Privacy policy
Kasvuasiaintoimisto Kansleri Oy processes the personal data of its customers and of visitors to the tapiokauranen.com website in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (tietosuojalaki). This policy explains what data is processed, why, and what your rights are.
Updated 1 October 2026. This policy was first drawn up on 27 September 2020.
Controller
Kasvuasiaintoimisto Kansleri Oy
Business ID 3144343-7
Keskuskatu 19 B, 37550 Lempäälä, Finland
Contact person responsible for the register: Tapio Kauranen, tapio@kansleri.fi
Name of the register: the customer register of Kasvuasiaintoimisto Kansleri Oy. This policy also covers the data of visitors to the tapiokauranen.com website.
Purposes and legal bases
Personal data is processed for the following purposes:
- Communicating with customers, sales and marketing. The legal basis is the controller’s legitimate interest in communicating with its customers and in selling and marketing its services.
- Quotes, contracts and delivering the services ordered. The legal basis is a contract, or steps taken before entering into one.
- Invoicing and accounting. The legal basis is a legal obligation, such as those under the Finnish Accounting Act (kirjanpitolaki).
- Website visitor statistics. The legal basis is your consent: the website’s own visitor statistics and Google Analytics are used only if you allow analytics.
- Anonymous visitor counts and statistics from the server logs. The legal basis is the controller’s legitimate interest in knowing how much the website is visited, which pages are read and where visitors come from.
- Website operation and security. The legal basis is the controller’s legitimate interest in keeping the website working and secure.
Data processed
The register may contain the following data:
- name, job title and company or organization
- contact details: email address, phone number and postal address
- website addresses, and usernames and profiles on social media services
- messages, information sent through forms, and appointment bookings
- details of the services ordered and of changes to them, and billing details
- other information related to the customer relationship and the services ordered
- data on the use of the website: the IP address of your internet connection, browser and device information and, if you have allowed analytics, the analytics identifier and visit data
Where the data comes from
The data is obtained from customers themselves: from the details they give on the website’s forms and when booking an appointment, by email, by phone, through social media services, from contracts, at customer meetings and in other situations in which customers provide their data. Data on the use of the website is generated as you browse the website.
When you use the website
On the website, personal data is collected through the forms, the appointment booking, the anonymous counting of visitors and, if you allow it, visitor analytics.
Contact forms
The information you send through a form, such as your company, email address, phone number and message, is delivered to Tapio Kauranen by email. The website’s server does not store the content of the forms.
Appointment booking
Appointments for the free SEO check and the free WordPress consultation are booked through Calendly. The name, email address and other details you give when booking are stored in Calendly. Meetings are held on Google Meet.
Anonymous visitor counts
The website counts all visits anonymously, also without your consent. The count records the page viewed, the website you came from and any campaign tags. It also records which theme you used, your device type and browser, and whether you booked a meeting or sent a form. Nothing is stored in your browser, and your IP address is not stored.
Visits on the same day are linked by a hash. It is calculated from your IP address and your browser’s identifier with a key that changes every day and is deleted at the end of the day. Visits can therefore not be linked across days or to you. If your browser asks not to be tracked (Global Privacy Control or Do Not Track), your visit is not counted.
Visitor analytics
If you allow analytics, the website collects its own visitor statistics. They record the pages you view, where you came to the website from and any campaign tags. They also record how far you read a page and how long it was visible, whether you used the light or the dark theme, your clicks on buttons and on links to other websites, and whether you sent a form or booked a meeting. From your device, they record its type, your browser, the screen width and the language.
A random identifier, kept in your browser for 13 months, links your visits. Your IP address is not stored. The data is stored on the website’s own server in France (Alwaysdata) and is not passed on to anyone.
With the same consent, the website loads Google Tag Manager and Google Analytics. They collect data on how the website is used: the pages viewed, where you came to the website from, how long the visit lasts, your device, your browser and your approximate location. If you choose Accept all, Google may also use the data in its advertising services. Without your consent, neither of them starts.
The choices made in the cookie banner are counted without any identifier. The counts show how large a share of visits the statistics cover.
Images and videos
A few articles contain images from other websites, which load from those websites’ servers. YouTube videos embedded in articles load only once you accept them.
Server logs
The website’s hosting service keeps standard server logs: the IP address, the time, the page requested and browser information. They are used for the website’s security and for troubleshooting. Anonymous statistics are also compiled from the logs, such as the numbers of visits to pages, traffic sources and visits by search engines’ robots. No IP addresses are stored in the statistics.
Cookies
You can find the website’s cookies and your cookie settings on the Cookie policy page.
Disclosures and transfers
Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer, for example in client case studies.
Data is also processed by the service providers whose services the website and customer communications use: the website’s hosting and email services, Calendly (appointment booking) and Google (Analytics, Tag Manager and Meet).
Google and Calendly are US companies, so data may be transferred outside the EU and the EEA. These transfers are based on the EU-U.S. Data Privacy Framework or on standard contractual clauses approved by the European Commission.
Retention and security
Data is kept for as long as the customer relationship or ongoing communication requires it. Data in the register is deleted when there is no longer any reason to keep it.
Accounting records are kept for as long as the Accounting Act requires: accounting vouchers for six years and financial statements for ten years. The data of the website’s own visitor statistics is kept for at most 25 months, and Google Analytics event-level data for at most 14 months. How long each cookie lasts is set out in the cookie policy.
The register is handled with care, and data processed in information systems is appropriately protected. The website uses an encrypted HTTPS connection. When data is stored on internet servers, the physical and digital security of the hardware is looked after. Stored data, server access rights and other information critical to security are handled confidentially and only by the people whose duties include it.
Your rights
As a data subject, you have the right to:
- check what data has been stored about you
- have inaccurate data rectified or incomplete data completed
- request the erasure of your data (the “right to be forgotten”)
- request the restriction of processing
- object to processing based on legitimate interest, and opt out of direct marketing at any time
- receive the data you have provided in a machine-readable format and transmit it to another controller, where the processing is based on consent or a contract
- withdraw your consent, for example in the cookie settings. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Send your request in writing, for example by email to tapio@kansleri.fi. Where necessary, the controller may ask the person making the request to prove their identity. Requests are answered within the time limit set by the GDPR, as a rule within one month.
If you consider that the processing of your personal data infringes the GDPR, you can lodge a complaint with the supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).
Your data is not used for automated decision-making or for profiling that would have legal or similarly significant effects on you.