Privacy

Privacy Policy

How Tilitoimisto N.M. Oy collects, processes and protects your personal data under the EU General Data Protection Regulation (GDPR).

This is a translation of our Finnish privacy policy. If the versions differ, the Finnish version (tietosuojaseloste) applies.

1. Controller

Tilitoimisto N.M. Oy
Business ID: 3485356-2
Luhtatie 21, 37120 Nokia, Finland
Email: samu@tilitoimistonm.fi
Phone: +358 41 312 7714

Contact person for privacy matters: Samu Mononen, samu@tilitoimistonm.fi

2. Name of the register

Tilitoimisto N.M's customer register, website user register, and marketing and lead register (acquisition of business customers).

3. Purposes of processing

Personal data is processed for the following purposes:

  • Managing the customer relationship: providing bookkeeping, financial statement and tax services, and communicating with customers
  • Customer due diligence: identifying customers and verifying their identity as required by the Anti-Money Laundering Act, keeping customer due diligence data, ongoing monitoring of the customer relationship, and reporting suspicious transactions
  • Handling contact requests: processing and replying to messages sent through the website contact form
  • Chat assistant: answering questions asked in the website chat with the help of artificial intelligence, and monitoring the quality of the answers (see below)
  • Marketing: informing existing and potential business customers about our services (based on legitimate interest)
  • Website development: analysing the use of the website to improve the service

The legal bases for processing personal data are: performance of a contract (Article 6(1)(b)), a legal obligation (Article 6(1)(c)), legitimate interest (Article 6(1)(f)) and consent (Article 6(1)(a)). Consent is used as a legal basis only for Google Analytics cookies (see section 9), not for direct marketing.

Customer due diligence under the Anti-Money Laundering Act

As an accounting firm, we are an obliged entity under the Act on Preventing Money Laundering and Terrorist Financing (444/2017). The Act requires us to identify our customers, verify their identity, know the customer's beneficial owners and the origin of funds, and monitor the customer relationship. The legal basis for this processing is a legal obligation (GDPR Article 6(1)(c)). Providing this information is a condition for starting the customer relationship, because without it we are not allowed by law to carry out the assignment.

In accordance with Chapter 3, Section 3 of the Anti-Money Laundering Act, we inform you that customer due diligence data and other personal data may be used to prevent, detect and investigate money laundering and terrorist financing, and to refer for investigation money laundering, terrorist financing and the offence through which the property or proceeds of crime subject to money laundering or terrorist financing were obtained. Data obtained solely for preventing and detecting money laundering and terrorist financing is not used for any other purpose.

If we detect a suspicious transaction, we must report it to the Financial Intelligence Unit of the National Bureau of Investigation. By law, we may not tell the person the suspicion concerns about the report (Anti-Money Laundering Act, Chapter 4, Section 4).

Our compliance with the Anti-Money Laundering Act is supervised by the Finnish Supervisory Agency (Lupa- ja valvontavirasto). Tilitoimisto N.M. Oy was entered in the anti-money laundering supervision register maintained by the Finnish Supervisory Agency on 19 August 2026. You can check the entry at raksi.lvv.fi with business ID 3485356-2.

Legal basis for direct marketing

Direct marketing to businesses and the maintenance of the lead register are based on the controller's legitimate interest (GDPR Article 6(1)(f)). The legitimate interest is marketing our accounting services to businesses, that is, acquiring new customers. According to Recital 47 of the GDPR, direct marketing may be regarded as processing carried out for a legitimate interest. Marketing is therefore not based on consent.

Electronic direct marketing is directed to businesses and to contact details that the businesses have provided, in accordance with Section 202 of the Act on Electronic Communications Services (917/2014). Under that section, direct marketing may be directed to a legal person unless it has expressly prohibited it. Every message tells you about your right to opt out, and opting out is free of charge (reply to the message with the word "poista", meaning remove).

