Privacy Policy
Privacy Policy
Regulyn Oy (Regulyn Ltd) | Business ID 3572857-9 Version 1.0 | Effective 01.07.2026
Who we are
Regulyn Oy, Finland, is the controller for the processing described in this policy. Privacy matters may be addressed to [contact@regulyn.com].
When we process personal data on behalf of a client during an engagement, we act as a processor and the client's data processing agreement applies instead of this policy.
Whose and what data we process
We process personal data relating to clients, prospects, partner organizations, website visitors and event participants.
Typical categories of data we process include:
- Client data - client's contact details, email exchange
- Billing data - billing information, invoices, receivables
- Prospecting data - name, email address, company name, industry
- Marketing data: name, email, newsletter subscription, events attended
- Website data: IP-address, sites visited, cookie preferences
Purposes and basis of data processing
We process personal data for the following purposes:
- client relationship management
- service delivery
- billing and accounting
- prospecting and website analytics
The legal basis we rely on include performance under agreement, legitimate interest, consent and fulfilling regulatory obligations.
Retention
Our personal data retention policies vary based on the personal data category and processing purposes. A summary of the typical retention periods can be found below:
- Client data - 2 years from latest engagement
- Billing data - 6-10 years, in accordance with accounting regulations
- Prospecting data - maximum of 1 year from latest engagement, deleted immediately upon objection
- Marketing data: up to 2 years from latest engagement
- Website data: up to 12 months for analytics, security logs for up to 2 years
Where the data comes from
We obtain personal data directly from you, from the organisation you represent, from public sources such as company websites, public registers, professional networking platforms and trade press, and from business data providers.
Who receives the data
We do not sell personal data and we do not disclose it for the marketing purposes of third parties.
We use processors under written agreements satisfying Article 28 of the GDPR for website management, communication, cloud storage, electronic signatures and information security support.
We may disclose data to independent controllers, such as the Tax administration subject to legal obligation.
Transfers outside the European Economic Area
We keep personal data within the European Economic Area wherever that is practicable.
Where a service provider processes data elsewhere, the transfer relies on a European Commission adequacy decision, including certification under the EU–US Data Privacy Framework, or on standard contractual clauses supported by a documented transfer impact assessment.
Details for a specific provider are available on request.
We do not carry out automated decision making within the meaning of Article 22 of the GDPR.
How we protect the data
We apply various organizational and technical measures, including binding written data processing agreements, role-based access control, internal policies and processes and encryption.
Your rights
You have the right to obtain access to your personal data and a copy of it, and to have inaccurate data rectified.
Subject to the conditions in the GDPR you may also request erasure, restriction of processing, and the transmission of your data to another controller.
You may object, on grounds relating to your particular situation, to processing based on our legitimate interests.
You may object to direct marketing at any time and without giving reasons, and we will stop immediately.
Where processing is based on consent you may withdraw it at any time, which does not affect the lawfulness of processing carried out beforehand.
Requests may be sent to [contact@regulyn.com]. We respond within one month of receipt. Where a request is complex we may extend that period by two further months, and we will tell you within the first month if we do. We may ask for further information in order to confirm your identity.
Complaints
If you consider that we have infringed the GDPR you may lodge a complaint with a supervisory authority.
In Finland this is the Office of the Data Protection Ombudsman, PO Box 800, FI-00531 Helsinki, tietosuoja@om.fi, telephone +358 29 566 6700. We ask that you contact us first so that we may resolve the matter directly.
Changes to this policy
We review this policy regularly and whenever our processing changes materially. The current version is published at www.regulyn.com/privacy.
We will inform you before a material change takes effect.
