Mushin

Privacy Policy

Last updated

Effective date: 9 October 2026

This policy explains how Mushin Oy (“Mushin Helsinki”, “we”, “us”) handles personal data when you visit mushin.biz, book a call with us, or email us. It is written to meet the information requirements of the EU General Data Protection Regulation (GDPR, Articles 13 and 14) and the Finnish Data Protection Act (1050/2018).

The short version

1. Who is responsible for your data

The data controller is:

Mushin Oy
Business ID (Y-tunnus): 3615947-8
Olarinluoma 7, 02200 Espoo, Finland
Email: info@mushin.biz

We are a small company. Our co-founders, Anu Guttorm and Petteri Forsman, handle all privacy questions and requests. Email us at info@mushin.biz. We haven’t appointed a Data Protection Officer because the law doesn’t require one for a business like ours.

2. Where your data comes from

We only use data that:

We don’t buy contact lists or collect data about you from other sources.

3. What we do with your data, and why

3.1 Showing you the website and keeping it secure

What data IP address, date and time of the request, the page or file requested, browser and operating system (user agent), referring page, and approximate location derived from the IP address (country or region). If a page fails to load, your browser may also send Cloudflare a short technical error report (“Network Error Logging”) with the same kind of information.
Why To deliver the website quickly from a server near you, to keep it running, and to protect it against attacks, abuse and bots (for example denial-of-service attacks).
Legal basis Our legitimate interest in running a secure, working website (GDPR Art. 6(1)(f)). Without this data, the site can’t technically reach your device.
Who processes it Cloudflare, Inc. (hosting, content delivery network and security), acting on our behalf.
How long Cloudflare keeps request and security logs for short periods under its own retention practices. Any logs available to us in our Cloudflare account (Workers Logs) are deleted automatically after 7 days at most.

Cloudflare runs a global network. Your request is normally handled in the data centre closest to you, so for visitors in Europe that is usually a European location.

3.2 Counting visits (website statistics)

What data Pages viewed (without any query parameters), the referring site, browser, operating system and device type, country, and page-load performance measurements. A small script from Cloudflare (static.cloudflareinsights.com) collects this and sends it to Cloudflare.
What it doesn’t do It sets no cookies, uses no local storage, and does no fingerprinting. It doesn’t recognise you across visits or across websites. We only see aggregated totals, never individual visitors.
Why To understand, in general terms, how many people visit the site, where they come from, and whether the page loads fast enough, so we can improve it.
Legal basis Our legitimate interest in understanding and improving our website in a privacy-friendly way (GDPR Art. 6(1)(f)).
Who processes it Cloudflare, Inc. (Cloudflare Web Analytics), acting on our behalf.
How long Cloudflare keeps the raw measurements for 7 days and then reduces them to a statistical sample. Aggregated statistics stay available to us for up to 6 months.

You can block the statistics script with any common content blocker without losing any website functionality.

3.3 Booking a call with us

The “Book a call” buttons take you to our booking page in Google Calendar (part of Google Workspace), hosted by Google. Nothing is collected on mushin.biz itself.

What data The details you enter: your name, email address, the time slot you choose, and anything you add (for example your company name or what you’d like to discuss). Google Calendar sends you a booking confirmation and a calendar invitation by email.
Why To schedule and hold the meeting, prepare for it, and follow up afterwards about a possible engagement.
Legal basis Taking steps at your request before entering into a contract (GDPR Art. 6(1)(b)) if you are looking for our services for yourself or your own company. If you book on behalf of an organisation, our legitimate interest in arranging and handling business meetings (Art. 6(1)(f)).
Who processes it Google (Google Cloud EMEA Limited, Ireland), which runs the booking page and our calendar (Google Workspace) on our behalf. The booking is stored as an event in our calendar.
How long 12 months after our last contact with you, unless you become a client (see section 5).

The booking page is hosted on Google’s servers and may use Google’s own cookies. If you are signed in to a Google account while booking, Google’s privacy policy also applies to your use of that account: https://policies.google.com/privacy.

3.4 Emailing us

What data Your name and email address, the content of your message and any attachments, our replies, and the usual technical email information (such as date and time).
Why To read and answer your message and to keep a record of our business correspondence.
Legal basis Our legitimate interest in responding to inquiries and communicating with business contacts (GDPR Art. 6(1)(f)). If your email is about a possible or ongoing engagement with you, also steps before or for a contract (Art. 6(1)(b)).
Who processes it Google (Google Cloud EMEA Limited, Ireland), which provides our email and calendar (Google Workspace) on our behalf.
How long 12 months after our last contact with you, unless you become a client (see section 5).

