Privacy Policy
Privacy Policy
Last Updated: 13 July 2026
Elandz Oy Ab (“Elandz”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why and how we process it, who we share it with, and the rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (1050/2018).
This policy covers all of our activities:
- our website elandz.com and the marketing, forms, chat, and scheduling tools on it;
- our consulting and operations services: revenue operations (RevOps) and HubSpot consulting, intelligent automation and AI agent deployment, and web operations;
- our content marketing platform (the “Platform”): software our customers use to plan, create, and publish content;
- our sales and marketing activities, including newsletters and business outreach.
1. Data controller
Elandz Oy Ab (also trading as Elandz Ltd)
Business ID: 2581308-3
Vesurikatu 7
20780 Kaarina
Finland
Email: privacy@elandz.com
2. Controller or processor: which one we are
For most data described in this policy, website visitors, leads, newsletter subscribers, Platform user accounts, customer contacts, and billing, Elandz is the data controller.
In two situations we act as a data processor on behalf of our customers, who remain the controllers of that data:
- Consulting engagements: when we work inside a client’s systems (for example their HubSpot portal, CRM, website, analytics, or automation tools), we may have access to personal data of the client’s own customers and leads. We process that data only on the client’s documented instructions, under a data processing agreement (DPA), and only to deliver the agreed work.
- The Platform: content, documents, brand material, and any personal data our customers place in their Platform workspace is processed on their behalf to provide the service.
If you are a customer or lead of one of our clients and want to exercise your data rights, please contact that company directly; we will assist them in responding.
3. What data we collect and why
3.1 Website visitors (elandz.com)
- Contact and enquiry forms: name, email address, company, phone number, and your message. Used to respond to you and follow up on your enquiry. Legal basis: pre-contractual steps / legitimate interest.
- Meeting booking: when you book a call through our scheduling page, our scheduling provider (HubSpot Meetings) collects your name, email address, and the time you choose. Legal basis: pre-contractual steps.
- Chat: if you use the chat widget (Crisp), we receive the messages you send, your email if you provide it, and technical metadata (pages viewed, browser, approximate location derived from IP). Legal basis: legitimate interest in answering visitor questions.
- Newsletter: email address, used only to send the updates you subscribed to. Legal basis: consent; every message contains an unsubscribe link.
- Analytics and behaviour data: see section 7 (Cookies and tracking) for the full list of tools, including Google Analytics and Microsoft Clarity session analytics. Legal basis: consent for non-essential cookies.
- Free tools: utilities we publish, such as the UTM builder, run in your browser; we do not store what you type into them.
3.2 Customers and prospects (CRM)
- Business contact data: name, role, work email, phone, company, and our correspondence and meeting notes, held in our CRM (HubSpot). Used for sales, account management, proposals, and contract delivery. Legal basis: performance of a contract / legitimate interest in managing business relationships.
- B2B outreach: we may contact people in relevant professional roles about our services using publicly available or licensed business contact information. Legal basis: legitimate interest in direct B2B marketing under Finnish law; you can object at any time and we will stop.
- Billing data: invoicing details and payment records. Legal basis: performance of a contract and statutory bookkeeping obligations.
3.3 Platform users
- Account data: name, work email address, role, and password (stored only as a salted hash; we cannot read it). If you sign in with Google, we receive your name, email address, and profile picture from Google. Legal basis: performance of a contract.
- Workspace content: brand guidelines, audience and positioning descriptions, documents you upload, keywords, and the content you create, edit, approve, and publish. Processed to provide the service (see section 2; for this data we act as processor for the customer).
- Activity and security logs: sign-in events, actions taken in the Platform, IP address, and device information, kept for security auditing, abuse prevention, and support. Legal basis: legitimate interest in securing the service.
3.4 Connected third-party services (Platform integrations)
The Platform lets customers connect their own accounts on external services. We only gain access after you explicitly authorize each connection, we request the minimum permissions the feature needs, and you can revoke access at any time from the Platform settings or from the third-party service itself. All access tokens and credentials are encrypted at rest.
- Google Search Console and Google Analytics: search performance and website analytics data for your own website, used to inform content recommendations and reporting. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising and we never sell it.
- WordPress and Webflow: publishing credentials you provide so the Platform can deliver finished content to your website.
- LinkedIn: if you connect a LinkedIn company page, we store the OAuth tokens needed to create posts as that page. We access only posting and page-administration information; we do not read private messages, connections, or follower lists. Posts are published only after a person in your workspace approves them.
- X (Twitter): if you connect an X account, we store the credentials needed to publish posts to it, with the same human-approval rule.
- Slack, n8n, and other workflow tools: where an engagement or Platform feature involves notifications or automations, we process the identifiers and message content needed to run the workflow you configured.
3.5 AI processing
The Platform and some of our automation services use third-party large-language-model providers, including Anthropic and OpenAI, to generate and analyse content. Content and business context you provide may be sent to these providers to deliver the service. We use their business API offerings, whose terms prohibit training their models on our customers’ data. AI output in the Platform is reviewed and approved by humans before it is published anywhere. We do not sell personal data to AI providers.
4. Automated decision-making and profiling
We do not make automated decisions that produce legal or similarly significant effects on individuals. AI in our services generates draft content and recommendations; publication and business decisions are made by people.
5. Who we share data with
We never sell personal data. We share it only with service providers under data processing agreements, and only to the extent needed to run our business:
- Hosting and infrastructure: Hetzner Online GmbH (Germany, EU), where our Platform and databases run.
- CRM, marketing and scheduling: HubSpot (forms, CRM, email, meeting booking).
- Chat: Crisp (website chat widget).
