Legal & GDPR Compliance (Finland / EU)

Privacy Policy

Last updated: August 2026 · Compliant with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).

01. Data Controller (Rekisterinpitäjä)

Company / Platform: AMA IT (ama-it.fi)
Location: Helsinki, Finland
Contact Email: info@ama-it.fi

AMA IT is responsible for the lawful processing and safeguarding of your personal data under applicable Finnish and EU regulations.

02. Personal Data We Collect

We only collect information necessary to deliver software development, IT services, and technical support:

  • Account Details: Name, email address, password hash, and optional phone number.
  • Order & Billing Data: Service selections, project specifications, invoice history, and transaction references (credit card details are handled directly and securely by Stripe; we never store raw card numbers).
  • Support Communications: Support ticket inquiries, responses, and file attachments uploaded through our encrypted helpdesk.
  • Technical Logs: IP address, browser type, and session timestamps for security, fraud prevention, and session maintenance.

03. Purpose and Legal Basis for Processing

Data processing is conducted based on Article 6 of the GDPR:

  • Contractual Performance: Processing orders, fulfilling digital services, and managing client subscriptions.
  • Legal Obligation: Statutory accounting and tax record-keeping required under Finnish law.
  • Legitimate Interest: Safeguarding platform security, troubleshooting errors, and preventing abuse.

04. Data Retention & Private Storage Security

All customer files and confidential ticket attachments are stored in private, non-indexed storage volumes located within the EU. Access to files requires authenticated and authorized sessions with role-based validation.

Data is retained only as long as necessary for the fulfillment of active services or compliance with Finnish accounting retention requirements (normally up to 6 years for financial records).

05. Third-Party Processors

We work exclusively with GDPR-compliant service providers:

  • Stripe Payments Europe, Ltd: For secure, PCI-DSS compliant credit card and payment processing.
  • Hosting Infrastructure: EU-based cloud servers ensuring strict data residency compliance.

06. Your Rights Under GDPR (Rekisteröidyn oikeudet)

Under Finnish and EU data protection laws, you are entitled to:

  • Right of access to your personal data.
  • Right to rectification of incorrect or outdated details.
  • Right to erasure ("Right to be forgotten") upon closing your account.
  • Right to data portability.
  • Right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).

To exercise any of these rights, please contact us at info@ama-it.fi.