How I handle your data

Trust & Security

Last updated 9 September 2026

I work as a solo IT management consultant, and I hold myself to the same data protection and security standards I’d expect from a larger vendor. This page explains what data I hold, where it lives, and how I protect it.

GDPR & data protection

I process personal data — contact details and project context — as a data controller under the EU General Data Protection Regulation and the Finnish Data Protection Act (1050/2018).

  • Data minimisation. I only collect what I need to run the engagement.
  • Legal basis. I rely on legitimate interest for business contacts, and contract performance for active client work.
  • Retention. Contact data is kept for the duration of the relationship plus 3 years. Project data is kept per the contractual terms, or for 5 years where needed for legal or tax purposes.
  • Your rights. You can ask me to access, correct, or erase your data at any time — see Contact below.

What data I hold, and why

  • Client and prospect contact information: name, email, role, company.
  • Project and engagement notes, scoped to the work being delivered.
  • Invoice and contract records, kept for 10 years as required by Finnish accounting law.

I do not hold sensitive personal data on clients — no health, financial, or biometric data.

Third-party processors

I keep the number of processors small and choose EU/EEA-based providers wherever practical:

  • Infomaniak kSuite (kMail, kDrive) — my email and working-document platform. Infomaniak is a Swiss provider with Swiss data centres, GDPR-compliant, and does not transfer data to the US. No advertising business model.
  • Google Workspace — used for calendar and identity only, not for email or document storage.
  • Holvi — my business banking provider, a Finnish fintech regulated by the Finnish Financial Supervisory Authority (FIN-FSA).
  • Hetzner — EU-based servers (Germany and Finland) that run this website, my backend automation and infrastructure.
  • Obsidian — my working notes system. Notes are synced end-to-end encrypted via Obsidian Sync and mirrored to servers I control in the EU. The sync provider cannot read the content.

I do not use Microsoft 365 for client data.

Security practices

  • TLS encryption in transit for all email and web traffic.
  • Multi-factor authentication on my business banking and on my email and document platform.
  • No client data stored on shared or unencrypted drives.
  • Credentials and access secrets are kept in a self-hosted password manager under my own control, not a third-party consumer product.
  • Contract and invoice files are stored with access controls, not in open or public locations.
  • This website itself is static: no user accounts, no database, no cookies, no third-party scripts — nothing that could leak visitor data. See the Privacy Policy.

AI-assisted work

I use AI tools — principally Anthropic’s Claude — for research, drafting, and administrative support. I am direct about how that works: these are general-purpose cloud services, and I do not claim special vendor terms for them.

The boundary I hold is the one I actually control: client-identifying information does not go into them. I work with general patterns, anonymised context, and my own material rather than named client data. Client records — contracts, engagement notes, invoices — stay in my own controlled systems. AI tools support how I work; they are not a system of record, and they are not a place client data is stored.

Data breach response

If I confirm a data breach, I will notify affected parties and the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) within 72 hours, in line with GDPR requirements.

Contact

For privacy questions or data requests, contact me at martin@bilboconsult.com. I respond within 30 days.