based on legitimate interest. The data subject has the right to object to direct marketing at any time and without justification, after which the data will no longer be processed for direct marketing purposes.
  • Right to withdraw consent (Art. 7): at any time, without affecting the lawfulness of processing carried out before the withdrawal.
  • Right to lodge a complaint with a supervisory authority (Art. 77): if the data subject considers that the processing infringes data protection legislation, they have the right to lodge a complaint with the Finnish Data Protection Ombudsman: Office of the Data Protection Ombudsman, Lintulahdenkuja 4, FI-00530 Helsinki, Finland, tietosuoja@om.fi, www.tietosuoja.fi/en.

11. Principles of data security

Personal data is protected in accordance with Ziirto’s information security policy through appropriate technical and organisational measures. Digitally stored data is protected by means including access rights management, strong authentication, encryption and firewalls; access to the data is limited to persons whose duties require it. Personnel are trained in secure processing in compliance with data protection legislation, and the training is renewed annually. Manual materials are stored in locked premises. Service providers are contractually required to maintain a corresponding level of information security.

12. Changes to this notice

We continuously develop our operations and may update this notice. Material changes will be announced on our website. The current version is always available at ziirto.fi/tietoturva.

In the event of any discrepancy between the Finnish and English versions of this notice, the Finnish version shall prevail.