Privacy

Privacy notice — contacting companies and buying reports

This notice covers the Luotain programme: analysing websites, contacting companies about the results, and buying reports. Version 1.1, updated 5 September 2026. English translation for convenience; the Finnish tietosuojaseloste prevails.

Want off the list right now?

Reply to any of our messages with the word "poista" (or "remove") or email tietosuoja@aamucompliance.fi. We delete your details permanently and will not contact you again. This is free and needs no justification.

Controller

Aamu Advisory Oy (Business ID 3435542-4), service name Aamu Compliance
Email: tietosuoja@aamucompliance.fi

Why did you hear from us?

We analyse the public websites of Finnish companies for accessibility (the European Accessibility Act), technical baseline, search visibility and cookie practices, and offer reports on the findings as well as remediation services. We contact people in a professional role whose duties the matter substantially relates to.

What data we process and where it comes from

Data processed and its sources
DataSource
Name, job title, work email addressYour company's public website
Company name, business ID, industry, web addressYTJ / PRH open data (avoindata.prh.fi) and the trade register
Technical findings about the website (e.g. accessibility gaps, headers, cookies)Your site's public pages, fetched like an ordinary browser
Contact history (messages sent, replies, marketing opt-outs)Our own system

We do not process special categories of personal data or your private contact details.

Purpose and legal basis

  • B2B direct marketing and customer acquisition — legitimate interest of the controller (GDPR Art. 6(1)(f)). A balancing test has been drawn up and is available on request.
  • Maintaining marketing opt-outs — legal obligation and legitimate interest: honouring your objection requires recording it.

Electronic direct marketing to organisations is based on section 202 of the Finnish Act on Electronic Communications Services (917/2014); we message named individuals only where the matter substantially relates to their duties (section 200).

How long we keep data

DataRetention
Contact details, if you do not reply12 months from the last contact, then deleted
Website scan results12 months
Marketing opt-outsPermanently — this is how we make sure we never contact you again
Contacts that became customersAccording to customer-relationship practice (separate notice)

Recipients and transfers

We use service providers (processors) in the EU/EEA for sending email and storing data. Where a provider transfers data outside the EU/EEA, the transfer rests on a European Commission adequacy decision (for example the EU–US Data Privacy Framework) or standard contractual clauses. We do not sell or disclose your data to third parties for marketing.

Your rights

  • The right to object to direct marketing at any time (GDPR Art. 21(2)) — this right is absolute. Easiest: reply "poista" to any of our messages.
  • The right of access (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction of processing (Art. 18).
  • The right to lodge a complaint with the supervisory authority: the Office of the Data Protection Ombudsman, tietosuoja.fi.

Contact: tietosuoja@aamucompliance.fi. We reply within one month at the latest.

Buying reports and personal links

When we send a company a message, it may contain a personal link (address of the form aamucompliance.fi/r/…) through which the reports made for the company's site can be bought. The link is tied to the company and the site, not to a person: the page contains neither your name nor your email address, and opening it is not tracked at the individual level. The site sets no cookies.

When you buy a report, payment is processed by Stripe Payments Europe Ltd (Ireland) as an independent controller for payment data and as our processor for receipts and invoices. From Stripe we receive the email address you give at payment, the company name and any business ID or VAT number, the products bought and the payment identifier. We use these to perform the contract (GDPR Art. 6(1)(b)) and keep them for the period required by the Finnish Accounting Act (6 years from the end of the financial year). Reports and order records are stored with Cloudflare, Inc. (EU region) as our processor.

Cookies on this site

This site sets no cookies and uses no analytics or tracking services. A company that sells accessibility and privacy should not track its visitors.

Website analysis (the Luotain bot)

We analyse only publicly available pages using the same methods as an ordinary browser. The bot identifies itself with the user-agent LuotainAudit; its behaviour and the opt-out instructions are on the Luotain bot page.