Privacy policy
Updated 10.10.2026
Translation. The Finnish version prevails.
Draft. This text is under legal review and may still change.
This policy explains how Selko Consulting processes personal data on its website, in its contact form and in its sales to companies. It is written in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (2016/679).
In short: the website sets no cookies and loads nothing from third parties. Contact form data is stored in the EU. General contact details of companies are used for business-to-business email marketing, which can be stopped with a single message.
In client engagements we process personal data on behalf of the client and under the client's instructions. That is agreed in a separate data processing agreement, and this policy does not cover that processing.
1. Controller
Controller: Ville Alén (sole trader, trading as Selko Consulting). Business ID 3660597-6, VAT number FI36605976. Atlantinkatu 7 B 77, 00220 Helsinki. Contact for data protection matters: info@selkoconsulting.com.
The controller's identification details will change when the business is entered in the Trade Register. Until then the controller is the person named above, because an unregistered name cannot carry rights or obligations or respond to a data subject's request. We will update this section at registration, and the update date is shown at the top of the policy.
We have no data protection officer, because the law does not require one for this activity. The controller handles every data protection enquiry personally.
2. What this policy covers
The policy covers four things: use of the website, visitor counting, the contact form and prospecting business customers by email. We also describe briefly how we process the data of our clients' contact persons for invoicing and correspondence.
The policy does not cover personal data we process on a client's behalf in engagements (for example a client's customer service messages or internal documents). There the client is the controller and we are the processor, and the processing is agreed in a data processing agreement.
3. The website: no cookies, no third-party loads
The website sets no cookies or similar identifiers in the browser. It loads nothing from third-party servers: no fonts, no analytics, no embeds, no advertising. Fonts and other files are served from our own server. The only thing stored in your browser is the theme you chose (dark or light). It does not identify you, and it is not sent to us.
When your browser requests a page, the server processes the request technically (IP address, browser details, the requested page) in order to deliver the page. The site is hosted by Cloudflare, Inc. (Workers): a request is handled in the nearest data centre on Cloudflare's network, and server functions run primarily in Northern Europe. We do not store these technical request details in our own systems. Cloudflare's own technical logs are governed by Cloudflare's terms.
4. Visitor counting on our own server
We count page views and a few anonymous events on our own server, into our own database. The counting uses no third-party analytics service, no cookies, no browser storage and no browser identifiers. IP addresses are not stored. The theme choice (section 3) has nothing to do with counting.
We store daily counters only: page address and language, the referring site's domain, an email campaign code, clicks on the main buttons, use of the demo, pricing page tabs, and time on page and scroll depth. The campaign code is the same for every recipient of the same mailing, so it does not identify anyone.
Counting tells us which pages are viewed and how much. It does not tell us who views them, and no row is left about an individual visitor. The counting database is in Supabase Inc.'s service in Stockholm, Sweden.
Legal basis, insofar as counting involves processing personal data at the moment of the request: legitimate interest (Article 6(1)(f)), monitoring the operation and content of the website.
5. Contact form
When you submit the contact form or the free quick assessment form, we store the name, company, email address and message or your five answers, and which of the two forms you used. The data is stored in Supabase Inc.'s database in Stockholm, Sweden. The same retention period applies to both.
To prevent abuse, we store at submission a one-way hash of your IP address (not the address itself) together with the number of submissions per hour. The hash is computed with a secret value, so it cannot be turned back into an address. These rows are deleted once they are more than two hours old; the deletion runs at the next submission and in a daily clean-up. The hash is not attached to your contact details.
A new contact may trigger an alert message to our own mailbox through an email service. The alert contains the form data. The email service and our mailbox provider are listed in the sub-processor table (section 8).
Purpose: responding to the enquiry, arranging an assessment and preparing a proposal. Legal basis: legitimate interest (Article 6(1)(f)), namely responding to your request. If you are personally a party to the contract (for example a sole trader), the legal basis is taking steps at your request prior to entering into a contract (Article 6(1)(b)).
