
• Website visits. IP address or device identifiers, pages viewed, timestamps, basic diagnostics, and cookie preferences.
• Booking a call or session. Name, email, availability, location preference (video), any details you choose to share in the notes.
• Coaching delivery. Scheduling info, session history, working notes you ask us to retain, and relevant communications.
• Payments. Billing details and transaction metadata processed by our payment provider (we don’t see full card numbers).
• Newsletter (Org-Clinic list). Email address and your consent status.
• B2B briefs. Organisation, role, scope, goals, budget range, timelines, and attachments you submit.
• Email. Messages you send to our protonmail address.
• To run the site and keep it secure (basic logs, cookie preferences). Legitimate interests.
• To schedule and deliver coaching (including discovery/intake). Contract or steps before entering a contract.
• To take payments and meet accounting duties. Contract and legal obligation (Finnish accounting law).
• To send the newsletter and Org-Clinic invites. Consent (you can withdraw anytime).
• To handle B2B enquiries. Legitimate interests (replying to your request and preparing an offer).
• To improve our materials and services (non-essential analytics only if you consent). Consent.
These purposes and legal bases align with GDPR’s transparency rules.
• Client communications and files: for the coaching relationship and up to 24 months after the last interaction, unless you ask us to delete earlier (unless we must keep records to comply with law or defend legal claims).
• Newsletter data: until you unsubscribe or we clean inactive lists.
• B2B briefs: 12 months after last contact, unless a project proceeds.
• Accounting records: per Finnish law, financial statements/ledgers 10 years from the end of the financial year; vouchers/receipts and supporting documents 6 years from the end of the calendar year in which the accounting period ends.