Legal document
Privacy Policy
How Classic Garage Oy processes personal data collected through this website, under Regulation (EU) 2016/679 (GDPR) and the Finnish Data Protection Act 1050/2018.
Last updated 2026-09-13
1. Controller
The controller is Classic Garage Oy, Osakeyhtiö (limited liability company), Business ID 0113488-7, EU VAT FI01134887, registered address Niittyläntie 6, 00620 Helsinki, Finland. Contact: contact@classicgarageoy.com.
Classic Garage Oy has not appointed a Data Protection Officer: it is not a public authority, its core activity is not large-scale monitoring, and it does not process special categories of data at scale, so Article 37 does not require one. Data-protection questions go to the address above.
This policy covers the website www.classicgarageoy.com. Personal data processed inside a client engagement — the payroll and accounting records of a client company — is governed by the engagement letter and the data processing agreement with that client, where Classic Garage Oy generally acts as a processor.
2. What this website collects
2.1 The proposal request form
Company name, contact person, business email, the number of invoices and receipts per month, the number of employees on payroll, the service needed, and an optional phone number and message. The server adds a model estimate of monthly workload, computed from those figures.
2.2 The contact form
Your name, email and message, and optionally your company and phone number.
2.3 Recorded with each submission
The time, the page the form was sent from, the version of the privacy notice shown, whether you confirmed that you read it, whether you ticked the optional marketing box, the legal basis relied on, your browser's user-agent string, and a salted SHA-256 hash of your IP address. The IP address itself is never stored with a submission. The hash, the time the form spent open and an empty decoy field exist only to stop automated abuse.
2.4 The simulation engine
Everything you enter into the Accounting & Tax Simulation Engine is calculated in your browser and is not sent to us. Only if you press the button that copies figures into the proposal form, and then submit that form, do those two figures reach us.
2.5 Server logs
The web server records the time, URL, status, referrer and user-agent of each request in an access log, kept for a short period for security and troubleshooting.
2.6 Cookies and local storage
No optional cookie is set before you choose. One browser storage key records the choice itself. The full list is in the Cookie Policy.
3. Purposes and legal bases
Preparing a proposal and answering your request — Article 6(1)(b) GDPR, steps taken at your request before entering into a contract, and Article 6(1)(f), our legitimate interest in replying to a business enquiry.
Keeping the site secure and the forms free of abuse — Article 6(1)(f).
Legal obligations where an engagement follows — Article 6(1)(c), with the Finnish Accounting Act (1336/1997) and the Anti-Money Laundering Act (444/2017).
Measurement and advertising cookies, if you accept them — Article 6(1)(a), consent, withdrawable at any time.
Occasional emails about accounting and tax deadlines, if you tick the optional box — Article 6(1)(a), consent. The box is unticked by default and is not needed for your request.
About the "I have read the privacy notice" box. The forms ask you to confirm that you have read the notice printed beside them, and we record that confirmation. It documents that you were informed under Article 13; it is not consent to processing, and your request is not processed on the basis of consent.
4. Retention
- Requests that do not lead to an engagement — 24 months from your last contact, then deleted. You may ask for erasure sooner.
- Requests that lead to an engagement — kept with the client file; accounting records for the period the Finnish Accounting Act requires.
- Rate-limit records — deleted after 24 hours.
- Web server access logs — rotated and deleted within 30 days.
- Your cookie choice — in your own browser until you clear it or this policy version changes.
5. Recipients
Classic Garage Oy does not sell personal data and does not share it with data brokers or advertisers. Data is disclosed only to:
- Namecheap, Inc. (Los Angeles, California, United States) — the hosting provider of the server this website runs on, acting as our processor.
- Our email provider, when a request is forwarded to our mailbox and when we reply.
- Microsoft Advertising, only if you accept advertising cookies — see the Cookie Policy.
- Authorities, where the law obliges us, including under the Anti-Money Laundering Act.
6. Transfers outside the EEA
The server that runs this website is located in Los Angeles, California, United States, which is outside the European Economic Area. The provider is Namecheap, Inc., a United States company, so personal data submitted through this website is transferred to a third country.
The transfer is made under European Commission Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor), together with supplementary technical measures: TLS 1.2+ in transit and encryption at rest. We state this plainly rather than advertising EU hosting we do not have; if the hosting changes, this section changes with it.
7. Your rights
- access to your data and a copy of it (Articles 15 and 20);
- rectification of inaccurate data (Article 16);
- erasure (Article 17), subject to records the law requires us to keep;
- restriction while a question is resolved (Article 18);
- objection to processing based on legitimate interests (Article 21);
- withdrawal of any consent at any time, without affecting earlier lawful processing (Article 7(3)).
Write to contact@classicgarageoy.com. We answer within one month. Quoting the reference your form returned lets us find and erase a request without asking for anything further.
8. Complaints
Tell us first if you can; it is usually the fastest fix. You also have the right to complain to the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PO Box 800, 00531 Helsinki, Finland, or to the supervisory authority where you live or work.
9. Automated decisions
None. The model estimate attached to a proposal request is a planning figure for our staff, not a decision about you, and the rate limit is a volume control on a form.
10. Children
This is a business-to-business website and is not directed at children.
11. Security
The site is served over HTTPS with HSTS. The database is not reachable from the internet, IP addresses are hashed with a secret salt before storage, and server access is by key-based authentication. If a breach is likely to result in a high risk to your rights, we will tell you as Article 34 requires.
12. Changes
The date at the top of this page is the version. A change that materially affects data you have already given us will be announced on the site, not made quietly.