This document is effective as of 6 January 2025.
Altum Vista Oy ("Altum Vista," "we," "us," or "our") is committed to protecting the privacy of our website visitors and clients. This Privacy Notice outlines our practices for collecting, using, and safeguarding your personal data in accordance with the General Data Protection Regulation (GDPR).
1. Data Controller and Processor
Altum Vista Oy is the data controller for the personal data collected through this website. We utilize Google Workspace for services such as email, document storage, and website hosting. Google, acting as a data processor, stores our Google Workspace data within its European data centers. We also employ Google Analytics to analyze website traffic. Google's privacy policy is available at: [link to Google's privacy policy].
2. Personal Data We Collect
We may collect the following categories of personal data:
Identity and Contact Data: Name, email address, phone number, and address (if provided).
Professional Data: Job title and company (if provided).
Financial Data: Billing information for services rendered (clients only).
Technical Data: IP address, browser type, operating system, referring website, pages visited, and website interactions. This information is collected through cookies and similar technologies (see Section 9).
Usage Data: Information about how you utilize our services.
3. How We Use Personal Data
We use your personal data solely to respond to inquiries, provide and enhance our services, and fulfill our contractual obligations. We do not sell or share your data with third parties for marketing or any other purposes, except as described in this Privacy Notice. Specifically, we use personal data for the following purposes:
Providing advisory and consultancy services.
Responding to inquiries and providing support.
Billing and contract management (clients only).
Complying with legal obligations, including tax laws and data protection regulations.
4. Legal Basis for Processing
We process personal data based on the following lawful grounds:
Performance of a contract: To provide the services you have requested.
Legitimate interests: To improve our services, conduct business analysis, and communicate with you about relevant offerings.
Compliance with legal obligations: To fulfill our legal responsibilities.
Consent: Where necessary, we will obtain your explicit consent for specific processing activities.
5. Data Sharing
We may share your personal data with the following categories of trusted third parties:
Service providers: We engage service providers, such as Google Workspace for email and document storage, Google Analytics for website analytics, and others for IT support, cloud storage, and payment processing.
Professional advisors: Legal, accounting, or other consultancy services.
Authorities: We may disclose your personal data as required by law or legal process.
We ensure that all third parties with whom we share personal data adhere to strict confidentiality and data protection standards in compliance with the GDPR.
6. Data Retention
To comply with legal requirements in Finland (Finnish Accounting Act 655/2003) and Portugal (Portuguese Commercial Code and Decree-Law No. 28/2019), We retain business records, including those that may contain personal data, for a period of 10 years. This retention period encompasses documents such as invoices, purchase orders, and other records relevant to financial transactions. This practice ensures adherence to legal and fiscal obligations, supports accurate financial reporting and auditing, and protects the company's legitimate interests. We implement appropriate security measures to safeguard these records and ensures that only necessary data is retained. Secure disposal procedures are employed upon expiration of the required retention period.
7. Your Rights
Under the GDPR, you have the following rights:
Access: Request access to your personal data.
Rectification: Request correction of inaccurate or incomplete data.
Erasure: Request deletion of your data (right to be forgotten).
Restriction: Request restriction of processing of your data.
Objection: Object to the processing of your data.
Data Portability: Request a copy of your data in a portable format.
Withdrawal of Consent: Withdraw your consent at any time.
To exercise your rights, please contact us at contact@altumvista.com.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. These measures include data encryption, access controls, and regular security assessments.
9. Cookies
Our website uses cookies to enhance your browsing experience and analyze website traffic. Cookies are small text files that are not executable code and pose no security risk. They cannot be used to distribute viruses. Cookies enable the website to remember your actions and preferences (such as login, language, font size, and other display preferences) over a period of time, so you don't have to keep re-entering them whenever you return to the site or browse from one page to another. More about cookies see aboutcookies.org.
We use the following types of cookies:
Essential cookies: Necessary for the website to function properly, enabling basic functions like page navigation and access to secure areas.
Analytics cookies: Used by Google Analytics to collect information about how visitors use our website, helping us to improve the website and your browsing experience. You can learn more about how Google uses your data here: [link to Google's privacy policy].
You can control and/or delete cookies as you wish –You can delete all cookies that are already on your computer and you can set most browsers to prevent them from being placed. However, if you do this, you may have to manually adjust some preferences every time you visit a site, and some services and functionalities may not work.
10. Contact Us
If you have any questions or wish to exercise your rights, please contact us at: contact@altumvista.com
Altum Vista's Board of Directors
6 January 2025