Last updated 4 October 2026
This notice explains how personal data is processed on the Nettiteeri Oy website (nettiteeri.fi and nettiteeri.com) and in the electronic signature and contract archive service at sign.nettiteeri.fi. It is based on Articles 13 and 14 of the EU General Data Protection Regulation ((EU) 2016/679, “GDPR”) and the Finnish Data Protection Act (1050/2018).
Nettiteeri Oy is the controller for data about the use of the website, for enquiries sent to it and for the user accounts of the signing service (company employees who send signature requests and manage the contract archive).
The signing service is operated by Nettiteeri Oy. Several companies use it, each with its own contract archive. The controller for the personal data in a contract and its signature request is the company in whose name the request is sent and in whose archive the contract is stored. That company’s name is shown in the invitation email, on the signing page and on the certificate page of the completed contract.
Where the controller is a company other than Nettiteeri Oy, Nettiteeri Oy processes the data on that company’s behalf and on its instructions as a processor (Article 28 GDPR). Requests about such a contract are best sent directly to that company; Nettiteeri Oy forwards any requests it receives to the right controller.
Companies using the service: Nettiteeri Oy (business ID 3331525-2) and [OPEN: other companies using the service – name, business ID and privacy contact].
A company uses the service to send a contract for electronic signature. Signers sign it through a personal link, and the completed contract is stored in the company’s archive and sent to all parties. Contracts signed elsewhere can also be stored in the archive.
The service does not collect personal identity codes. If the parties have written one into the contract document, it is processed only as part of the contract and within the limits of section 29 of the Finnish Data Protection Act.
The signer’s name and email address and the contract document are provided by the company sending the signature request, which has usually received them from the signer or the organisation the signer represents while preparing the contract. Identification and verification data is generated when the signer uses the signing link. Contracts signed elsewhere (for example, previously in the SignHero service) and their details are added to the archive by the company from its own records. User account data comes from the user and from the administrator who creates the account. No data is collected from public sources.
Invitations, one-time codes and completed contracts are sent by email in the name of the company acting as controller. Sending involves the recipient’s name, email address and the content of the message, which may have the completed contract attached. The legal basis and retention period are those of the processing the message relates to.
The website itself uses no cookies and no analytics or advertising tools. The Spotify players on the home page are loaded from Spotify’s servers only when you click the load button shown in place of the player. When a player loads, Spotify may store cookies on your device and receives data such as your IP address and browser details. Spotify processes this data as an independent controller under its own privacy policy.
Loading the players is based on your consent (section 205 of the Finnish Act on Electronic Communications Services 917/2014 and Article 6(1)(a) GDPR). Your choice is not stored: the players are loaded only for that page view, and you can withdraw your consent by reloading the page. Spotify cookies already stored on your device can be deleted in your browser settings.
The signing service (sign.nettiteeri.fi) uses only cookies that are strictly necessary for it to work, such as session and security cookies, which do not require consent (section 205(2)).
Data is not sold or disclosed for marketing.
Mailgun is a service of Mailgun Technologies, Inc., a US company in the Sinch group. If a company uses Mailgun’s US region, messages and delivery data are stored in the United States. In the EU region, too, data may be processed by the group’s US companies to provide the service. These transfers are based on the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914), which are part of Mailgun’s data processing agreement.
Spotify may transfer data outside the EU under its own privacy policy. Hosting: [OPEN: whether data is transferred outside the EU/EEA and on what basis].
Under the GDPR, you have the right to
Send your request to the controller (section 1). Requests about a contract are best sent to the company in whose name the signature request was sent. Requests are answered without undue delay and at the latest within one month (Article 12). Your identity may need to be verified before data is disclosed.
If you consider that the processing of your data infringes data protection law, you can lodge a complaint with the supervisory authority, which in Finland is the Data Protection Ombudsman (Article 77 GDPR, section 8 of the Data Protection Act):
Providing the data is not a statutory requirement. However, your name and email address are necessary for signing a contract in the service: without them, the invitation and the one-time code cannot be sent. If you do not want to sign electronically, you can agree on another way of signing with the company that sent the request. A service user account requires a name, an email address and two-factor authentication. Browsing the website requires no data from you.
Your data is not used for automated decision-making or profiling that would produce legal effects concerning you or similarly significantly affect you (Article 22).
A signature given in the service is an electronic signature within the meaning of Article 3(10) of the EU eIDAS Regulation ((EU) No 910/2014, as amended by Regulation (EU) 2024/1183), a so-called simple electronic signature. It is not an advanced or qualified electronic signature within the meaning of the Regulation, and it does not rely on strong electronic identification (such as online banking credentials or a mobile certificate).
The signer is therefore identified by having access to the email address to which the signature request was sent. The service does not verify the signer’s identity against an official source.
The service records the signing events (opening the link, sending and confirming the one-time code, signing or declining) with timestamps, together with the IP address and browser identifier of each event. A SHA-256 hash is calculated from the original document so that it can later be shown that the signed document is the same as the one sent for signature.
When all parties have signed, a certificate page showing the parties, the signing times and the hashes is appended to the original document. The pages of the original document are not changed. The whole file is sealed with a PDF electronic seal (PAdES) using the certificate of the company that sent the signature request, and the completed contract is emailed to all parties.
The seal shows that the file has not been altered after sealing and that the seal was created with the key of that certificate. The seal does not prove the signers’ identity, and it is not a qualified electronic seal within the meaning of the eIDAS Regulation. If the company uses a certificate it created itself, a PDF reader may show the issuer of the seal as unknown, even though the integrity of the file can be checked. Timestamps are based on the clock of the service’s server; no qualified electronic time stamp is used.
Under Article 25(1) of the eIDAS Regulation, an electronic signature shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form or that it does not meet the requirements for qualified electronic signatures. In Finland, most contracts can be concluded in any form. The service is not suitable for legal acts for which the law sets specific formal requirements, such as the sale of real property or a will. The evidential value of a signature depends on the recorded verification data and the circumstances of the case.
Contracts signed elsewhere, for example in the SignHero service, are stored in the archive as they are. Verification of their signatures relies on the records of the original service; this service does not add its own verification to them.
This notice is updated when the service or the law changes. The current version is always on this page, and its date is shown at the top.