Data controllerArt. 4(7) GDPR
The controller is Voitta Oy, Business ID 3187442-1, Aleksanterinkatu 48, 00100 Helsinki, Finland. Privacy requests: [email protected]. Data Protection Officer: [email protected].
Personal data we processArt. 5, 6 GDPR
- Account data — name, work email, company name, business ID.
- Usage data — workspace settings, CPV codes, bid templates.
- Log data — IP address, user agent, session and login events (audit).
- Billing data — Stripe customer ID, billing events.
Legal basesArt. 6 GDPR
- Contract (6.1.b) — providing the service.
- Legitimate interest (6.1.f) — security, product improvement.
- Legal obligation (6.1.c) — accounting, tax, authority requests.
- Consent (6.1.a) — marketing, non-essential cookies.
SubprocessorsArt. 28 GDPR
| Processor | Purpose | Location | Transfer |
|---|---|---|---|
| Hetzner GmbH | Application hosting | Helsinki / Nürnberg | EU |
| Cloudflare | CDN, WAF | EU edge | EU-DC |
| Stripe | Payment processing | Dublin / US | SCC |
| Postmark | Transactional email | EU | EU |
| Anthropic | AI-assisted generation | EU / US | SCC |
| OpenAI | AI-assisted generation | EU / US | SCC |
| Google (Gemini) | AI-assisted generation | EU / US | SCC |
| Sentry | Error monitoring | EU / US | SCC |
| HubSpot | CRM integration (optional) | EU / US | SCC |
| Microsoft | Teams & SharePoint integrations | EU / US | SCC |
| Slack | Workspace notifications (optional) | US | SCC |
Your rightsArt. 15–22 GDPR
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. You may withdraw consent at any time and lodge a complaint with the Finnish Data Protection Ombudsman.
Exercise your rights by emailing [email protected]. We verify your identity before disclosing data.
SecurityArt. 32 GDPR
- All traffic over TLS 1.3; data at rest AES-256.
- Passwords hashed with bcrypt; SSO (SAML, OIDC) on Kirjoita tier.
- Least-privilege access; full audit logging.
- Customer data is not used to train AI models.
Contact
Privacy: [email protected] · DPO: [email protected]. Full Finnish notice: /tietosuoja.