Privacy policy

Privacy policy


Controller contact details

Tickingbot Oy

Visiokatu 4, FI-33720 Tampere, Finland

Business ID 2757079-1

Person responsible for data protection

Juho Kokkonen | security@tickingbot.fi

1. Our principles for processing personal data

Tickingbot Oy is committed to complying with the EU General Data Protection Regulation (GDPR) and applicable Finnish data protection legislation.

1.1 Basic principles

  • Personal data is confidential and is primarily processed only by our employees.
  • Collection and use are planned. We avoid unnecessary collection, processing and retention.
  • Processing is based on consent, a contract, a legal obligation or a legitimate interest.
  • We use personal data mainly to provide services, manage customer relationships, invoice customers, conduct sales and recruitment, and develop these activities.

2. How do we use your personal data?

We collect, retain and process personal data only for predefined purposes, including service delivery, customer management, invoicing and debt collection, complaint handling, customer support, customer satisfaction measurement, legal obligations, accounting and human resources administration.

3. What data do we collect and from which sources?

We mainly collect personal data directly from you when you contact us. We may also collect customer data from public sources and registers, including LinkedIn and other social media. Website visitor information may be collected for analytics and service development.

  • Customer contact details: employer, name, work address, business email, phone number, position, communications and customer relationship history.
  • Information submitted through contact forms and chat.
  • Website usage data, including IP address or another identifier.
  • Employee and applicant data, including basic information, CV, application, references with consent, payroll information and information required to fulfil employment obligations.
  • Certain special-category employee data, such as trade union membership or health data, only where required to meet the employer’s legal obligations.

4. Legal bases for processing

We ensure that processing always has a lawful basis. Customer register data is primarily processed to prepare and perform contracts and on the basis of legitimate interests such as service delivery, customer management, complaint handling and the provision of maintenance and further development. We may also process data on the basis of consent or a legal obligation. Consent may be withdrawn at any time where it is the sole basis for processing.

5. Who processes your data and is it disclosed?

Personal data is processed by employees who need it for their duties, such as customer service, sales, marketing and recruitment. Data is handled confidentially and only to the extent necessary. It is not disclosed to third parties without a lawful basis, except where required for service delivery, legal compliance, the data subject’s consent or a corporate transaction.

6. Is data transferred outside the EU?

In certain situations, data may be transferred outside the EU because some cloud services operate outside the EU. Where this occurs, we ensure that the transfer has a lawful basis and appropriate safeguards, such as an adequacy decision or the European Commission’s standard contractual clauses. Tickingbot uses HubSpot CRM for customer data management, marketing and customer relationship management. According to the Finnish source, the servers used for this data are located in the European Union.

7. How long do we retain personal data?

We retain personal data only for as long as necessary for its purpose or to meet legal obligations. Customer data is retained during the relationship and for a reasonable period afterwards. Marketing data is retained until consent is withdrawn or deletion is requested. Recruitment data is retained for a maximum of 24 months. Data required by law, such as accounting records, is retained for the statutory period. When retention is no longer necessary, data is securely deleted or anonymised.

8. How do we protect your data?

Data is mainly stored electronically on service providers’ servers protected according to generally accepted industry practices. Access is limited through personal credentials, passwords and permissions. Our premises are locked and protected.

9. Is providing data mandatory?

If you do not provide personal data or permit its processing, we may be unable to serve you fully. If you do not want us to process your data under this notice, please do not submit personal data to us.

10. Your rights

  • Withdraw consent where processing is based on consent.
  • Obtain confirmation of whether we process your personal data and access that data.
  • Request correction of inaccurate, outdated or incomplete data.
  • Object to processing based on public interest or legitimate interests, subject to legal exceptions.
  • Request restriction of processing in certain situations.
  • Receive data you provided electronically in a commonly used format where processing is based on consent or a contract.

11. How to exercise your rights

Contact us at security@tickingbot.fi. Please include your name, address and phone number. We may request proof of identity to verify your request.

12. Updates to this notice

We may update this privacy notice when our operations, privacy practices or legislation change. Changes take effect when the updated notice is published. Please review the notice regularly.

13. Data protection contact

Tickingbot Oy, Visiokatu 4, FI-33720 Tampere, Finland | Business ID 2757079-1

Juho Kokkonen | security@tickingbot.fi

Finnish source last updated: 4 November 2025