Our page links to our Google Calendar booking page (see 3.3) and to our LinkedIn company page. These are plain links. We don’t embed Google or LinkedIn content, and we don’t use their tracking pixels on mushin.biz, so nothing is shared with them unless you click. Once you are on their sites, their own privacy and cookie policies apply.

3.6 What we don’t do

4. Who receives your data

We only share data with service providers who process it on our behalf and under our instructions (data processors), each bound by a data processing agreement as required by GDPR Art. 28:

Provider Service Data involved
Cloudflare, Inc. (USA, global network) Website hosting, content delivery, security, website statistics, DNS Technical visit data (sections 3.1 and 3.2)
Google (Google Cloud EMEA Limited, Ireland; parent company Google LLC, USA) Email, calendar and booking page (Google Workspace) Bookings, emails and meeting entries (sections 3.3 and 3.4)

These providers use their own sub-processors, which they list publicly.

Beyond this, we only disclose personal data if the law requires it (for example to authorities) or if it’s needed to establish, exercise or defend legal claims. If our business were ever sold or reorganised, data could pass to the new owner, who would remain bound by this policy.

5. How long we keep your data

Data How long
Hosting and security logs (Cloudflare) A few days. Logs in our Cloudflare account: up to 7 days.
Website statistics Aggregated, non-identifying data: up to 6 months
Booking details and email correspondence 12 months after our last contact with you
If you become a client For the duration of the engagement and then 3 years (the general limitation period under the Finnish Act on the Statute of Limitations of Debts, 728/2003). Accounting records (such as contracts and invoices) are kept for as long as the Finnish Accounting Act requires: 6 years for accounting vouchers and 10 years for the books, from the end of the financial year.
If you ask us not to contact you again A minimal note (your email address and the request) so we can respect your wish

Once these periods end, we delete or anonymise the data.

6. Transfers outside the EU/EEA

Some of our providers are based in the United States or use sub-processors outside the EU/EEA. When personal data is transferred outside the EU/EEA, it is protected in one of these ways:

Provider-specific notes:

For a copy of the safeguards that apply, contact us at info@mushin.biz.

7. Your rights

Under the GDPR you have the right to:

Your right to object

Where we process your data on the basis of our legitimate interests (sections 3.1, 3.2, 3.4, and 3.3 when you book on behalf of an organisation), you have the right to object at any time, on grounds relating to your particular situation. We will then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims.

To block the website statistics yourself, you can also use a content blocker (see section 3.2).

How to use your rights: email info@mushin.biz. We’ll reply within one month. If a request is complex, we may extend this by up to two more months, and we’ll tell you if we do. Using your rights is free. If we can’t be sure who you are, we may ask you to confirm your identity.

Note: for data that Cloudflare collects purely as part of delivering the website (section 3.1), we usually can’t link the data to a specific person, so in practice we may not be able to find “your” records (GDPR Art. 11).

8. Your right to complain

If you think we handle your data unlawfully, you can lodge a complaint with a supervisory authority. In Finland that is:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Postal address: P.O. Box 800, 00531 Helsinki, Finland
Visiting address: Lintulahdenkuja 4, 00530 Helsinki
Phone: +358 29 566 6700 · Email: tietosuoja@om.fi
Website: https://tietosuoja.fi/en

You can also complain to the supervisory authority in the EU/EEA country where you live or work. Please contact us first, because we would like the chance to sort it out.

9. Do you have to give us your data?

10. Cookies

mushin.biz does not set any cookies and doesn’t store anything else on your device (such as local storage). Our website statistics work without cookies (section 3.2). That’s why there is no cookie banner.

As part of its security service, Cloudflare may in exceptional cases set a strictly necessary security cookie, for example cf_clearance after showing a “verify you are human” check during an attack. Such cookies only protect the site and don’t track you. Under the Finnish Act on Electronic Communications Services (917/2014, section 205) they don’t require consent.

External sites we link to, such as the Google Calendar booking page and LinkedIn, use their own cookies under their own policies (section 3.5).

11. Security

We protect personal data with appropriate technical and organisational measures, following professional care and good industry practice. For example, connections to our website are encrypted (HTTPS), access to personal data is limited to the people who need it, and we only use reputable service providers that are themselves bound to keep data secure.

12. Changes to this policy

We’ll update this policy when our website, services or the law change. The “Last updated” date at the top shows when it last changed. If we make important changes that affect how we use data you’ve already given us, we’ll also tell you directly where we can.

13. Contact

Questions about this policy or your data? Email info@mushin.biz.

Mushin Oy · Business ID 3615947-8 · Olarinluoma 7, 02200 Espoo, Finland