Privacy and GDPR Notice
This notice explains how GG Ventures Oy processes personal data through the Girişimci Göçmen website, callback form, CRM, advisory work, application preparation and service payments under the GDPR and applicable Finnish law.
1. Controller
GG Ventures Oy determines the purposes and means of personal-data processing for Girişimci Göçmen services.
- Controller and service provider
- GG Ventures Oy
- Business ID
- 3473339-2
- Address
- Karvaamokuja 3 A, 00380 Helsinki, Finland
- Contact
- info@girisimcigocmen.com
2. Data we process
The exact data depends on the service and your contact with us. We process only data that is relevant and proportionate to the stated purpose.
- Identity and contact details, including name, phone number, email, country of residence and preferred contact channel.
- Advisory information, including professional background, education, language skills, entrepreneurship history, business project, investment and family-relocation plans.
- Service-file information, including agreements, business plans, financial work, meeting notes, deliverables and application correspondence.
- Callback and CRM records, including the request, service category, follow-up status, referrals and consent records.
- Billing and payment records, including invoice details, amount, date, payment status and transaction reference. GG Ventures Oy does not request full card numbers or card security codes.
- Technical and security data, including IP address, browser and device information, request logs and cookie or local-storage preferences.
3. Purposes and legal bases
- Enquiries and pre-contract steps
- To assess your request and take steps at your request before a possible service agreement.
- Callback and CRM follow-up
- To receive, route, respond to and securely track your request, based on pre-contract steps and legitimate interests.
- Advisory service
- To form and perform a service agreement, prepare agreed work and communicate with you.
- Accounting and statutory obligations
- To meet legal, accounting, audit and tax obligations applicable to GG Ventures Oy.
- Optional communications and non-essential technologies
- Your consent, which can be withdrawn for future processing.
4. Recipients and processors
Access is limited to authorised GG Ventures Oy team members and service providers required for the relevant purpose.
- OpenAI Sites for website hosting; Vercel and Supabase for the callback CRM application and database.
- Email, secure file, accounting and payment providers used for a service you request.
- YouTube/Google or Instagram/Meta only when you choose to load their external content.
- EDUCON or AVISEN only after the intended referral and recipient have been explained and you authorise the transfer.
- Competent public authorities, courts or advisers where required by law or necessary to establish, exercise or defend legal claims.
5. International transfers
GG Ventures Oy is established in Finland and its core processing takes place in the European Economic Area. Global technology providers and their subprocessors may process limited data outside the EEA. Where Chapter V GDPR applies, an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism is used as applicable.
6. Retention
- Callback, referral, consent and CRM follow-up records: up to 24 months after the last contact if no service relationship is formed.
- Advisory and application-service files: up to six years after the service ends, unless a longer period is required for an ongoing claim or statutory obligation.
- Invoices, payment and accounting records: for the mandatory Finnish financial-record retention period.
- Security logs and local preferences: only for the period reasonably necessary for security or the stated technical purpose.
7. Your rights
Depending on the processing and legal basis, you may request access, rectification, erasure, restriction, data portability or object to processing. You may withdraw consent at any time for future processing. You may also complain to the Office of the Data Protection Ombudsman in Finland.
8. Security and sensitive documents
Access is role-limited and proportionate technical and organisational safeguards are used. Do not send health, biometric, criminal-record or other sensitive documents through the general callback form. If an agreed official application genuinely requires such material, we will provide the appropriate process and legal basis.
Relevant rules and official guidance
Do you have a question or rights request?
Please identify yourself, provide contact details and explain which processing activity your request concerns.