Retention: 12 months from the last contact, unless a client relationship arises. If one arises, the data moves to client data (section 7).
Submitting the form is not mandatory. You can also contact us directly by email, in which case your message is processed in our mailbox on the same basis.
6. Prospecting business customers and email marketing
We look for potential business customers in Finland and email them about our services. The marketing is aimed at companies and organisations, not consumers. Direct marketing to an organisation is permitted in Finland unless the organisation has prohibited it (Act on Electronic Communications Services).
The data we collect: company name, business ID, the company's general email address (for example info@ or sales@), website address, line of business, region, and where the information came from. We do not collect personal email addresses or phone numbers, and we do not profile people. If a company's general address is of the form firstname.lastname@, it is personal data, and we process it under this section.
Sources: the open data of the Finnish Patent and Registration Office (avoindata.prh.fi) and the company's own website. We do not buy address lists.
Legal basis: legitimate interest (Article 6(1)(f)). Our interest is to offer services to companies that may benefit from them. We have assessed the processing as low impact, because the data consists of general contact details published by the companies themselves, messages are sent rarely, and opting out is immediate.
Opting out: every message explains how to prohibit marketing. The prohibition takes effect at once, and we delete the prospect data.
So that the opt-out also holds after the prospect data has been deleted, we keep permanently only a one-way hash of the opted-out address (HMAC-SHA256 with a secret key), and where needed of the domain. The hash cannot be turned back into the address, and no name or other data is kept with it. Every new import and every mailing batch is checked against the hash. Legal basis: legitimate interest (Article 6(1)(f)) and our obligation to respect the opt-out (Article 21).
For now we process the data of Finnish companies only. If we start prospecting in other countries, we will update this section before doing so.
Retention: 12 months from the last contact, unless a business relationship arises. If one arises, the data moves to client data (section 7).
The data in this section is obtained from sources other than the data subject (Article 14). We inform you of this processing in our first message, with a link to this policy.
7. Clients, invoicing and email
When a client relationship arises, we process the name, work email, phone number and job title of the client's contact persons, and the messages and documents relating to the order, invoicing and correspondence. Legal basis: performance of a contract (Article 6(1)(b)) and legitimate interest in corresponding with a company's representatives (Article 6(1)(f)).
Invoices and their supporting documents are kept for the period required by the Accounting Act: vouchers for 6 years and accounting books for 10 years from the end of the financial year. Legal basis: legal obligation (Article 6(1)(c)).
Other client correspondence is kept for the duration of the relationship and 3 years after it ends, to handle possible claims.
Our email is in Zoho Mail's EU service (section 8).
Order acceptance record: when a client accepts an offer on the acceptance page or in the application, we store the accepting person's name, job title and work email, the company details, the ticked acceptances word for word, the version and hash of the terms and the data processing agreement accepted, and the time. We do not store the IP address. Purpose: to show what was agreed. Legal basis: performance of the contract (Article 6(1)(b)) and legitimate interest in handling possible claims. Retention: for the contract period and 10 years after it ends, for accounting and claims.
8. Recipients and sub-processors
We do not sell or disclose personal data for marketing purposes. The following service providers process data on our behalf. Some of them concern client engagements only, not the website; this is marked in the table.
Data may be disclosed to an authority if the law requires it.
