Privacy Policy
How Vestit Solutions Oy handles personal data on our website and in the Vestit service.
1. Introduction and scope
This Privacy Policy explains how Vestit Solutions Oy (“Vestit”, “we”, “us”) collects and uses personal data when you visit our website, contact us, join our waitlist, or use our equity and cap-table management platform (the “Service”) as a representative of a customer.
When a customer uses the Service to manage its cap table, it uploads personal data about its own shareholders, option holders, employees and advisers. For that data Vestit acts as a processor on behalf of the customer, which is the controller. That processing is governed by our agreement and Data Processing Agreement with the customer, and individuals should contact the relevant customer to exercise their rights over it.
This Privacy Policy covers only the personal data for which Vestit itself is the controller: data about website visitors, prospects, waitlist subscribers, and the people who register and sign in to accounts.
2. Who we are
The controller of the personal data described in this Policy is Vestit Solutions Oy, business ID 3634150-1, registered office in Espoo, Finland. You can contact us about privacy matters at dataprivacy@vestit.fi.
We are not required to appoint a Data Protection Officer and have not appointed one; privacy enquiries are handled at the address above.
3. Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Account and sign-in data: your verified email address, your language and number and date format preferences, and the credential used to sign in. Passwords are never stored in readable form, only as a salted hash.
- Session and technical data: IP address, browser and device information from the user-agent string, when a session was created and last used, and application and server log data.
- Communications: messages, support requests and correspondence you send us.
- Waitlist and marketing data: the email address you submit to our waitlist and whether you indicated interest in early access, plus contact details and preferences of business prospects.
- Billing data: billing contact, company details and the information needed to process payments and issue invoices.
Where you appear in a customer’s cap table, that customer may also hold your name, address and tax or national identity number in the Service. We process that data only as a processor on the customer’s instructions; addresses and tax identifiers are encrypted at rest under a key held per customer. We do not collect special categories of personal data for the accounts we control.
4. How we collect personal data
- Directly from you, when you contact us, join our waitlist, register, or use the Service.
- Automatically, through strictly necessary cookies and server logs when you use our website or the Service.
- From third parties, such as our customers (who may provide your contact details as an authorised user) and our service providers.
5. Why we use personal data, and our legal bases
We process personal data for the purposes and on the legal bases set out below. All references are to the EU General Data Protection Regulation (GDPR).
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing, administering and supporting the Service and accounts | Account and sign-in, session, communications | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Billing and collecting payment | Contact and billing data | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Securing the Service and preventing misuse or fraud | Session, technical and log data | Legitimate interests (Art. 6(1)(f)) |
| Improving and developing our products | Usage data, aggregated where possible | Legitimate interests (Art. 6(1)(f)) |
| Operating the waitlist and telling you when the Service opens | Waitlist data | Consent (Art. 6(1)(a)) |
| Marketing to business contacts | Contact and marketing data | Legitimate interests, or consent where required (Art. 6(1)(a)/(f)) |
| Complying with accounting, tax and other legal duties | Billing and contact data | Legal obligation (Art. 6(1)(c)) |
6. Cookies and similar technologies
We use only strictly necessary cookies on our website and in the Service: to keep you signed in, to complete the login flow, and to remember the interface language and display preferences you chose. We do not use analytics, advertising or third-party tracking cookies, and we therefore do not show a cookie consent banner.
7. Who we share personal data with
We share personal data only as necessary, with:
- Service providers and sub-processors: they help us run the Service under contracts that protect the data.
- Professional advisers: auditors, accountants and lawyers, where needed.
- Authorities: where we are legally required to disclose data.
- Acquirers: in connection with a merger, acquisition or sale of assets, subject to confidentiality.
Our current sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Hetzner Online GmbH | Application and database hosting, document storage, encrypted backups | Helsinki, Finland (EU) |
| Stripe Payments Europe, Ltd. | Payment processing and invoicing | Ireland (EU), with support access from the United States |
| Resend, Inc. | Delivery of transactional email (sign-in, invitations, notifications) | United States |
Electronic signing of documents happens inside the Service itself; no third-party signing provider is involved. We do not use an analytics provider, and we do not sell personal data.
8. International transfers
We aim to keep personal data within the European Economic Area (EEA): our hosting, database, document storage and backups are all located in Finland. Two providers involve processing outside the EEA — our transactional email provider is established in the United States, and our payment provider may allow support access from the United States. Those transfers are made under the European Commission’s Standard Contractual Clauses together with the additional measures required, and we limit the personal data exposed to them to what the service needs. You can request more information using the contact details above.
9. How long we keep personal data
We keep personal data only as long as necessary for the purposes described above, then delete or anonymise it.
- Account and contact data: for the duration of the customer relationship, and a reasonable period afterwards to handle queries and disputes.
- Sessions: deleted when they expire or you sign out; a session lasts at most 30 days.
- Accounting and invoicing records: for the retention period required by the Finnish Accounting Act, currently six years from the end of the accounting year.
- Waitlist data: until the Service opens to you, or until you ask us to remove you, whichever comes first.
- Backups: encrypted database backups are retained on a rolling schedule; data deleted from the live Service disappears from backups as that cycle completes.
10. Security
We maintain appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss or misuse, including:
- encryption of all traffic in transit (HTTPS/TLS);
- envelope encryption at rest for the most sensitive fields, such as residential addresses and tax identifiers, and for stored documents;
- encrypted, integrity-verified database backups held in a separate, write-protected location;
- role- and company-scoped access control, so each user sees only the company data they are entitled to; and
- audit logging of security- and equity-relevant actions, and regular review of access.
No system is completely secure, but we work to protect your data and to respond promptly to any incident. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you.
11. Your rights
Subject to the conditions in applicable law, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected, and incomplete data completed;
- have your data erased in certain circumstances;
- restrict or object to certain processing, including direct marketing;
- receive certain data in a portable format; and
- withdraw any consent at any time, without affecting earlier processing.
To exercise your rights, contact us using the details in section 2. If your data is held in a customer’s cap table, we will direct your request to that customer, who is the controller for it.
You also have the right to lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) — or with the data protection authority in your own country, for example Datatilsynet in Norway and Denmark, IMY in Sweden, or Persónuvernd in Iceland.
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not profile you.
13. Children
The Service is a business product and is not directed at children. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this Policy from time to time. We will post the updated version here and change the date shown above. Where changes are significant, we will take reasonable steps to notify you.
15. Contact us
If you have questions about this Policy or how we handle your personal data, contact us at dataprivacy@vestit.fi.