How Countex Oy processes personal data collected through this website, under Regulation (EU) 2016/679 (GDPR) and the Finnish Data Protection Act 1050/2018.
Last updated 2026-09-05
1. Who is the controller
The controller is Countex Oy, Osakeyhtio (limited liability company), Business ID 0149516-4, EU VAT FI01495164, registered office at c/o Miettinen, Pohjoisranta 2 E 13, 00170 Helsinki, Finland. Contact: info@countexoy.com.
Countex Oy has not appointed a Data Protection Officer. It is not a public authority, its core activity is not large-scale monitoring, and it does not process special categories of data at scale, so Article 37 does not require one. Enquiries about data protection go to the address above and are answered by the company.
This policy covers the website at countexoy.com. Personal data processed inside a client engagement — the payroll and accounting records of a client company — is governed by the engagement letter and the data processing agreement made with that client, where Countex Oy generally acts as a processor rather than a controller.
2. What this website collects
2.1 Data you type into a form
The enquiry forms collect: your name, your email address, and your message. Optionally, your company name, your telephone number and the service your enquiry concerns. Nothing else is required, and there is no hidden field that collects anything about you beyond what is described in section 2.3.
Please do not send confidential financial figures, personal data about third parties, or identity documents through this form. Those are exchanged after an engagement letter, over a channel agreed with you.
2.2 Data your browser sends
Our web server records the usual request data in its access log: the time, the URL requested, the HTTP status, the referring page and the user-agent string. IP addresses are not stored in readable form alongside a submission: an enquiry record keeps only a salted SHA-256 hash of the address, which lets us enforce a rate limit and investigate abuse without holding the address itself.
2.3 Anti-abuse signals attached to a submission
Each submission carries: the salted IP hash described above, the time the form spent open before it was sent, and an empty decoy field that only automated software fills in. These exist to stop automated abuse of the form. They are not used to profile you, and they are deleted with the enquiry.
2.4 Cookies and local storage
This site sets no cookie before you make a choice. A single browser storage key records the choice itself. Everything that can be set, and what each item does, is listed in the Cookie Policy.
3. Why we process it, and on what legal basis
To answer your enquiry and take steps toward a possible engagement — Article 6(1)(b) GDPR, steps taken at your request prior to entering into a contract, and Article 6(1)(f), our legitimate interest in replying to a business enquiry addressed to us.
To keep the website working and to prevent abuse of the forms — Article 6(1)(f), our legitimate interest in the security and availability of our own service.
To comply with obligations imposed on us — Article 6(1)(c), together with the Finnish Accounting Act (1336/1997) and the Anti-Money Laundering Act (444/2017) where an engagement follows.
Measurement and advertising cookies, if you switch them on — Article 6(1)(a), your consent, which you may withdraw at any time.
Occasional emails about accounting and tax deadlines, if you tick the optional box — Article 6(1)(a), your consent. That box is unticked, it is genuinely optional, and nothing about sending the form depends on it.
We do not require your consent in order to answer you. There is no consent tick-box gating the enquiry form. Consent obtained as the price of sending a message would not be freely given under Article 7(4), and it is not the basis we rely on.
4. How long we keep it
- Enquiries that do not lead to an engagement — 24 months from your last contact, then deleted. You can ask for erasure sooner.
- Enquiries that lead to an engagement — retained with the client file, and accounting records are kept for the period the Finnish Accounting Act requires (generally six or ten years depending on the record).
- Web server access logs — rotated and deleted within 30 days.
- Your cookie choice — 12 months in your own browser, or until you clear it.
5. Who else sees it
Countex Oy does not sell personal data, does not share it with data brokers, and does not disclose it to advertisers. Data is disclosed only to:
- Namecheap, Inc. (Los Angeles, California, United States) — the hosting provider that operates the server this website runs on. It has access to the server as a matter of technical necessity and acts as our processor.
- The email provider that carries our mail, where an enquiry is forwarded to our mailbox, and where we then reply to you.
- Microsoft Advertising, but only if you switch on advertising cookies. See the Cookie Policy.
- An authority, where a law obliges us to disclose, including the reporting obligations the Anti-Money Laundering Act places on accounting firms.
6. Transfers outside the EEA
The server that runs this website is located in Los Angeles, California, United States, which is outside the European Economic Area. The provider is Namecheap, Inc., a United States company. Personal data you submit through this website is therefore transferred to a third country.
That transfer is made under European Commission Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor), together with supplementary technical measures: TLS 1.2+ in transit and encryption at rest. We state this plainly rather than advertising EU hosting we do not have. If the hosting arrangement changes, this section changes with it.
7. Your rights
Under the GDPR you may ask us to:
- tell you what we hold about you and give you a copy (Articles 15 and 20);
- correct anything inaccurate (Article 16);
- erase it (Article 17), subject to records we are required by law to keep;
- restrict how we use it while a question is resolved (Article 18);
- stop processing based on legitimate interests, by objecting under Article 21 — for an enquiry, we will stop unless we have compelling grounds that override your objection;
- withdraw a consent you gave, at any time, without affecting what was lawful before you withdrew it (Article 7(3)).
Write to info@countexoy.com. We answer within one month. If you quote the reference the form gave you, we can find and erase an enquiry without asking you for anything further.
8. Complaints
If you think we have handled your data wrongly, tell us first — it is usually the fastest fix. You also have the right to complain to a supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PO Box 800, 00531 Helsinki, Finland. You may also complain to the authority in the EU state where you live or work.
9. Automated decisions and profiling
There are none. Nothing on this website makes a decision about you automatically, and no profile is built from your visit. The rate limit described in section 2.3 is a volume control on a form, not a decision about a person.
10. Children
This is a business-to-business website and it is not directed at children. We do not knowingly collect data from anyone under 16.
11. Security
The site is served over HTTPS with HSTS. Submissions are stored in a database that is not reachable from the public internet, IP addresses are hashed with a secret salt before storage, and access to the server is by key-based authentication only. No system is perfect; if we ever suffer a breach that is likely to result in a high risk to your rights, we will tell you as Article 34 requires.
12. Changes
The date at the top of this page is the version. Where a change materially affects how we use data you have already given us, we will say so on the site rather than change the text quietly.