| Service | Purpose | Location | Transfer basis |
|---|---|---|---|
| Cloudflare, Inc. (Workers) | Website hosting and server functions | Cloudflare's network: a request is handled in the nearest data centre, server functions primarily in Northern Europe; a US company | EU-US Data Privacy Framework (Cloudflare is certified) and the EU standard contractual clauses in Cloudflare's data processing agreement |
| Supabase Inc. | Database: contact form and visitor counting | Stockholm, Sweden; a US company | EU-US Data Privacy Framework or the EU standard contractual clauses |
| Zoho Corporation (Zoho Mail, EU) | Our mailbox: enquiries, client correspondence and alert messages. | EU: the account is in Zoho's EU service (zoho.eu), where data is stored in EU data centres | Data is stored in the EU. Possible access from outside the EU: the EU standard contractual clauses in Zoho's data processing terms |
| Resend Inc. | Sending the alert message about a new enquiry to our mailbox. Only if this feature is switched on. | United States | EU standard contractual clauses (Resend's data processing agreement) |
| Cloudflare, Inc. (R2) | Storage of the encrypted backups of the agent products' database in client engagements. Not used on the website. Taken into use before the first client. | EU: the storage location is restricted to the EU; a US company | The data is stored in the EU. Possible access from outside the EU: EU-US Data Privacy Framework or the EU standard contractual clauses. |
| Anthropic PBC | Language model API in client engagements. Not used on the website. | United States | EU standard contractual clauses (Anthropic's data processing agreement). Does not use customer data to train models. Inputs and outputs are deleted by default within 30 days. |
| Make (Celonis) | Automation platform in client engagements. Not used on the website. | The EU server region is chosen for the account; the parent company Celonis Inc. is a US company | EU-US Data Privacy Framework (Celonis Inc.) or the EU standard contractual clauses |
| OpenAI | Embedding models in the knowledge search baseline in client engagements. Not used on the website. | United States; EU data residency is chosen when available | EU standard contractual clauses (OpenAI's data processing agreement). Does not use API data for training by default. Retention at most 30 days, or zero retention. |
9. Transfers outside the EU
Data is stored in the EU; some of the service providers are US companies that may access the data from the United States under the EU-US Data Privacy Framework or the EU standard contractual clauses.
The language model APIs (Anthropic, OpenAI) process the content sent to them in the United States unless EU data residency has been chosen. They are used in client engagements only, not for processing website or contact form data.
You can request a copy of the transfer safeguards used from info@selkoconsulting.com.
10. Retention periods in summary
We delete data once its purpose has ended, as follows:
- Visitor counting: no personal data in stored form.
- Contact form: 12 months from the last contact, unless a client relationship arises.
- Contact form IP hash and submission counts: at most two hours.
- Prospect data: 12 months from the last contact, unless a business relationship arises.
- Marketing opt-out: a one-way hash of the address, permanently, so that the opt-out can be honoured. No address and no name.
- Client contact persons and correspondence: for the duration of the relationship and 3 years after it.
- Invoices and vouchers: 6 years; accounting books 10 years from the end of the financial year.
- Order acceptance record: the contract period and 10 years after it.
11. Security
The agent products' data and backups are stored in the EU: the database in Supabase's service in Stockholm and the encrypted backups (AES-256-GCM, key held only by us) in the Cloudflare R2 storage service, with the location restricted to the EU. The copies are deleted after 14 days. No copies are kept on our own devices. Backups are taken into use before the first client.
Data is protected with user accounts and multi-factor authentication. The service providers encrypt data in transit and at rest. Only the controller has access to the data. The prospect list and enquiries are kept only in the services named in this policy, not for example as spreadsheet attachments in email.
If a data breach is likely to pose a risk to your rights, we will notify you and the Data Protection Ombudsman as the Regulation requires.
12. Rights of the data subject
You have the right to know whether we process your data and to receive a copy of it; the right to have inaccurate data rectified; the right to have data erased; the right to restrict processing; the right to object to processing based on legitimate interest; and the right to have the data you provided transferred to another system insofar as the processing is based on a contract or on consent.
You can prohibit direct marketing at any time without giving reasons, and the prohibition takes effect at once.
Requests are sent to info@selkoconsulting.com. We respond within a month. We may ask you to clarify the request or to verify your identity if that is needed to protect the data. Fulfilling a request is free of charge unless the request is manifestly unfounded or excessive.
If you consider that we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Finland that is the Office of the Data Protection Ombudsman, tietosuoja.fi.
13. Changes to this policy
We update the policy when the processing changes, for example when the business is registered, or when a sub-processor changes. The update date is shown at the top of the policy. We tell prospects and clients about material changes to their processing in our next contact.