Some of the contact details provided by businesses are in the form firstname.lastname@company.fi, in which case the address identifies a natural person. Messages to these addresses are based on the person's role in the business: the message is sent to a person who acts on behalf of the business in a role to which our service is substantially related. Bookkeeping is a statutory obligation of a business that is required to keep accounts, so it falls within the duties of the person responsible for the business. This assessment is made and recorded for each recipient before a message is sent.

We have carried out the legitimate interest assessment required by the GDPR (a three-part purpose, necessity and balancing test). The assessment identifies the effects of the processing on data subjects and the safeguards that reduce them: opt-outs are carried out within 48 hours and stored on a permanent suppression list, sending volumes are limited, messages are not resent to wrong recipients, access to the register is restricted, and the data is limited to what marketing needs. No profiling or automated decision-making takes place, and no special categories of personal data are processed. You can get a summary of the assessment by requesting it from samu@tilitoimistonm.fi.

Chat assistant

The answers in the website chat are generated by artificial intelligence (Anthropic's Claude model). The messages you write in the chat are sent to the model to generate an answer, and the conversation is stored for 30 days so that we can check the accuracy of the answers and see what people ask about our services. The conversation is stored together with the page on which the chat was opened, the language, and the country, which is derived from the IP address. The IP address is not stored with the conversation: for daily usage limits, a one-way hash of it is stored and deleted within two days. The legal basis for the processing is our legitimate interest in answering visitors' questions and developing the service (GDPR Article 6(1)(f)). The chat makes no decisions about you, and conversations are not used for profiling or marketing. Do not write your personal identity code, bank details or other sensitive information in the chat: your company's own matters are handled with your accountant by email or phone.

4. Personal data processed

We collect and process the following personal data:

  • Basic details: name, email address, phone number
  • Company details: company name, business ID, address
  • Contact details: messages and information sent through the contact form
  • Chat conversations: the messages you write in the chat and the assistant's answers, the page on which the chat was opened, language and country
  • Customer due diligence data (Anti-Money Laundering Act): name, date of birth, personal identity code and address, the same details of a representative, the names, dates of birth and nationalities of board members, information on beneficial owners and the ownership structure, the details or a copy of the document used to verify identity, information on the remote identification procedure, information on the nature and scope of the business and the origin of funds, whether the person is a politically exposed person, and for a foreign customer the nationality and travel document details
  • Technical data: IP address, browser type and version, operating system
  • Cookie data: data about the use of the website (see section 9)

5. Retention periods

Personal data is kept only for as long as necessary for the purposes described in this policy:

  • Customer data: for the duration of the customer relationship and after it for the period required by the Accounting Act (generally 6 to 10 years)
  • Customer due diligence data: five years from the end of a regular customer relationship; for an occasional transaction, five years from the transaction (Anti-Money Laundering Act, Chapter 3, Section 3)
  • Data on suspicious transactions: five years from the end of the customer relationship or from the transaction. The data is kept separate from the customer register and used only for the purpose laid down in the Anti-Money Laundering Act (Chapter 4, Section 3)
  • Contact requests: up to 12 months after the contact, unless a customer relationship is formed
  • Chat conversations: 30 days, after which they are deleted automatically. The hash of the IP address stored for usage limits is deleted within two days.
  • Marketing and lead register: contact details for up to 12 months from the last contact if the contact has not been answered. The communication history of those who replied for up to 24 months, or, if a customer relationship is formed, the data is transferred to the customer register. The data is deleted earlier if the data subject objects to the processing or requests erasure.
  • Marketing opt-outs: the opt-out record (email address) is kept permanently so that the opt-out can be honoured and no further messages are sent to the same address
  • Cookie data: according to the lifetime of the cookies (see section 9)

6. Sources of data

Personal data is collected from the following sources:

  • The customer: information the customer gives when entering into the customer relationship, by phone, by email or in meetings
  • Contact form: information sent through the website contact form
  • Chat: the messages you write in the website chat
  • Cookies and analytics: technical data collected automatically about the use of the website
  • Public registers: company information from the Trade Register and the Business Information System (YTJ), both from YTJ open data and from the YTJ data service interface

