
General Privacy Policy
Yritysmeili's Principles for the Processing of Personal Data
This General Privacy Policy (“General Privacy Policy,” “Privacy Policy,” or “Policy”) applies to all of Yritysmeili’s operations and the processing of personal data. This Policy explains how your personal data is collected and processed, to whom the data may be disclosed, how long the data is retained, and what your rights are regarding your personal data. Personal data refers to information that can be linked to you directly or indirectly. Information about a person representing a company, such as a CEO, is also considered personal data. However, information about a company that does not refer to a natural person is not considered personal data.
Yritysmeili
Business ID: 3383964-6
4 B Haarlankatu, 33230 Tampere
Phone: 010 3716460 (open weekdays from 9 a.m. to 5 p.m.)
Email: info@yritysmeili.fi
Data Protection Officer: Arttu Aaltonen
Yritysmeili may collect personal data in a variety of ways. You may provide data yourself, for example, when you contact us or use our services or customer service channels. In addition, personal data may be generated in connection with the use of the service, or it may be derived from existing data. Personal data may also be obtained from external third parties, such as public sources. The data obtained may be combined, for example, in connection with the provision of services or marketing communications.
Providing personal information is not mandatory, but failure to do so may affect our ability to provide the service or respond to your requests. In some cases, we cannot provide the service without the required information. In addition, calls related to customer service and sales may be recorded both when you call us and when we call you.
The type and amount of personal data processed are limited to what is necessary in each case. Examples of categories of personal data collected and processed:
Personal data is collected, processed, and used only to the extent necessary for business operations, effective customer service, and commercial activities. Data may also be processed for the purpose of anonymization. Processing is carried out only for legitimate and strictly defined purposes, and the data is not used in any incompatible manner.
Personal data is primarily processed for the purpose of providing, delivering, and maintaining services, as well as managing the customer relationship between you or the company you represent and Yritysmeili. This processing is based on the agreement between you or the company you represent and Yritysmeili.
The company may contact you to inform you about new features of its services and to market and sell its other services. Personal data may also be used for market research and customer surveys. The processing is based on the legitimate interest of providing information about services and marketing other services. You have the right to object at any time to the processing of your personal data for direct marketing purposes.
Service Development, Data Security, and Internal Reporting We also process personal data to ensure the security of our service and website, to improve the quality of our service and website, and to develop our service. We may also compile internal reports based on personal data for management use to ensure the proper management of our business. In these cases, the processing of personal data is based on our legitimate interest in ensuring the appropriate security of our service and website, as well as in obtaining sufficient and appropriate information for the development of the service and the management of our business. Compliance with Laws We may process your personal data to fulfill our legal obligations, e.g., regarding accounting, or to comply with lawful requests for information from authorities. Other purposes to which you have consented We also process your personal data for other purposes if you have given your consent to such processing. Sharing and disclosure of personal data We may disclose personal data to third parties in the following cases: To the extent required or permitted by law, for example, to comply with a request from a competent authority or in connection with legal proceedings. When our service providers or subcontractors process personal data on our behalf and in accordance with our instructions. We are in control of the processing of your personal data and are always responsible for it. When we deem it necessary to exercise or protect our rights, such as to respond to legal claims, to protect your or others’ safety, or to investigate misconduct. When you have given consent to the disclosure of your data. In such cases, the data will be disclosed in accordance with your consent. Transfer of personal data outside the EU or EEA Some of the service providers or subcontractors we use operate outside the European Union or the European Economic Area (EEA), so when they process your personal data, the data must be transferred outside the EEA. In these cases, we ensure the necessary safeguards are in place as required by applicable law. Retention of Personal Data Personal data is retained only for as long as necessary to fulfill the purpose of processing, including to meet legal, accounting, or reporting requirements as described in this Notice. Personal data processed on the basis of a contractual relationship with you or the company you represent is generally retained for the duration of the contractual relationship or for as long as necessary to provide the services. When the customer relationship or the provision of services ends, personal data will be retained to the extent necessary in accordance with statute of limitations laws to respond to claims for compensation or legal actions. We may also retain