Privacy notice.

LAST UPDATED: 2026-10-02 · EFFECTIVE: 2026-10-02

What personal data NorthPoint collects when you use this site, its forms or the free compliance checks — who processes it, how long we keep it, and your rights under the GDPR.

Who we are.

NorthPoint Marketing Solutions Oy. Lapinlahdenkatu 16, 00180 Helsinki, Finland. VAT FI34987341. Contact for all privacy matters: hello@northpoint.fi.

What we collect.

Contact form. Your name, email, chosen topic and message, plus the plan you clicked through from and how you first reached the site (source, campaign, landing page). Relayed to our inbox by Resend and handled as business correspondence — no account is created, and nothing is added to a marketing list. Your name, email and topic (never the message) are also kept in our site database for 90 days and copied into our own lead records. A confirmation email goes out only if you pass the Cloudflare bot check, and at most once per address in 24 hours (we hold the address that long to enforce it).

Other forms. The partner form (name, email, enquiry type, message) is relayed to our inbox by Resend and not stored. The Teardown request (site address, company, email, notes) and the report’s benchmark-read request (email, company site) are relayed the same way, kept in our site database for 90 days and copied into our own lead records. None of these emails you automatically.

Abuse logs. Each form submission writes one line (IP address, rough location, browser, referring page and, except on the Teardown form, your email) to our Vercel hosting logs, read only to investigate abuse. Your IP also counts toward an hourly submission limit.

Free check pages. The eleven public tools (MiCA, GDPR, FCA, EAA, SEC, MAS, VARA, TGE readiness, Ad Creative, Non-EEA marketing, AEO visibility) run in your browser or via a server-side fetch. Your IP is processed transiently for rate-limiting only; the counter expires at the end of its window and the IP is not kept beyond it. Pasted text is not stored. Where a tool accepts a URL, our server fetches that page once to run the check and retains nothing from it. The lite-skill downloads on these pages ask for your email.

Live page scan. With your consent, the client portal’s scan keeps your email, the page’s domain and the verdict, and copies the email and domain into our own lead records.

Billing (plan clients). Payment information for Fractional CMO plans is handled entirely by Stripe; we never see or store card details. We receive the billing email, Stripe customer ID and payment status.

Analytics. Google Analytics 4 runs on public marketing pages, collecting aggregate traffic data — pages viewed, device class, rough region. We never send it names, emails or message contents; GA4 identifiers and IP handling follow Google’s processing terms.

Why we are allowed to process it.

Under GDPR Article 6: contract performance and pre-contractual steps for plan clients and for answering your enquiry (Art. 6(1)(b)); legitimate interest for IP-level rate-limiting and abuse checks on the free tools and forms (preventing abuse of a free public service) and for aggregate traffic measurement (Art. 6(1)(f)); legal obligation for accounting records (Art. 6(1)(c)); consent for any marketing email you actively opt in to receive (Art. 6(1)(a)).

Who else touches your data.

A short list of sub-processors, each under its own GDPR-compliant terms. Transfers outside the EEA rely on standard contractual clauses or an adequacy decision.

We never share, sell, rent or trade your data for marketing. There is no marketing list.

How long we keep it.

What you can ask us to do.

Under GDPR you may access the personal data we hold about you, have it corrected or deleted, receive it in a portable format, restrict our processing, or object to it. Email hello@northpoint.fi with “GDPR request” in the subject line. We respond within 30 days.

You may also complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) at tietosuoja.fi.

What we set in your browser.

Google Analytics 4 cookies — public marketing pages only, for aggregate traffic measurement. Opt out using the methods above.

np_session — HttpOnly cookie set only if you sign in to the legacy client portal. Expires after 30 days. Strictly necessary; never set on a public marketing page.

When this notice changes.

Material changes are emailed to active clients, and the revised notice is posted here with a new “Last updated” date.

Questions: hello@northpoint.fi