Reachify

Legal

Privacy Policy

How Reachify Oy handles personal data, what we collect, why we are allowed to process it, and the rights you have under the EU General Data Protection Regulation.

Last updated: 11 August 2026

Reachify Oy ("Reachify", "we") is the data controller for personal data processed through this website and in our client relationships. This policy is legally binding on us and describes our processing under Regulation (EU) 2016/679 (GDPR) and the Finnish Data Protection Act (1050/2018). By using this website or ordering our services you acknowledge this policy.

01Data we collect

We collect only data that is necessary for running our business and delivering our services.

  • Contact and business data: name, role, company, email, phone, venue address, business ID.
  • Contract and billing data: offers, orders, invoices, payment status, correspondence.
  • Service delivery data: access details you grant us, account configurations, published content, review and ranking statistics from third-party platforms.
  • Technical data: IP address, device and browser type, pages visited, referrer, timestamps and language preference stored locally in your browser.

02Purposes and legal bases

We process personal data to conclude and perform service agreements (Art. 6(1)(b)), to comply with accounting, tax and other statutory duties (Art. 6(1)(c)), for our legitimate interests in operating, securing, measuring and improving our website and services and in direct B2B marketing (Art. 6(1)(f)), and, where required, on the basis of your consent (Art. 6(1)(a)) which you may withdraw at any time.

We do not sell personal data, do not use it for automated decision-making with legal effects, and do not knowingly collect data from children.

03Cookies and analytics

This website uses only technically necessary storage by default, including a local browser entry that remembers your chosen language. Any analytics or marketing cookies are set only where permitted by law and, when consent is required, only after you have given it. You can block or delete cookies in your browser settings; some functions may then stop working.

04Sharing and processors

We share personal data only with service providers acting as our processors under written data processing agreements — for example hosting, email, analytics, accounting, payment and Google services — and with authorities where the law requires it.

Where data is transferred outside the EU/EEA, we rely on adequacy decisions or the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures.

05Retention

Personal data is retained only as long as necessary for the purposes above: client and contract data for the duration of the relationship and up to ten (10) years afterwards for limitation-period and evidentiary purposes, accounting data for the statutory retention period, marketing contact data until you object, and technical log data typically up to twelve (12) months.

06Security

We apply appropriate technical and organisational measures, including access control, least-privilege credentials, encryption in transit and confidentiality obligations for personnel and subcontractors. No online service can be guaranteed absolutely secure, and to the fullest extent permitted by law we accept no liability for unauthorised access, interception or loss that occurs despite these measures.

07Your rights

Subject to statutory conditions you have the right to access your data, to have it rectified or erased, to restrict or object to processing, to data portability, to withdraw consent and to lodge a complaint with a supervisory authority. Send requests to privacy@reachify.cloud; we may need to verify your identity before acting.

08Third-party platforms and links

Our services interact with third-party platforms such as Google. Those providers process data as independent controllers under their own privacy policies, and reviews left by your customers are published on their platforms, not ours. Reachify has no control over and, to the fullest extent permitted by law, accepts no liability for the processing, availability, moderation, removal or loss of data by any third-party platform or externally linked website.

09Client data and roles

When we process personal data on a client’s behalf while delivering services (for example content or account data inside the client’s own systems), the client is the controller and Reachify acts as processor on the client’s documented instructions. The client is responsible for the lawfulness of those instructions and of the data it provides to us.

10Changes to this policy

We may update this policy at any time by publishing a new version on this page with an updated date. Material changes take effect thirty (30) days after publication; continued use of the website or services after that date constitutes acknowledgement. This policy is governed by Finnish law, and mandatory GDPR rights are never limited by it.

Contact and complaints

Data protection requests: privacy@reachify.cloud — Reachify Oy, Helsinki, Finland. You may also lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi). We respond to verified requests within one month.