Nettiteeri Oy logo – digital services expert

Privacy notice

Last updated 4 October 2026

This notice explains how personal data is processed on the Nettiteeri Oy website (nettiteeri.fi and nettiteeri.com) and in the electronic signature and contract archive service at sign.nettiteeri.fi. It is based on Articles 13 and 14 of the EU General Data Protection Regulation ((EU) 2016/679, “GDPR”) and the Finnish Data Protection Act (1050/2018).

1. Controllers and contact details

Controller
Nettiteeri Oy (business ID 3331525-2)
Contact person
Juha-Pekka Teirikangas
Email
juha-pekka@nettiteeri.fi
Phone
+358 44 280 9861

Nettiteeri Oy is the controller for data about the use of the website, for enquiries sent to it and for the user accounts of the signing service (company employees who send signature requests and manage the contract archive).

Signature requests and the contract archive

The signing service is operated by Nettiteeri Oy. Several companies use it, each with its own contract archive. The controller for the personal data in a contract and its signature request is the company in whose name the request is sent and in whose archive the contract is stored. That company’s name is shown in the invitation email, on the signing page and on the certificate page of the completed contract.

Where the controller is a company other than Nettiteeri Oy, Nettiteeri Oy processes the data on that company’s behalf and on its instructions as a processor (Article 28 GDPR). Requests about such a contract are best sent directly to that company; Nettiteeri Oy forwards any requests it receives to the right controller.

Companies using the service: Nettiteeri Oy (business ID 3331525-2) and [OPEN: other companies using the service – name, business ID and privacy contact].

2. Data processed in the signing service and its sources

A company uses the service to send a contract for electronic signature. Signers sign it through a personal link, and the completed contract is stored in the company’s archive and sent to all parties. Contracts signed elsewhere can also be stored in the archive.

Signers

  • Name, email address and language.
  • Signature request details: the contract, the sender, the cover message and the status of the request (sent, opened, signed or declined).
  • Signature: the typed or drawn name, the acceptance and its time, or the fact that the signer declined.
  • Identification and verification data: use of the signing link and of the one-time code sent by email, event timestamps, IP address, browser identifier (user agent) and document hashes (SHA-256).
  • Data contained in the contract document, such as the parties’ contact details and other information written into the contract.

The service does not collect personal identity codes. If the parties have written one into the contract document, it is processed only as part of the contract and within the limits of section 29 of the Finnish Data Protection Act.

Service users (company employees)

  • Name, email address, user role and company-specific access rights.
  • Login data: the password as a hash, and the two-factor authentication (TOTP) secret and recovery codes in encrypted form.
  • Session data: IP address, browser identifier and time of last activity.
  • Actions taken in the service, such as signature requests sent and contracts stored in the archive.

Where the data comes from

The signer’s name and email address and the contract document are provided by the company sending the signature request, which has usually received them from the signer or the organisation the signer represents while preparing the contract. Identification and verification data is generated when the signer uses the signing link. Contracts signed elsewhere (for example, previously in the SignHero service) and their details are added to the archive by the company from its own records. User account data comes from the user and from the administrator who creates the account. No data is collected from public sources.

3. Purposes, legal bases and retention periods

Sending signature requests and signing the contract

Data
The signer’s name, email address and language, the signature request details and the signature.
Legal basis
Entering into and performing a contract where the signer is a party to it (Article 6(1)(b) GDPR). Where the signer represents a company or other organisation, the controller’s legitimate interest in concluding the contract electronically and verifiably (Article 6(1)(f) GDPR).
Retention
A signed contract is kept as described under “Contract archive”. Data on requests that were left unfinished, cancelled, expired or declined is deleted 12 months after the request ended.

Identifying the signer and verifying the signature

Data
Use of the signing link and the one-time code, event timestamps, IP address, browser identifier and document hashes.
Legal basis
The legitimate interest of the controller and the contracting parties in being able to show who signed the contract and when, and that the document has not been altered, and to establish, exercise or defend legal claims (Article 6(1)(f) GDPR).
Retention
Verification data is kept together with the contract. The one-time code is valid only for a short time and cannot be reused; only the fact that it was sent and confirmed is kept.