The data in the marketing and lead register is collected from sources other than the data subject. The sources are the open data of the Business Information System (YTJ) of the Finnish Patent and Registration Office and the Finnish Tax Administration, the YTJ data service interface maintained by the Finnish Patent and Registration Office, which we use under an agreement and from which we also get the email address and phone number that the business itself has reported to YTJ, and businesses' own public websites. The register contains the company name, business ID, company form, industry, domicile and registration date, the company's website address, email address and phone number (the address may be in the form firstname.lastname@company.fi or an address of a general email service, in which case it is personal data), the publicly available name and position of a contact person, and the communication history, meaning messages sent, replies and opt-out requests.

7. Disclosure to third parties

As a rule, we do not disclose personal data to third parties. Data may, however, be disclosed in the following situations:

  • Statutory obligations: the Finnish Tax Administration, authorities and other parties to whom disclosure is based on law
  • Financial Intelligence Unit: a report on a suspicious transaction and the information necessary to investigate it (Anti-Money Laundering Act, Chapter 4, Section 1)
  • Finnish Supervisory Agency: information and documents requested for supervision under the Anti-Money Laundering Act (Chapter 7, Section 2)
  • Providing accounting services: to providers of financial management software to the extent that providing the service requires
  • With the customer's consent: if the customer has given explicit consent to the disclosure

Personal data is never sold or disclosed for direct marketing purposes.

8. Service providers and transfers outside the EU/EEA

We use the following service providers in maintaining the website and handling contacts. They process personal data on our behalf. Some of them may process data outside the EU/EEA, mainly in the United States:

  • Cloudflare, Inc.: technical hosting of the website and receiving and storing contact form submissions and chat conversations. Information you send through the form is stored in Cloudflare's storage service for up to 12 months and chat conversations for 30 days. Data may be processed in the United States.
  • Anthropic Ireland, Limited (Ireland): generating the chat assistant's answers with an AI model. The messages you write in the chat are sent to Anthropic to generate an answer. Anthropic does not use data processed through its API to train AI models. Data may be processed in the United States.
  • Resend (San Francisco, United States): forwarding form notifications to our email. Processes the name, email address, phone number and message content you give in the form. Resend uses its own subprocessors, which are listed at resend.com/legal/subprocessors.
  • Google Workspace (Gmail): email communication and receiving contacts at samu@tilitoimistonm.fi. Google may process data in the United States.
  • Supabase, Inc.: database for customer relationship management and contacts. Data is stored in the EU (Frankfurt, Germany), but maintenance access to the database may come from outside the EU/EEA.
  • Google Analytics (G-BH3TCNS55Z): analysing the use of the website, only if you have accepted analytics (see section 9). Google may process data in the United States.
  • Cloudflare Web Analytics: measuring the use of the website without cookies (see section 9). Cloudflare may process data in the United States.
  • Google Maps map embed: the map on the Finnish home page and contact page, which loads only when you press the Näytä kartta (Show map) button. Loading the map transfers your IP address to Google, which may process data in the United States.
  • Smartlead.ai (United States): sending marketing messages to businesses and managing replies. Processes the contact details and communication history in the marketing register.
  • Zapmail: managing sender domains and mailboxes for marketing messages.

Transfers are based on the standard contractual clauses approved by the European Commission and on data processing agreements with the service providers. Google LLC and Cloudflare, Inc. have also certified their adherence to the EU-U.S. Data Privacy Framework.

9. Cookies and analytics

The website stores the following data in your browser. Analytics cookies are used only if you accept them in the cookie banner (Section 205 of the Finnish Act on Electronic Communications Services).

Necessary data that does not require consent

  • Your cookie choice: we store your choice in the browser's local storage (localStorage) so that the banner does not appear on every page. It stays until you change your choice or clear your browser data.
  • Chat: the chat stores the ongoing conversation, and whether the chat hint has been shown, in your browser's session storage (sessionStorage), so that the conversation continues when you move from page to page. It is deleted when you close the browser tab.

