Skip to content Enter

Privacy Statement – Customer Relationship Management

 

  1. Introduction

This Privacy Statement describes what personal data Greenstep and its Group companies (collectively “Greenstep”, “we”, or “us”) collect and how we use that data in our Customer Relationship Management (CRM). We process personal data primarily in connection with our customer relationship management activities, including data collected through prospecting, day‑to‑day business interactions, meetings, events, and other communications related to sales and customer cooperation. The information we gather enables us to manage customer relationships, provide and develop our services, and communicate relevant updates to our existing and potential customers in a secure and lawful manner.

 

  1. Controller and contact details 

The Controller of personal data processed in accordance with this Privacy Statement is:

Greenstep Oy, business ID 2306461-3

Address: Keilalahdentie 2-4, 02150 Espoo, FINLAND

Contact: compliance@greenstep.com

In addition, companies belonging to the Greenstep Group act as joint controllers with Greenstep Oy whenever they process the same personal data in their activities, and all Group companies follow the data protection principles described in this Privacy Statement. While the Group companies act as joint controllers, Greenstep Oy serves as the primary point of contact for exercising data subject rights and managing compliance related queries.

 

  1. Basis of processing of personal data

Greenstep’s primary duty is to provide services to our customers, and this constitutes the main purpose for which we process personal data. Greenstep processes personal data only when there is a specific and lawful purpose for doing so under applicable data protection legislation. Greenstep relies on one or more of the following legal bases when processing personal data:

  • Performance of a contract: Processing is necessary to fulfil contractual obligations or to take steps at the request of a data subject prior to entering a contract.
  • Legitimate interests: Processing is necessary for Greenstep’s legitimate interests in operating a secure and efficient business, provided these interests are not overridden by the person’s rights and freedoms. These legitimate interests may include:
    • manage and develop our relationship with the customer, e.g., service improvement and business analytics;
    • providing information or services to the persons who interact with Greenstep’s website or digital channels;
    • conducting and analysing customer surveys as well as prospecting and marketing activities.
  • Consent: Greenstep may rely on the person’s consent in certain situations, such as recording meetings, sending marketing communications, event invitations, or processing optional information. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Purpose of processing Categories of personal data Legal basis
Customer Relationship Management – prospects
  • Sales and marketing contact data: The data collected via our marketing and sales  efforts or prior customer relationship including contact data (e.g., name, email address, phone number, work title, and association with the entity)
  • Communication information: If you communicate with us, such as via email or our contact form or our pages on social media sites, we may collect personal data like your name, contact information, and the contents of the messages you send
  • Information about whether the person has consented to or opted out of receiving direct marketing
  • Sales, communication, and marketing information (e.g., marketing preferences, event participation, and meeting transcript)
  • Automatically collected data, i.e., data collected by our website cookies and e.g., information about whether the person has opened and read an email message we have sent
Legitimate interest Consent 
Customer Relationship Management – customers
  • Contact data (e.g., name, email address, phone number)
  • Information essential for providing our services and fulfilling contractual engagements (e.g., the contents of the messages you send)
  • Title and association with the customer, such as work title
  • Sales, communication, and marketing information (e.g., marketing preferences, event participation, and meeting transcript)
  • Information essential for providing Greenstep’s services and fulfilling contractual engagements
Taking steps to enter or executing a contract Legitimate interest  Consent
  1. Transfer and disclosure of personal data

Greenstep and its processors shall not transfer any personal data to any country outside of the European Economic Area (EEA) unless the transfer is made to a country considered as a place giving an appropriate level of protection by the European Commission, or subject to such other data transfer mechanism or protections that are approved and accepted by the applicable Data Protection Legislation taking into account the requirements of the competent authorities.

Greenstep may also disclose personal data when:

  • requested by the person;
  • required to deliver publications or reference materials requested by the person;
  • required to facilitate conferences or events hosted by a third party;
  • required by law, regulation, or competent authorities; or
  • otherwise described in this Privacy Statement.

 

  1. Storage and retention of personal data 

Retention periods are defined in Greenstep’s data administration practices and take into account the nature of the data, its sensitivity, and applicable legal obligations. When data is no longer needed, it is securely deleted or anonymised in accordance with Greenstep’s data governance and protection policies. Meeting recordings are retained for up to 90 days and are then automatically deleted. Other personal data is stored only as long as required to support operational needs, fulfil the purposes for which it was collected, or comply with statutory retention requirements.

 

  1. Protection of personal data

Greenstep has implemented generally accepted standards of technology and operational security in order to protect personal data from loss, misuse, alteration, or destruction. Only authorized persons are granted access to personal data processed by Greenstep, and such persons have agreed to maintain the confidentiality of this information.

While Greenstep uses appropriate security measures once we have received personal data, the transmission of data over the internet (including by e-mail) is never completely secure. Greenstep strives to protect personal data, but we cannot guarantee the security of data transmitted to or by us.

 

  1. Rights of data subjects

Data protection legislation guarantees persons as data subjects with several rights concerning the processing of their personal data. The scope of these rights depends on the legal basis applied to the relevant processing activities. Greenstep is committed to respecting and facilitating these rights.

The rights available to data subjects include where applicable:

  • Right of access – The person can request confirmation of whether we process their personal data and receive a copy of that data, along with information on how it is used.
  • Right to rectification – The person may ask us to correct inaccurate personal data or, when necessary, complete incomplete data.
  • Right to object – The person may object to processing based on our legitimate interests if their situation outweighs those interests. The person may always object to the use of their data for direct marketing.
  • Right to data portability – The person may request the personal data they have provided to us – when processed based on consent or a contract – in a structured, commonly used, and machine‑readable format, and have it transferred to another controller.
  • Right to erasure (“right to be forgotten”) – The person may request the deletion of their personal data when there is no valid reason for us to continue processing it, for example if it is no longer needed or the person withdraws their consent.
  • Right to restriction of processing – In certain circumstances, the person may request that we limit the processing of their personal data, for example while verifying its accuracy.
  • Right to give and withdraw consent – When processing is based on a consent, the person may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

 

  1. Questions and complaints

Requests for the execution of the data subject’s rights may be addressed to compliance@greenstep.com. The fulfilment of certain rights may be subject to additional legal requirements. Greenstep may also request further information from the person submitting the request to ensure secure and lawful processing of the request.  

The data subject has the right to lodge a complaint with a competent data protection supervisory authority, including the Office of the Data Protection Ombudsman in Finland, if they believe their personal data is being processed in violation of applicable laws.

 

  1. Amendments to this Privacy Statement

This Privacy Statement was last updated on 19 August 2026. Greenstep may update or amend this Privacy Statement at any time by publishing an updated version on Greenstep’s website.