GDPR

Privacy notice

This notice describes how ATM-Tilintarkastus Ky processes personal data on its website and in its client relationships. It is drawn up in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (2016/679).

1. Controller

ATM-Tilintarkastus Ky
Business ID 0416655-0 · EU VAT FI04166550
Harjukatu 18 A 12, 18100 Heinola, Finland
+358 3 812 3456 · support@atm-tilintarkastus-ky.com

The company has not appointed a data protection officer, as the conditions in Article 37 GDPR are not met. Data protection matters can be raised at the email address above.

2. Data we process

Through the website we process only the data you enter into a form yourself:

  • Offer request form: company name, Business ID (optional), contact name, email, telephone (optional), service selection, turnover band (optional), your message, and the estimator selections if you attach them.
  • General contact form: name, email, telephone (optional), subject and message.
  • Technical logs: IP address, timestamp, requested URL and user agent. These are written to the server log, as on any web server.
  • Spam protection: the submission time and a hidden field used to distinguish automated submissions from human ones.

In a client relationship we additionally process the data the engagement requires, such as accounting records, payroll data and tax returns. That processing rests on the engagement agreement and on statutory obligations.

3. Purpose and legal basis

  • Responding to enquiries and preparing offers — steps prior to entering into a contract (Article 6(1)(b) GDPR).
  • Performing the engagement — contract (Article 6(1)(b) GDPR).
  • Obligations under accounting, tax and anti-money-laundering legislation — legal obligation (Article 6(1)(c) GDPR).
  • Service security and prevention of abuse — legitimate interest (Article 6(1)(f) GDPR).

We do not use personal data for profiling, automated decision-making or marketing without separate consent.

4. Cookies and tracking

This site sets no cookies. It uses no analytics, no advertising networks, no social media embeds and no browser local storage. Fonts, images and scripts are served from this same server, so browsing the site opens no connection to a third party.

The claim can be checked in the network tab of a browser’s developer tools. Because there are no cookies there is no consent banner either — section 205 of the Finnish Act on Electronic Communications Services requires consent only where something is stored on the terminal device.

5. Retention periods

  • Enquiries that do not lead to a client relationship: 24 months from the last contact, after which the data is deleted.
  • Server logs: 12 months.
  • Accounting records and financial statements: the period the Finnish Accounting Act requires — vouchers at least six years and accounting books at least ten years from the end of the financial year.
  • Customer due diligence data under anti-money-laundering legislation: five years from the end of the client relationship.

6. Recipients and transfers

Personal data is not sold, rented or disclosed for marketing purposes. It is disclosed only where the law requires it or the engagement demands it — for example filings to the Tax Administration, Incomes Register reports, and the audit file supplied to the statutory auditor.

The site and its database are hosted on a server within the European Union. Personal data is not transferred outside the EU or the EEA.

7. Your rights

Under the GDPR you have the right to:

  • access the data concerning you (Art. 15)
  • have inaccurate data corrected (Art. 16)
  • request erasure, to the extent a statutory retention obligation does not prevent it (Art. 17)
  • restrict processing (Art. 18) and object to processing (Art. 21)
  • receive the data in a portable format (Art. 20)

Requests can be sent to support@atm-tilintarkastus-ky.com. We respond within one month. Identity must be verifiable before any data is released.

8. Security

The site runs over HTTPS only. Form submissions are stored in a database reachable only through named accounts. Accounting records are handled in separate financial administration systems whose access is limited to performing the engagement. Everyone working on an engagement is bound by confidentiality.

A personal data breach likely to result in a risk to the rights of data subjects is reported to the Data Protection Ombudsman within 72 hours and to the data subjects without undue delay.

9. Supervisory authority

If you consider that your personal data has been processed contrary to the GDPR, you may lodge a complaint with a supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi). We would ask you to contact us first — most matters are resolved in a single email.