- Analytics: Google (Tag Manager, Analytics) and Microsoft (Clarity session analytics); see section 7.
- Email delivery: Brevo (transactional and marketing email, EU).
- AI providers: Anthropic and OpenAI (US), as described in section 3.5.
- Google Workspace / Drive: internal document storage and the Google services customers choose to connect.
- Research and SEO data providers: services such as DataForSEO and Apify process the search queries and public web pages we request; they do not receive your account data.
- Social and publishing platforms: LinkedIn, X, WordPress, Webflow, when you connect them and approve an action.
- Professional advisers and authorities: accountants, lawyers, and public authorities where disclosure is required by law.
6. International transfers
Our primary infrastructure is in the European Union. Some providers (for example Anthropic, OpenAI, Microsoft, Google, HubSpot) process data in or from the United States. Where personal data leaves the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.
7. Cookies and tracking
elandz.com uses the following categories of cookies and similar technologies:
- Necessary: session, security, and consent-preference cookies required for the site and Platform sign-in to work. These do not require consent.
- Analytics: Google Analytics (via Google Tag Manager) for aggregate visitor statistics, and Microsoft Clarity, which records anonymised interaction data such as clicks, scrolling, and session replays to help us improve the site. Clarity masks typed input by default.
- Functional / marketing: HubSpot cookies that connect your visits to your CRM record once you submit a form or book a meeting, and Crisp chat cookies that keep your conversation history.
Non-essential cookies are set only with your consent where required. You can withdraw consent at any time through the cookie settings on this site or by clearing cookies in your browser. You can also opt out of Google Analytics with the Google Analytics opt-out add-on.
8. How long we keep data
- Enquiries and chat conversations: up to 24 months after our last exchange.
- CRM records of customers and prospects: for the duration of the business relationship; prospect records are reviewed and purged when no longer relevant.
- Newsletter subscriptions: until you unsubscribe.
- Platform account and workspace data: for the duration of the customer agreement and up to 12 months after termination, unless the customer requests earlier deletion or a longer export window.
- Third-party access tokens: until you disconnect the integration or the agreement ends; deleted on disconnection.
- Security and access logs: up to 12 months.
- Bookkeeping material: as required by the Finnish Accounting Act (generally 6 to 10 years).
9. How we protect data
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption at rest for credentials and integration tokens, salted password hashing, role-based access control, tenant-level data isolation on the Platform (each customer’s workspace data is segregated and every data access is scoped to that customer), access logging, and the principle of least privilege for both personnel and system components. No method of transmission or storage is completely secure; if a personal data breach occurs that risks your rights, we will notify the supervisory authority and affected persons as the GDPR requires.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”) where there is no overriding legal ground to keep it;
- restrict processing in the situations set out in Article 18;
- object to processing based on legitimate interest, including direct marketing, where objection is absolute;
- data portability: receive data you provided in a structured, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out.
To exercise any of these rights, email privacy@elandz.com. We may need to verify your identity, and we respond within one month. If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the Finnish Office of the Data Protection Ombudsman (tietosuoja.fi) or the supervisory authority of your EU member state.
11. Children
Our website and services are intended for business use and are not directed at children under 16. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We update this policy when our services, providers, or legal obligations change. The “Last updated” date at the top reflects the latest revision. Material changes will be communicated to Platform customers by email or in-app notice, and the current version will always be available at this address.
13. Contact
Elandz Oy Ab · Vesurikatu 7, 20780 Kaarina, Finland
Questions about this policy or your personal data: privacy@elandz.com
Privacy Policy
Last Updated: 01-November 2024
Elandz Ltd (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our application (“App”) and related services.
1. Information We Collect
Personal Data
When you register to use our App, we may collect personal information such as:
- Contact Information: Name, email address, and phone number.
- Account Information: Usernames, passwords, and other authentication data.
- Stripe Data: Access to your Stripe account data necessary for exporting to Google Sheets.
- Google Drive Data: Access to your Google Drive to create and manage Google Sheets.
Usage Data
We may collect information about your interaction with the App, including:
- Device information (e.g., IP address, browser type).
- Log files and usage statistics.
- Cookies and similar tracking technologies.
2. How We Use Your Information
We use the information we collect for purposes including:
- Providing Services: To facilitate the export of your Stripe data to Google Sheets.
- Account Management: To manage user accounts and provide customer support.
- Improvement: To analyze usage and improve our App.
- Compliance: To comply with legal obligations and protect our rights.
3. Disclosure of Your Information
We may share your information:
- With Service Providers: Third-party vendors who assist in providing our services (e.g., Stripe, Google APIs).
- Legal Obligations: If required to do so by law or in response to valid requests by public authorities.
- Business Transfers: In connection with any merger, sale of company assets, or acquisition.
4. Data Security
We implement security measures to protect your information, including:
- Encryption: Data encryption in transit and at rest.
- Access Controls: Strict access controls to personal data.
- Tokenization: Use of tokens instead of passwords for secure access.
However, please note that no method of transmission over the Internet is 100% secure.
5. Your Rights
Depending on your jurisdiction, you may have rights including:
- Access: Request access to your personal data.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your personal data.
- Objection: Object to the processing of your personal data.
To exercise these rights, please contact us at privacy@elandz.com.
6. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure that appropriate safeguards are in place to protect your data.
7. Third-Party Services
Our App may contain links to third-party websites or services that are not owned or controlled by us. We are not responsible for the privacy practices of such third parties.
8. Retention of Data
We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law.
9. Children’s Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 18.
10. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by updating the “Last Updated” date of this Privacy Policy.
11. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at:
Elandz Ltd
Palosaarentie 61
Vaasa, Finland 65200
Email: privacy@elandz.com