Contract archive

Data
Signed contracts with their certificate pages, contracts signed elsewhere and imported into the archive, and details of their parties and signatures.
Legal basis
The controller’s legitimate interest in keeping the contracts it has concluded and evidence of them (Article 6(1)(f) GDPR), and the retention obligation under the Finnish Accounting Act (1336/1997) where the contract is part of the accounting records (Article 6(1)(c) GDPR).
Retention
For the duration of the contractual relationship and thereafter for as long as claims based on the contract can be made (Finnish Act on the Statute of Limitations of Debts 728/2003), as a rule 10 years after the relationship ends. A contract that forms part of the accounting records is kept at least as long as the Accounting Act requires, i.e. six years from the end of the year in which the financial period ended.

Sending emails

Invitations, one-time codes and completed contracts are sent by email in the name of the company acting as controller. Sending involves the recipient’s name, email address and the content of the message, which may have the completed contract attached. The legal basis and retention period are those of the processing the message relates to.

Service user accounts and security

Data
The user’s name, email address, role and access rights, login and session data, and technical logs.
Legal basis
The legitimate interest of Nettiteeri Oy and the companies using the service in admitting only authorised users and protecting contract data (Article 6(1)(f) GDPR).
Retention
A user account is kept as long as the user has access to the service and is deleted 12 months after the account is closed. Session data is deleted when the session expires. A user’s name may remain in a contract’s verification data, for example as the sender of the signature request, for the contract’s retention period.

Using the website

Data
Server log data, such as IP address, time, requested address and browser identifier.
Legal basis
Legitimate interest in maintaining the website and investigating faults and misuse (Article 6(1)(f) GDPR).
Retention
At most 3 months.

Enquiries

Data
The name and contact details of the person getting in touch and the content of the message.
Legal basis
Legitimate interest in responding to enquiries (Article 6(1)(f) GDPR) or steps taken at the person’s request prior to entering into a contract (Article 6(1)(b) GDPR).
Retention
As long as handling the matter requires. If the enquiry leads to a customer relationship, the data is kept for its duration and thereafter as long as the Accounting Act requires.

4. Cookies and third-party content

The website itself uses no cookies and no analytics or advertising tools. The Spotify players on the home page are loaded from Spotify’s servers only when you click the load button shown in place of the player. When a player loads, Spotify may store cookies on your device and receives data such as your IP address and browser details. Spotify processes this data as an independent controller under its own privacy policy.

Loading the players is based on your consent (section 205 of the Finnish Act on Electronic Communications Services 917/2014 and Article 6(1)(a) GDPR). Your choice is not stored: the players are loaded only for that page view, and you can withdraw your consent by reloading the page. Spotify cookies already stored on your device can be deleted in your browser settings.

The signing service (sign.nettiteeri.fi) uses only cookies that are strictly necessary for it to work, such as session and security cookies, which do not require consent (section 205(2)).

5. Recipients and processors

  • The other parties to the contract. The completed contract with its certificate page is sent to all parties to the contract. The certificate page shows each signer’s name, email address, time of signing and method of identification, and the document hashes. Where the same contract is signed separately with several people (for example, a project agreement), each gets their own copy and the signers do not see each other’s details.
  • Mailgun (Sinch group) sends invitations, one-time codes and completed contracts as a processor. Each company has its own Mailgun account and chooses whether it uses Mailgun’s EU or US region; in the EU region, messages are stored in the EU. See section 6.
  • Email service for system messages. Invitations and password reset messages to service users are sent through a processor: [OPEN: system email provider and its country].
  • The hosting provider runs the website and the signing service as a processor: [OPEN: provider name and country where the servers are located].
  • Nettiteeri Oy processes other companies’ contract data on their behalf as the operator of the service (see section 1).
  • Authorities, where the law requires data to be disclosed.

Data is not sold or disclosed for marketing.

6. Transfers outside the EU and the EEA

Mailgun is a service of Mailgun Technologies, Inc., a US company in the Sinch group. If a company uses Mailgun’s US region, messages and delivery data are stored in the United States. In the EU region, too, data may be processed by the group’s US companies to provide the service. These transfers are based on the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914), which are part of Mailgun’s data processing agreement.

