Skip to content
Privacy Policy

Kletta Privacy Policy

Accounting is an essential part of running a business, but it shouldn’t be complicated. That’s why we created Kletta — an easy-to-use and reliable accounting solution tailored for sole proprietors.

Privacy Notice for Kletta Software Service Users

Effective Date: 01.01.2024

Who is the Data Controller?

The data controller is Kletta Oy (Business ID: 3131376-3), Riskutie 42 B, 00950 Helsinki, Finland (“data controller”).


Whose Data Is Collected?

This Privacy Notice applies to:

  • Registered users of the Kletta Oy software service

  • Former users of the service

  • Other individuals whose contact information is provided to Kletta in connection with the provision of the service (“data subject”)


What Personal Data Is Collected?

The following personal data may be collected:

  • Registered user information: name, address, email, phone number, date and place of birth, personal identity code, and nationality

  • Any personal data provided during customer communication, either voluntarily or as part of a support case

We may process sensitive personal data only when necessary for the performance of contractual or legal obligations and only to the extent permitted or required by law.


Why Is Personal Data Collected and How Is It Used?

The purpose of processing personal data is to provide the service in accordance with the contract between Kletta Oy and the user.

Personal data is processed to:

  • Manage administrative tasks: user registration, business registration, customer service

  • Control access: user credentials and login data

  • Manage tax matters: tax filings and other agreed services

  • Conduct customer satisfaction activities: feedback surveys, user testing

  • Comply with legal obligations and official regulations

We do not process personal data for any purposes other than those stated in this Privacy Notice, unless the data subject gives explicit consent or processing is necessary to fulfill a contract or comply with legal obligations.


Where Does the Data Come From?

Personal data is primarily collected directly from the user during registration and use of the service. We may also collect data from public authorities and publicly available sources (e.g., Suomi.fi, Finnish Legal Register Centre, Tax Administration, Trade Register), as well as from other relevant systems.

Users may also enter their own customers’ personal data into the service in connection with invoicing. In such cases, the user acts as the data controller, and Kletta Oy only functions as the system provider and/or data processor.


Who May Access or Receive the Data?

Personal data may be shared with third parties in the following situations:

  • With authorities such as the Tax Administration or other official bodies, where permitted or required by law

  • With partners, service providers, and IT system vendors processing personal data on behalf of Kletta Oy and under its instructions (e.g., IT systems, banks, insurance companies)

  • With other parties, if the data subject has provided explicit consent

When data is shared, Kletta takes reasonable steps to ensure that confidentiality and data protection obligations are followed.


How Is the Data Processed and Stored?

Personal data is processed with care and stored on a secure server, which is accessible only by the data controller and authorized technical administrators.

Only individuals whose duties require access to the data are allowed to handle it, and all personnel are bound by a confidentiality obligation.


How Is the Data Protected?

Kletta takes appropriate technical and organizational measures to protect personal data against loss, destruction, misuse, unauthorized access, or disclosure. However, no security measure is completely foolproof.

In the event of a personal data breach, we will notify you in accordance with applicable law.


How Long Is the Data Retained?

Personal data is generally retained for the duration of the customer relationship and for six (6) years after its termination, unless a longer retention period is necessary due to ongoing legal proceedings, criminal investigations, or the protection of the rights of Kletta Oy or its employees.

Data may also be retained longer to comply with legal obligations (e.g., anti-money laundering laws or accounting regulations).

If the user withdraws their consent after the end of the customer relationship, data not required to be retained by law will be deleted.


What Are Your Rights?

As a data subject, you have the right to:

  • Access the personal data we hold about you

  • Request correction, updating, or deletion of your data

  • Object to or restrict processing of your data under applicable law

  • Withdraw consent at any time, if processing is based on consent

  • Data portability: receive your data in a machine-readable format and transfer it to another data controller

  • File a complaint with the relevant supervisory authority if you believe your rights have been violated

Some data may be exempt from deletion or restricted use if required to fulfill legal obligations or if it is essential for the purposes described in this notice.


Who Can I Contact?

If you wish to exercise your rights or ask questions about data protection, please contact:

support@kletta.com

You also have the right to lodge a complaint with the Data Protection Ombudsman in Finland if you suspect that the data controller has violated applicable data protection laws.