Google Analytics, only with your consent

If you accept analytics, the website loads Google Analytics (ID G-BH3TCNS55Z). It stores the cookies _ga and _ga_BH3TCNS55Z in your browser, valid for up to two years. From them we see, in aggregate, which pages are viewed, how long people stay on them, where visitors come from, what kinds of devices they use and which features are used, such as clicks on the phone number and form submissions. For visits from the EU, Google uses the IP address only to derive a coarse location, such as country and city, and does not store it. Google Signals and advertising features are turned off, and the data is not used for advertising.

Once you have accepted analytics, the website also remembers for the session which site or campaign link you came from, and attaches that information to the contact form if you send one. It is kept in your browser's session storage and deleted when you close the tab.

Cloudflare Web Analytics, without cookies

We measure page views and page load times for all visitors with Cloudflare Web Analytics. It does not use cookies or store anything in your browser, and it does not identify individual visitors by IP address or browser details. The legal basis is our legitimate interest in monitoring how much the website is used and how well it works (GDPR Article 6(1)(f)).

Fonts and map

The website's fonts are loaded from our own server, so loading them does not pass your data to third parties. The Google Maps map on the Finnish home page and contact page loads only when you press the Näytä kartta (Show map) button (see section 8).

Changing your choice and withdrawing consent

You can change your choice at any time from the Cookie settings link at the bottom of every page, or by opening the cookie settings here. When you withdraw consent, the Google Analytics cookies are deleted from your browser and Google Analytics is no longer loaded. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

10. Your rights

Under the EU General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access: the right to check what personal data about you has been stored
  • Right to rectification: the right to have inaccurate or incomplete data corrected
  • Right to erasure: the right to have your personal data erased ("right to be forgotten"), unless there is a legal ground for keeping it
  • Right to restriction of processing: the right to have the processing of your data restricted in certain situations
  • Right to data portability: the right to receive the data you have provided in a structured, commonly used and machine-readable format
  • Right to object: the right to object, on grounds relating to your particular situation, to processing based on legitimate interest. For direct marketing the right to object is absolute: when you object, we stop the marketing and do not ask for a reason.

Opting out of direct marketing. You can opt out of marketing at any time free of charge by replying to any of our messages with the word "poista" (remove) or by writing to samu@tilitoimistonm.fi. We carry out the opt-out within 48 hours and store the opt-out record so that no further messages are sent to the same address.

Exception for anti-money laundering data. The data subject has no right to access data obtained to fulfil the obligation to report suspicious transactions, nor data and documents obtained to fulfil the obligation to obtain clarification (Anti-Money Laundering Act, Chapter 4, Section 3). At the data subject's request, the Data Protection Ombudsman can check the lawfulness of the processing of this data. Customer due diligence data cannot be erased for as long as the law requires it to be kept.

You can exercise your rights by contacting us by email: samu@tilitoimistonm.fi. We will respond to your request within one month at the latest.

You also have the right to lodge a complaint with the supervisory authority if you consider that the processing of your personal data infringes data protection legislation. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).

11. Security

We protect personal data with appropriate technical and organisational measures:

  • SSL/TLS encryption: all traffic between our website and the user is encrypted
  • Access control: personal data can be accessed only by persons whose duties require it
  • Password protection: systems are protected with strong passwords
  • Security updates: the software and systems we use are kept up to date

12. Changes to this privacy policy

We may update this privacy policy when needed. Significant changes are announced on our website. We recommend that you check this policy from time to time.

13. Contact for privacy matters

For any questions about the processing of personal data, you can contact us:

Samu Mononen
Tilitoimisto N.M. Oy
Email: samu@tilitoimistonm.fi
Phone: +358 41 312 7714
Address: Luhtatie 21, 37120 Nokia, Finland

This privacy policy was last updated on 24 September 2026.