Privacy Statement – Customer Relationship Management
-
Introduction
This Privacy Statement describes what personal data Greenstep and its Group companies (collectively “Greenstep”, “we”, or “us”) collect and how we use that data in our Customer Relationship Management (CRM). We process personal data primarily in connection with our customer relationship management activities, including data collected through prospecting, day‑to‑day business interactions, meetings, events, and other communications related to sales and customer cooperation. The information we gather enables us to manage customer relationships, provide and develop our services, and communicate relevant updates to our existing and potential customers in a secure and lawful manner.
-
Controller and contact details
The Controller of personal data processed in accordance with this Privacy Statement is:
Greenstep Oy, business ID 2306461-3
Address: Keilalahdentie 2-4, 02150 Espoo, FINLAND
Contact: compliance@greenstep.com
In addition, companies belonging to the Greenstep Group act as joint controllers with Greenstep Oy whenever they process the same personal data in their activities, and all Group companies follow the data protection principles described in this Privacy Statement. While the Group companies act as joint controllers, Greenstep Oy serves as the primary point of contact for exercising data subject rights and managing compliance related queries.
-
Basis of processing of personal data
Greenstep’s primary duty is to provide services to our customers, and this constitutes the main purpose for which we process personal data. Greenstep processes personal data only when there is a specific and lawful purpose for doing so under applicable data protection legislation. Greenstep relies on one or more of the following legal bases when processing personal data:
- Performance of a contract: Processing is necessary to fulfil contractual obligations or to take steps at the request of a data subject prior to entering a contract.
- Legitimate interests: Processing is necessary for Greenstep’s legitimate interests in operating a secure and efficient business, provided these interests are not overridden by the person’s rights and freedoms. These legitimate interests may include:
-
- manage and develop our relationship with the customer, e.g., service improvement and business analytics;
- providing information or services to the persons who interact with Greenstep’s website or digital channels;
- conducting and analysing customer surveys as well as prospecting and marketing activities.
- Consent: Greenstep may rely on the person’s consent in certain situations, such as recording meetings, sending marketing communications, event invitations, or processing optional information. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal.
| Purpose of processing | Categories of personal data | Legal basis |
|---|---|---|
| Customer Relationship Management – prospects |
|
Legitimate interest Consent |
| Customer Relationship Management – customers |
|
Taking steps to enter or executing a contract Legitimate interest Consent |
-
Transfer and disclosure of personal data
Greenstep and its processors shall not transfer any personal data to any country outside of the European Economic Area (EEA) unless the transfer is made to a country considered as a place giving an appropriate level of protection by the European Commission, or subject to such other data transfer mechanism or protections that are approved and accepted by the applicable Data Protection Legislation taking into account the requirements of the competent authorities.
Greenstep may also disclose personal data when:
- requested by the person;
- required to deliver publications or reference materials requested by the person;
- required to facilitate conferences or events hosted by a third party;
- required by law, regulation, or competent authorities; or
- otherwise described in this Privacy Statement.
-
Storage and retention of personal data
Retention periods are defined in Greenstep’s data administration practices and take into account the nature of the data, its sensitivity, and applicable legal obligations. When data is no longer needed, it is securely deleted or anonymised in accordance with Greenstep’s data governance and protection policies. Meeting recordings are retained for up to 90 days and are then automatically deleted. Other personal data is stored only as long as required to support operational needs, fulfil the purposes for which it was collected, or comply with statutory retention requirements.
-
Protection of personal data
Greenstep has implemented generally accepted standards of technology and operational security in order to protect personal data from loss, misuse, alteration, or destruction. Only authorized persons are granted access to personal data processed by Greenstep, and such persons have agreed to maintain the confidentiality of this information.
While Greenstep uses appropriate security measures once we have received personal data, the transmission of data over the internet (including by e-mail) is never completely secure. Greenstep strives to protect personal data, but we cannot guarantee the security of data transmitted to or by us.
-
Rights of data subjects
Data protection legislation guarantees persons as data subjects with several rights concerning the processing of their personal data. The scope of these rights depends on the legal basis applied to the relevant processing activities. Greenstep is committed to respecting and facilitating these rights.
The rights available to data subjects include where applicable:
- Right of access – The person can request confirmation of whether we process their personal data and receive a copy of that data, along with information on how it is used.
- Right to rectification – The person may ask us to correct inaccurate personal data or, when necessary, complete incomplete data.
- Right to object – The person may object to processing based on our legitimate interests if their situation outweighs those interests. The person may always object to the use of their data for direct marketing.
- Right to data portability – The person may request the personal data they have provided to us – when processed based on consent or a contract – in a structured, commonly used, and machine‑readable format, and have it transferred to another controller.
- Right to erasure (“right to be forgotten”) – The person may request the deletion of their personal data when there is no valid reason for us to continue processing it, for example if it is no longer needed or the person withdraws their consent.
- Right to restriction of processing – In certain circumstances, the person may request that we limit the processing of their personal data, for example while verifying its accuracy.
- Right to give and withdraw consent – When processing is based on a consent, the person may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
-
Questions and complaints
Requests for the execution of the data subject’s rights may be addressed to compliance@greenstep.com. The fulfilment of certain rights may be subject to additional legal requirements. Greenstep may also request further information from the person submitting the request to ensure secure and lawful processing of the request.
The data subject has the right to lodge a complaint with a competent data protection supervisory authority, including the Office of the Data Protection Ombudsman in Finland, if they believe their personal data is being processed in violation of applicable laws.
-
Amendments to this Privacy Statement
This Privacy Statement was last updated on 19 August 2026. Greenstep may update or amend this Privacy Statement at any time by publishing an updated version on Greenstep’s website.