Spotify may transfer data outside the EU under its own privacy policy. Hosting: [OPEN: whether data is transferred outside the EU/EEA and on what basis].

7. Your rights

Under the GDPR, you have the right to

  • know whether your data is processed and access it (Article 15)
  • have inaccurate data rectified (Article 16)
  • have your data erased (Article 17); this does not apply to data needed to comply with a legal obligation or to establish, exercise or defend legal claims, such as the verification data of a signed contract during its retention period
  • have processing restricted (Article 18)
  • object, on grounds relating to your particular situation, to processing based on legitimate interest (Article 21)
  • receive the data you have provided in a machine-readable format and transmit it to another controller where processing is based on a contract or consent and carried out by automated means (Article 20)
  • withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal (Article 7(3)).

Send your request to the controller (section 1). Requests about a contract are best sent to the company in whose name the signature request was sent. Requests are answered without undue delay and at the latest within one month (Article 12). Your identity may need to be verified before data is disclosed.

If you consider that the processing of your data infringes data protection law, you can lodge a complaint with the supervisory authority, which in Finland is the Data Protection Ombudsman (Article 77 GDPR, section 8 of the Data Protection Act):

Supervisory authority
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Postal address
PL 800, 00531 Helsinki, Finland
Email
tietosuoja@om.fi
Website
tietosuoja.fi

8. Is providing the data required?

Providing the data is not a statutory requirement. However, your name and email address are necessary for signing a contract in the service: without them, the invitation and the one-time code cannot be sent. If you do not want to sign electronically, you can agree on another way of signing with the company that sent the request. A service user account requires a name, an email address and two-factor authentication. Browsing the website requires no data from you.

9. Automated decision-making

Your data is not used for automated decision-making or profiling that would produce legal effects concerning you or similarly significantly affect you (Article 22).

10. Electronic signature and verification

A signature given in the service is an electronic signature within the meaning of Article 3(10) of the EU eIDAS Regulation ((EU) No 910/2014, as amended by Regulation (EU) 2024/1183), a so-called simple electronic signature. It is not an advanced or qualified electronic signature within the meaning of the Regulation, and it does not rely on strong electronic identification (such as online banking credentials or a mobile certificate).

How the signer is identified

  • Each signer receives their own unique signing link by email, which expires.
  • When the link is opened, a one-time code is sent to the same email address and must be entered before signing.
  • The signer reviews the document, types or draws their name and confirms that they accept the contract.

The signer is therefore identified by having access to the email address to which the signature request was sent. The service does not verify the signer’s identity against an official source.

What is recorded

The service records the signing events (opening the link, sending and confirming the one-time code, signing or declining) with timestamps, together with the IP address and browser identifier of each event. A SHA-256 hash is calculated from the original document so that it can later be shown that the signed document is the same as the one sent for signature.

The completed contract and the electronic seal

When all parties have signed, a certificate page showing the parties, the signing times and the hashes is appended to the original document. The pages of the original document are not changed. The whole file is sealed with a PDF electronic seal (PAdES) using the certificate of the company that sent the signature request, and the completed contract is emailed to all parties.

The seal shows that the file has not been altered after sealing and that the seal was created with the key of that certificate. The seal does not prove the signers’ identity, and it is not a qualified electronic seal within the meaning of the eIDAS Regulation. If the company uses a certificate it created itself, a PDF reader may show the issuer of the seal as unknown, even though the integrity of the file can be checked. Timestamps are based on the clock of the service’s server; no qualified electronic time stamp is used.

Legal effect

Under Article 25(1) of the eIDAS Regulation, an electronic signature shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form or that it does not meet the requirements for qualified electronic signatures. In Finland, most contracts can be concluded in any form. The service is not suitable for legal acts for which the law sets specific formal requirements, such as the sale of real property or a will. The evidential value of a signature depends on the recorded verification data and the circumstances of the case.

Contracts imported into the archive

Contracts signed elsewhere, for example in the SignHero service, are stored in the archive as they are. Verification of their signatures relies on the records of the original service; this service does not add its own verification to them.

11. Changes to this notice

This notice is updated when the service or the law changes. The current version is always on this page, and its date is shown at the top.

© Nettiteeri Oy 2026

Business ID: 3331525-2

Privacy notice