How I handle your data
Trust & Security
I work as a solo IT management consultant, and I hold myself to the same data protection and security standards I’d expect from a larger vendor. This page explains what data I hold, where it lives, and how I protect it.
GDPR & data protection
I process personal data — contact details and project context — as a data controller under the EU General Data Protection Regulation and the Finnish Data Protection Act (1050/2018).
- Data minimisation. I only collect what I need to run the engagement.
- Legal basis. I rely on legitimate interest for business contacts, and contract performance for active client work.
- Retention. Contact data is kept for the duration of the relationship plus 3 years. Project data is kept per the contractual terms, or for 5 years where needed for legal or tax purposes.
- Your rights. You can ask me to access, correct, or erase your data at any time — see Contact below.
What data I hold, and why
- Client and prospect contact information: name, email, role, company.
- Project and engagement notes, scoped to the work being delivered.
- Invoice and contract records, kept for 10 years as required by Finnish accounting law.
I do not hold sensitive personal data on clients — no health, financial, or biometric data.
Third-party processors
I keep the number of processors small and choose EU/EEA-based providers wherever practical:
- Infomaniak kSuite (kMail, kDrive) — my email and working-document platform. Infomaniak is a Swiss provider with Swiss data centres, GDPR-compliant, and does not transfer data to the US. No advertising business model.
- Google Workspace — used for calendar and identity only, not for email or document storage.
- Holvi — my business banking provider, a Finnish fintech regulated by the Finnish Financial Supervisory Authority (FIN-FSA).
- Hetzner — EU-based servers (Germany and Finland) that run this website, my backend automation and infrastructure.
- Obsidian — my working notes system. Notes are synced end-to-end encrypted via Obsidian Sync and mirrored to servers I control in the EU. The sync provider cannot read the content.
I do not use Microsoft 365 for client data.
Security practices
- TLS encryption in transit for all email and web traffic.
- Multi-factor authentication on my business banking and on my email and document platform.
- No client data stored on shared or unencrypted drives.
- Credentials and access secrets are kept in a self-hosted password manager under my own control, not a third-party consumer product.
- Contract and invoice files are stored with access controls, not in open or public locations.
- This website itself is static: no user accounts, no database, no cookies, no third-party scripts — nothing that could leak visitor data. See the Privacy Policy.
AI-assisted work
I use AI tools — principally Anthropic’s Claude — for research, drafting, and administrative support. I am direct about how that works: these are general-purpose cloud services, and I do not claim special vendor terms for them.
The boundary I hold is the one I actually control: client-identifying information does not go into them. I work with general patterns, anonymised context, and my own material rather than named client data. Client records — contracts, engagement notes, invoices — stay in my own controlled systems. AI tools support how I work; they are not a system of record, and they are not a place client data is stored.
Data breach response
If I confirm a data breach, I will notify affected parties and the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) within 72 hours, in line with GDPR requirements.
Contact
For privacy questions or data requests, contact me at martin@bilboconsult.com. I respond within 30 days.