Privacy Policy
How Vantica Oy collects, uses and protects personal data, and what you can ask us to do with it.
Who is responsible
The controller for the personal data described here is:
Vantica Oy
Business ID 3565211-3 · VAT FI35652113
Kampinkuja 2, 00100 Helsinki, Finland
business@vantica.fi
+358 50 511 8845
We have not appointed a data protection officer, as we are not required to. Data protection questions go to the address above.
What this covers
This policy covers personal data we process through this website and through contact with us — enquiries, job applications, and the technical records our hosting creates. It also covers analytics, if and when we enable it.
Booking a call sends you to Google's appointment scheduling service. What happens there is governed by Google's own terms and privacy policy, not this one; we receive the booking details.
What we collect
If you contact us. Your name, email address, phone number, company, and whatever you choose to put in the message.
If you apply for a role. Your name and contact details, your CV and any attachments, work history, and anything else you include. We do not ask for special categories of data and would rather you did not send any.
Automatically, when you visit. This site is served by GitHub Pages, which records standard server logs including IP addresses to keep the service secure and available. We never see those logs — we cannot read them, export them or change how long GitHub keeps them. GitHub processes them for its own security purposes, described in the GitHub Privacy Statement.
Analytics. Only if you accept it — Google Analytics then records which sections of the page you scroll to, which buttons you click, roughly where you are, and what kind of device and browser you used. It is not tied to your name and we make no attempt to identify individuals from it. See Cookies below.
Why, and on what basis
To answer your enquiry and to discuss working together — legitimate interest, and where a contract is in prospect, steps taken at your request before entering one (GDPR Art. 6(1)(b) and 6(1)(f)).
To assess your application — steps taken at your request before entering a contract (Art. 6(1)(b)).
To consider you for roles as they come up — an open application is a request to be considered for future work, so this is a step taken at your request (Art. 6(1)(b)). If you applied for one specific role and we would like to keep your details for others, we ask you first and rely on your consent (Art. 6(1)(a)).
To keep the site available and secure — legitimate interest (Art. 6(1)(f)).
To measure how the site is used — your consent (Art. 6(1)(a)), and consent under §205 of the Finnish Act on Electronic Communications Services.
How long we keep it
Enquiries — 24 months after our last contact, unless we start working together, in which case the business relationship sets the period.
Applications — 24 months, then deleted. Two reasons for that length: an open application asks us to keep you in mind for work that has not come up yet, and a discrimination claim under the Finnish Non-Discrimination Act can be brought within two years, so we need to be able to show how a decision was made. If we would like to keep your details past 24 months, we will ask you first.
Server logs — held by GitHub, not by us; see the GitHub Privacy Statement linked above.
Analytics — 14 months, the shortest retention Google Analytics allows, and only if you have accepted it.
Who else sees it
We do not sell personal data and we do not share it for anyone else's marketing. We use these service providers, each under a data processing agreement:
- GitHub (GitHub, Inc., a Microsoft company) — hosts this site on GitHub Pages and records the server logs described above
- Google (Google Ireland Limited) — Google Workspace hosts our email, so every enquiry and every application you send us is stored there; Google also provides the appointment scheduling behind "Book a Call", and Google Analytics, but only once you have accepted it
We may also disclose data where the law requires it.
Transfers outside the EEA
Both of our providers are US-headquartered and may process data outside the EEA. GitHub serves this site from a global network, and Google may process email and analytics data in the United States.
Those transfers rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework, under which both Google and Microsoft are certified, and on Standard Contractual Clauses where the framework does not apply.
Cookies
Until you accept analytics, this site sets no cookies and makes no third-party requests at all. Everything the page needs, including the fonts, is served from this domain, so opening it tells nobody but our host that you were here. Most sites load fonts, icons or scripts from elsewhere, which sends your IP address to those companies before you have clicked anything. This one does not.
If you accept, we load Google Analytics and it sets two cookies:
- _ga — 2 years — tells one browser apart from another so a return visit is not counted as a new person
- _ga_M5FV2K9X16 — 2 years — keeps track of the current visit
We use it only to see how people move through the page — which sections they reach and which buttons they click — and roughly where they come from. We have switched off advertising features, cross-device tracking and data sharing with Google beyond what the service needs to run, and Google Analytics 4 does not store IP addresses — it uses them to work out an approximate location and then discards them.
Refusing is exactly as easy as accepting and changes nothing about how the site works. Whichever you choose, we record that choice on your device so we do not have to ask again; that record is strictly necessary and needs no consent of its own.
You can change your mind at any time from Cookie settings in the footer. Refusing after having accepted stops the tracking and deletes the two cookies above.
Your rights
Under the GDPR you can ask us to:
- tell you what data we hold about you, and give you a copy
- correct anything that is wrong or incomplete
- delete it, where we have no reason to keep it
- restrict what we do with it while a question is resolved
- send it to you or another controller in a machine-readable form
- stop processing it where we rely on legitimate interest
Where we rely on your consent you can withdraw it at any time. That does not affect anything we did before you withdrew it.
Email it@vantica.fi and we will respond within one month. If we cannot identify you from the request we may need to ask for more information.
We make no automated decisions about you. Every application is read by a person, and nothing on this site profiles or scores you.
If you think we have handled your data badly, tell us first — but you are entitled to complain directly to the Finnish Data Protection Ombudsman (tietosuoja.fi).
Security
The site is served over HTTPS and has no database, no forms and no login — there is nothing on it to breach. Your enquiry or application lives in our Google Workspace email, where access is limited to the people who need it, on accounts protected by multi-factor authentication.
No system is perfectly secure, but we do not keep personal data we have no use for, which is the most effective protection available.
Changes
If we change how we handle personal data we will update this page and the date below. If the change is significant, and we hold your contact details, we will tell you directly.