LAST UPDATED: 2026-09-01 · EFFECTIVE: 2026-09-01
What personal data NorthPoint collects when you use this site, the contact form or the free compliance checks — who processes it, how long we keep it, and your rights under the GDPR.
NorthPoint Marketing Solutions Oy. Lapinlahdenkatu 16, 00180 Helsinki, Finland. VAT FI34987341. Contact for all privacy matters: hello@northpoint.fi.
Contact form. Your name, email, chosen topic and message, plus the plan you clicked through from. Relayed to our inbox by EmailJS and handled as business correspondence — no account is created, and nothing is added to a marketing list.
Free check pages. The eleven public tools (MiCA, GDPR, FCA, EAA, SEC, MAS, VARA, TGE readiness, Ad Creative, Non-EEA marketing, AEO visibility) run in your browser or via a server-side fetch. Your IP is processed transiently for rate-limiting only; the counter expires at the end of its window and the IP is not kept beyond it. Submitted text is not stored. Where a tool accepts a URL, our server fetches that page once to run the check and retains nothing from it.
Billing (plan clients). Payment information for Fractional CMO plans is handled entirely by Stripe; we never see or store card details. We receive the billing email, Stripe customer ID and payment status.
Analytics. Google Analytics 4 runs on public marketing pages, collecting aggregate traffic data — pages viewed, device class, rough region. We never send it names, emails or message contents; GA4 identifiers and IP handling follow Google’s processing terms.
Under GDPR Article 6: contract performance and pre-contractual steps for plan clients and for answering your enquiry (Art. 6(1)(b)); legitimate interest for IP-level rate-limiting on the free tools (preventing abuse of a free public service) and for aggregate traffic measurement (Art. 6(1)(f)); legal obligation for accounting records (Art. 6(1)(c)); consent for any marketing email you actively opt in to receive (Art. 6(1)(a)).
A short list of sub-processors, each under its own GDPR-compliant terms. Transfers outside the EEA rely on standard contractual clauses or an adequacy decision.
We never share, sell, rent or trade your data for marketing. There is no marketing list.
Under GDPR you may access the personal data we hold about you, have it corrected or deleted, receive it in a portable format, restrict our processing, or object to it. Email hello@northpoint.fi with “GDPR request” in the subject line. We respond within 30 days.
You may also complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) at tietosuoja.fi.
Google Analytics 4 cookies — public marketing pages only, for aggregate traffic measurement. Opt out using the methods above.
np_session — HttpOnly cookie set only if you sign in to the legacy client portal. Expires after 30 days. Strictly necessary; never set on a public marketing page.
Material changes are emailed to active clients, and the revised notice is posted here with a new “Last updated” date.
Questions: hello@northpoint.fi