Legal
Privacy Policy
Last updated: May 2025 · Lintu Investments Oy · Business ID 3359228-4
Lintu Investments Oy ("Lintu", "we", "us") is a Finnish company registered in Helsinki. This policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have under the General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (2018/1050).
1. Who we are (data controller)
GDPR Art. 4(7)
Data controller: Lintu Investments Oy, Helsinki, Finland, Business ID 3359228-4.
Contact for data protection matters: privacy@lintu.finance
We are not required to appoint a Data Protection Officer under Article 37 GDPR (we do not process data at large scale as a core activity), but your privacy contact above handles all data requests.
2. What data we collect
GDPR Art. 13
We collect only what is necessary to provide the service:
- Account data: username, password (hashed, never stored in plain text), account creation date, last login date.
- Personal information (PII): first name, last name, email address. Phone and address are optional and only stored if you provide them. All PII is encrypted at rest in a separate database table, keyed only by an anonymous client ID.
- Questionnaire responses: your answers to the 33-question investment profile questionnaire. These are stored with your anonymous client ID — not your name or email.
- Portfolio data: investment amount, risk tolerance, asset allocation, ETF holdings, and performance data. Stored with your anonymous client ID only.
- Technical data: IP address at login (for security), browser session tokens (deleted on logout).
- Consent records: the text you agreed to and when. Required by GDPR Article 7.
We do not collect: financial account numbers, payment card details, national identity numbers, health data, or data from third-party social networks.
3. Legal basis for processing
GDPR Art. 6
- Contract (Art. 6(1)(b)): account management, portfolio building, and delivering the analytics service you signed up for.
- Consent (Art. 6(1)(a)): sending you service emails if you opt in. You can withdraw consent at any time.
- Legitimate interest (Art. 6(1)(f)): security logging (login audit trail), fraud prevention, and service improvement using aggregated, anonymised data. We have conducted a balancing test — your interests do not override ours for these specific purposes.
- Legal obligation (Art. 6(1)(c)): retaining consent records and deletion audit logs as required by law.
4. How long we keep your data
GDPR Art. 5(1)(e)
- Account and PII: for as long as your account is active, plus 30 days after deletion to allow for recovery requests.
- Questionnaire responses: we keep the 3 most recent results. Older results are automatically deleted.
- Login audit logs: 3 years, then automatically purged.
- Active sessions: 8 hours (automatically expired). Expired session records purged after 30 days.
- Consent and deletion records: retained indefinitely — these are our legal records under GDPR Article 7 and Article 17.
5. Who we share your data with
GDPR Art. 13(1)(e)
We do not sell, rent, or share your personal data with third parties for their own purposes. We use the following data processors:
- Yahoo Finance (yfinance): we query public market price data. No personal data is sent to Yahoo Finance.
- Federal Reserve Economic Data (FRED): we query public macroeconomic series. No personal data is sent to FRED.
- Hosting infrastructure: if hosted on a cloud platform, a data processing agreement (DPA) is in place with the provider.
We may disclose data if required by Finnish law or a court order, and only to the extent legally required.
6. How we protect your data
Your PII is stored in a separate, encrypted database table accessible only via an anonymous client ID. Passwords are hashed using PBKDF2-SHA256 with 260,000 iterations and a unique random salt — they cannot be reversed. Sessions use HMAC-SHA256 signed tokens stored as httpOnly cookies, inaccessible to JavaScript. Login attempts are rate-limited to 5 per 15 minutes. All data transfers use HTTPS.
7. Your rights
GDPR Art. 15–22
You have the following rights. You can exercise them from your account settings page or by emailing privacy@lintu.finance. We respond within 30 days.
Right of access
Download a complete copy of everything we hold about you — your account data, questionnaire results, portfolio history, consent records, and login history (last 90 days).
Download my data →
Right to erasure
Delete your account and all associated data permanently. This includes your name, email, questionnaire answers, and all portfolio data. This cannot be undone.
Delete my account →
Right to rectification
Correct inaccurate personal data. Email us with the correction and we will update your records within 30 days.
Email a correction →
Right to lodge a complaint
If you believe we have mishandled your data, you can lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) at tietosuoja.fi.
tietosuoja.fi →
Right to restrict processing
Request that we stop processing your data while a dispute is resolved, without deleting it.
Request restriction →
Right to data portability
Receive your data in a structured, machine-readable JSON format suitable for transfer to another service.
Export as JSON →
8. Cookies
We use one strictly necessary cookie: session_token — an HMAC-signed session identifier, set as httpOnly and SameSite=Lax. It expires after 8 hours. We do not use tracking cookies, analytics cookies, or advertising cookies.
9. Changes to this policy
We will notify registered users by email of any material changes to this policy at least 30 days before they take effect. The date at the top of this page always reflects the most recent revision.
Contact
For any privacy question or to exercise your rights: privacy@lintu.finance · Lintu Investments Oy · Helsinki, Finland · Business ID 3359228-4