personal data to the extent necessary to comply with any direct marketing opt-out you have provided. Personal data processed on the basis of a legitimate interest is processed for as long as there are grounds for its processing. If personal data is processed to fulfill legal obligations, it is retained in accordance with legal requirements. The obligation to retain personal data is regulated, for example, by legislation concerning accounting and money laundering. The retention period for personal data processed on the basis of consent is determined by the purpose of the processing. Your rights and options regarding personal data depend on the specific situation and the purpose of the processing. Right of access You have the right to obtain confirmation as to whether your data is being processed and, if so, to access the data. This allows you to obtain information about how we process your personal data, as well as a copy of your data. Right to rectification You have the right to have inaccurate data corrected and, in some cases, to have incomplete personal data supplemented. Right to object to processing You have the right to object to the processing of your personal data based on our or a third party’s legitimate interests if your personal circumstances override
We process personal data to ensure the security of our service and website, to improve their quality, and to develop our service. In addition, we may compile internal reports based on personal data, which are used by management for the proper management of our business. In these situations, the processing of personal data is based on our legitimate interest in ensuring the security of our services and website, as well as in obtaining sufficient and appropriate information for service development and business management.
We also process your personal data to comply with legal obligations, such as accounting requirements or requests for information from authorities based on the law.
Personal data may also be processed for other purposes if you have given your consent.
Some of our service providers or subcontractors may be located outside the European Union or the European Economic Area. In such cases, we ensure that the transfer of personal data is carried out in accordance with the safeguards required by applicable law.
We retain personal data only for as long as necessary to fulfill the purpose of processing, including to meet legal, accounting, or reporting requirements. Personal data based on a contractual relationship is generally retained for the duration of the contractual relationship or for as long as necessary to provide the services. When the customer relationship or the provision of services ends, personal data is retained to the extent necessary in accordance with statute of limitations laws in case of claims for compensation or legal actions. We may also retain personal data to comply with the prohibition on direct marketing. Data processed on the basis of a legitimate interest is retained for as long as there is a basis for the processing. Personal data processed based on legal obligations will be retained in accordance with legal requirements, such as accounting and anti-money laundering laws. The retention period for data processed based on consent depends on the purpose of processing.
Your rights and options regarding your personal data depend on the situation and the purpose of the processing:
You have the right to object to the processing of your personal data if you do not agree with the legitimate interest cited for the processing. However, we may reject your objection if the processing of your personal data is necessary to enforce compelling and legitimate rights. You also have the right at any time to object to the processing of your personal data for direct marketing purposes and related profiling.
You may request access to the personal data you have provided to us for processing based on your consent or a contract. In such cases, we will provide the data to you or to a third party designated by you in a structured, commonly used, and machine-readable format.
You have the right to request the deletion of your personal data if there is no valid reason to continue processing it. This may apply in a situation where you feel that the processing of your personal data is no longer necessary for the purposes mentioned above, or if you wish to withdraw the consent you have given.
In certain cases, you may ask us to restrict the processing of your personal data, for example while we verify the accuracy of the information.
If the processing of your personal data is based on your consent, you have the right to withdraw your consent at any time.
We may ask you to provide certain information to verify your identity and ensure that you are entitled to exercise these rights.
You can exercise your rights by sending a request to info@yritysmeili.fi. If you feel that your personal data is not being processed appropriately, you may also contact the Data Protection Ombudsman.
We implement appropriate physical, technical, and administrative measures to protect personal data against loss, destruction, misuse, and unauthorized access or disclosure. Access to personal data is restricted to authorized employees, subcontractors, and service providers who need the information to perform their duties. They process your data only in accordance with our instructions and are bound by confidentiality obligations.
We may update this Privacy Policy if our practices regarding the processing of personal data change. The Privacy Policy is available at https://www.yritysmeili.fi/tietosuoja, and our other general terms and conditions are available at https://www.yritysmeili.fi/ehdot. This Policy was last updated on November 30, 2025.
Contact us: