PRIVACY NOTICE

EU General Data Protection Regulation (EU) 2016/679, Articles 13 and 14, and the Finnish Data Protection Act (1050/2018)

Invoicing Register / Ziirto Oy

Created: 21 January 2025 · Last updated: 2 September 2026

1. Controller

Ziirto Oy (Business ID 3155114-7)

Lentäjäntie 3, FI-01530 Vantaa, Finland

The invoicing company and controller is the group company that is the contracting party for the service in question. This notice covers the invoicing register of Ziirto Oy.

2. Contact person for data protection matters

Harri Hirvonen

Email: harri.hirvonen@2mm.fi

Requests concerning data subject rights (Section 10) should be addressed to the email address above.

3. Whose data we process

This notice describes how the personal data of contact persons relating to invoicing is processed. The data subjects are the invoicing contact persons of customer organisations and the reference persons named on invoices. Other processing of personal data relating to the customer relationship is described in the privacy notice for the corporate customer register. 

4. Purposes and legal bases of processing

Purpose of processing

Legal basis

Clarification

Preparing, allocating and delivering invoices to the customer, and managing payments and receivables

Contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f))

Contract in relation to the customer company; in relation to the contact person’s data, our legitimate interest is to invoice the services provided using the reference details supplied by the customer.

Accounting, auditing and value added tax obligations

Legal obligation (Art. 6(1)(c))

The Accounting Act (1336/1997), the Value Added Tax Act and other mandatory legislation.

We do not make decisions based solely on automated processing within the meaning of Article 22 of the GDPR that would produce legal effects or similarly significant effects.

5. Categories of personal data

  • Identification: first and last name and the organisation represented
  • Invoicing reference details: the reference person, reference number or other allocation details provided by the customer, and workplace contact details (email address for delivering invoices or invoice copies)
  • Information contained in the invoice to the extent that it identifies individuals (e.g. the professional who worked on the assignment or the person who performed the invoiced work on an itemisation line)
  • Change history of the above data

6. Sources of personal data

  • From the invoiced customer’s organisation (orders, contracts, reference and e-invoicing details provided by the customer)
  • From e-invoicing address registries and operators for the purpose of transmitting invoices
  • From the systems of group companies (ERP and customer relationship management) with respect to the data forming the basis of invoicing

Where data has been obtained from sources other than the data subject, this notice serves as the information to be provided under Article 14 of the GDPR.

7. Recipients and disclosures of personal data

  • Processors: the provider of the ERP and invoicing system, the e-invoicing operator, and the provider of accounting and financial administration services. Processors act on our behalf under agreements pursuant to Article 28 of the GDPR and have no right to process the data for their own purposes. Information on the processors currently used is available from the contact person referred to in Section 2.
  • Group companies: data is processed within companies belonging to the same group as Ziirto for internal invoicing and administrative purposes (including intra-group subcontracting invoicing).
  • Banks and payment transactions: to the extent required for executing payment transactions.
  • Authorities and auditors: for the fulfilment of statutory obligations (e.g. the Tax Administration) and for carrying out audits.
  • Debt collection: overdue receivables may be transferred to a debt collection service provider, which then acts in its own role as an independent controller or as a processor.

8. Transfers of data outside the EU or EEA

Personal data is processed within the EU/EEA and is not, as a rule, transferred outside the EU/EEA. Should an individual service provider exceptionally process data outside the EU/EEA, the transfer would be carried out in accordance with Chapter V of the GDPR, on the basis of a European Commission adequacy decision or the standard contractual clauses adopted by the Commission (2021/914), supplemented with additional safeguards where necessary. Further information is available from the contact person referred to in Section 2.

9. Retention periods

 Data category

Retention period

Invoices and other accounting vouchers

In accordance with the Accounting Act: 6 years from the end of the calendar year in which the financial period concerned ended.

Accounting books and charts of accounts

In accordance with the Accounting Act: 10 years from the end of the financial period.

Invoicing contact and reference details in systems

For the duration of the customer relationship; updated or deleted when the customer notifies of a change or the relationship ends, except for data included in accounting records.

At the end of the retention period, the data is reliably deleted or anonymised.

10. Rights of the data subject

Data subjects have the following rights under the GDPR. Requests should be addressed to the contact person referred to in Section 2. We will respond to requests without undue delay and in any event within one month of receipt of the request.

  • Right of access (Art. 15): confirmation of processing and a copy of the personal data undergoing processing.
  • Right to rectification (Art. 16): rectification of inaccurate data and completion of incomplete data.
  • Right to erasure (Art. 17): e.g. where the data is no longer necessary, where consent is withdrawn and there is no other legal basis, or where the data subject objects to the processing on justified grounds. This right is limited by statutory retention obligations (e.g. the Finnish Accounting Act).
  • Right to restriction of processing (Art. 18): e.g. for the period during which the accuracy of the data is being verified.
  • Right to data portability (Art. 20): applies to data that the data subject has provided themselves and that is processed by automated means on the basis of consent or a contract.
  • Right to object (Art. 21): on grounds relating to the data subject’s particular situation, where the processing is based on legitimate interest.
  • Right to withdraw consent (Art. 7): at any time, without affecting the lawfulness of processing carried out before the withdrawal.

  • Right to lodge a complaint with a supervisory authority (Art. 77): Office of the Data Protection Ombudsman, Lintulahdenkuja 4, FI-00530 Helsinki, Finland, tietosuoja@om.fi, www.tietosuoja.fi/en.

11. Principles of data security

Personal data is protected in accordance with Ziirto’s information security policy through appropriate technical and organisational measures: access rights management, strong authentication, encryption, firewalls, and limiting access to persons whose duties require the processing. Personnel are trained annually in secure processing in compliance with data protection legislation. Manual materials are stored in locked premises. Service providers are contractually required to maintain a corresponding level of information security.

12. Changes to this notice

We may update this notice as our operations develop. Material changes will be announced on our website. The current version is available at ziirto.fi/tietoturva.

In the event of any discrepancy between the Finnish and English versions of this notice, the Finnish version shall prevail.