Privacy Policy

Updated 6/2026

01Data Controller

The data controller is Tilitoimisto Debit Credit (Business ID / Y-tunnus 3512702-8), Haapaniemenkatu 7–9 B, 16th floor, 00530 Helsinki. Data-protection contact: Vladimir Nyman, vladimir@debitcredit.fi.

02Personal data we collect

We collect and process: (a) via the contact form — your name, email address, phone number, company name and message; (b) via the Vaavo client portal (our accounting platform) and the accounting service — bookkeeping material, invoices, source documents (tositteet), bank-transaction data and identifying data, processed under the service agreement.

03Legal basis for processing (GDPR Art. 6)

We process personal data on the following legal bases: performance of a contract (providing accounting services and the Vaavo platform); compliance with a legal obligation (the Accounting Act / kirjanpitolaki and tax law); our legitimate interest (responding to enquiries and securing the service); and consent (any marketing, only with your consent).

04Purposes of processing

We process personal data to handle contact requests; to provide accounting, payroll and tax services and the Vaavo client portal; to fulfil statutory bookkeeping and reporting obligations; and to communicate with you. We do not use your data for marketing without your consent.

05Recipients and processors

We use carefully selected processors under data-processing agreements (DPAs): website hosting — Vercel Inc.; contact-form email delivery — Mailgun (EU region); and for the Vaavo service: Supabase (database and hosting), Enable Banking (PSD2 bank-data access), Maventa (e-invoicing, where the customer enables it) and AI providers (OpenAI and Mistral AI) for document recognition. We also disclose data to authorities (e.g. the Tax Administration / Verohallinto and the Incomes Register / Tulorekisteri) as required by law. We do not sell your data.

06Transfers outside the EU/EEA

Some of our processors (e.g. Vercel and OpenAI) may process data outside the EU/EEA. Such transfers are protected by the EU Standard Contractual Clauses (SCCs) or by an adequacy decision of the European Commission.

07Retention periods

Contact-form data is retained for up to 2 years. Bookkeeping material is retained under the Accounting Act (kirjanpitolaki): financial statements and accounting books for 10 years, and source documents (tositteet) for 6 years from the end of the year. We cannot erase data that we are legally required to retain before the retention period ends.

08Data security

We protect personal data with appropriate technical and organisational measures, including access control, encryption of data in transit and the use of trusted processors.

09Your rights

You have the right of access, the right to rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent. We cannot erase data that we are legally required to keep (for example, bookkeeping material). To exercise your rights, contact vladimir@debitcredit.fi. You also have the right to lodge a complaint with the supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi).

10Cookies

The site uses only technically necessary cookies (for language selection and basic functionality). We do not use analytics or tracking cookies. If this changes, we will ask for your consent.