Data Processing
Updated: July 28, 2026
FHATAL Oy complies with the EU General Data Protection Regulation (GDPR) and other applicable privacy regulations in the processing of personal data. This document supplements our privacy policy and provides more detailed information on data processing.
Legal Basis for Processing
We process your personal data on the following legal bases (GDPR Art. 6):
Consent (GDPR 6(1)(a))
We use consent for sending marketing communications and for the use of non-essential cookies.
Contract (GDPR 6(1)(b))
We process your data to fulfill customer contracts and deliver services.
Legal Obligation (GDPR 6(1)(c))
We process your data to meet the requirements of accounting and tax legislation.
Legitimate Interest (GDPR 6(1)(f))
We process your data based on our legitimate interests in website security, fraud prevention, and business development.
Data Categories and Sources
Data collected directly from you
- Contact information (name, email, phone number)
- Company information (company name, industry, Business ID)
- Communication content (contact forms, emails)
- Project information (requirements, documentation)
Automatically collected data
- Technical data (IP address, browser type, operating system)
- Usage data (site visits, clicks)
- Device data (device type, screen resolution)
Recipients of Data
- Formspree: processor for contact form submissions.
- Google reCAPTCHA: independent controller, for spam and abuse prevention on the contact form.
- Google Analytics 4: processor for website usage statistics, only where you have consented to analytics.
- Hosting providers: for server and infrastructure maintenance.
- IT service providers: for technical support and maintenance.
- Legal authorities: in situations required by law.
All processors are bound by a written agreement covering the processing of personal data. We do not sell personal data, and we do not share it for advertising purposes. Our privacy policy and cookie policy describe these recipients and the cookies involved in more detail.
International Data Transfers
We strive to keep your data within the EU/EEA. If data is transferred outside the EU/EEA, we ensure appropriate protection using EU Commission-approved Standard Contractual Clauses (SCCs) or other GDPR-compliant transfer mechanisms.
Retention Periods
Customer data
We retain customer data for the duration of the customer relationship. After it ends, we keep only what we are required to keep: under the Finnish Accounting Act, accounting records are retained for 10 years and accounting vouchers for 6 years from the end of the financial year. Customer data that is not part of those records is deleted once it is no longer needed for the purpose it was collected for.
Contact information
We retain data collected via contact forms for 2 years, unless a customer relationship is formed.
Technical logs
We retain technical log data for security reasons for a maximum of 6 months.
Security Measures
- SSL/TLS encryption for all data in transit
- Access control: production environments and data are restricted to the team members who need them
- Data minimisation — we collect only what we need
- Regular dependency and security updates
- A defined process for handling suspected personal data breaches, including the notifications described below
Data Subject Rights
- Right of access (GDPR 15): obtain a copy of your personal data being processed.
- Rectification (GDPR 16): request correction of inaccurate data.
- Right to erasure (GDPR 17):the "right to be forgotten" under certain conditions.
- Restriction of processing (GDPR 18): restrict the processing of your data under certain conditions.
- Data portability (GDPR 20): receive your data in a structured format and transfer it to another controller.
- Right to object (GDPR 21): object to processing based on legitimate interest.
- Withdrawal of consent: withdraw consent at any time.
- Right to lodge a complaint (GDPR 77): lodge a complaint with the Data Protection Ombudsman.
To exercise your rights, please contact support@fhatal.com.
Notification of Data Breaches
If a personal data breach occurs, we notify the Finnish Data Protection Ombudsman without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with GDPR Article 33 — unless the breach is unlikely to result in a risk to the rights and freedoms of data subjects.
If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with GDPR Article 34.
Updates
This document may be updated to reflect changing practices and legal requirements. Updates will be published on this page with an updated date.
Contact Information
Controller:
FHATAL Oy
Business ID: 3546336-3
Email: support@fhatal.com