Privacy Policy for VULLOT | Book Initial Consultation

Drafted: 1 December 2025 Updated: 1 December 2025

Privacy Policy in accordance with the EU General Data Protection Regulation (GDPR).

Data Controller m.u.i.t.u Ltd Business ID: 3471873-1 Registered Office: FI-00870 Helsinki, Finland.

Contact Person for the Registry Name: Tony Schildt Email: office@vullot.com

Name of Registry VULLOT Client Registry

Purpose and Legal Basis for Processing Personal Data The primary basis for processing personal data is the contract between the Client and VULLOT, the fulfilment of the assignment, and statutory obligations (such as the Accounting Act and the Act on the Statute of Limitations).

Personal data is processed for the following purposes: Management of the client relationship, service production, and communication. Invoicing, payment monitoring, and debt collection. Ensuring the data security of the service. Data is not used for direct marketing or profiling without the separate consent of the Client.

Data Content of the Registry We adhere to strict data minimisation. Only information necessary for the administrative client relationship is stored in the Client Registry. We do not store sensitive assignment data or investigation reports in this registry.

Data stored: Corporate Clients: Company name, Business ID, postal and billing address, contact person's name and contact details (phone, email). Private Clients: Name, contact details (phone, email), postal and billing address. Client Relationship Data: Order history, billing information, and payments.

Regular Sources of Information Information is primarily collected from the data subject themselves upon contact or ordering. Data (such as Business ID and address) may be verified and updated from public registry sources (e.g., the Finnish Business Information System YTJ, Population Information System) to ensure the accuracy of billing information.

Data Retention Period We retain data only for as long as is necessary: Invoicing: Retained for six (6) years from the end of the financial year (Accounting Act, Chapter 2, Section 10). Contract Data: Retained for three (3) years from the end of the client relationship due to liability for defects (Act on the Statute of Limitations). Other Communication: Deleted when there is no longer a basis for retention.

Disclosures and Transfers of Data VULLOT does not disclose data to outside parties for marketing purposes. Data may be transferred to third parties only in the following situations: Service Providers: We use trusted IT and financial administration partners who process data under a separate agreement (e.g., invoicing systems). Authorities: If required by law or official order. Data is processed primarily within the European Economic Area (EEA).

Principles of Registry Security The confidentiality of client data is the core of our operations. In managing the registry, we utilize technology and partners that meet financial industry standards.

Technical Security: Strong Encryption: All data transmission and storage are protected by standard encryption algorithms. Secure Cloud Environment: Systems are located in secure data centres monitored 24/7 by automatic alarm systems. Access Control: Access to the registry is restricted to personnel whose duties require it. Logging into the system requires Multi-Factor Authentication (MFA), utilizing biometric identifiers or rotating codes in addition to passwords. Event Logs: The system collects log data on user actions to prevent misuse and ensure traceability. Manual Material: Any potential paper material is kept in a locked space accessible only to relevant parties.

Cookies Our website uses only technically necessary cookies to ensure the functioning of the service. We do not use cookies for targeted advertising or third-party tracking without consent.

Rights of the Data Subject You have the right to inspect the data concerning yourself, demand the rectification of incorrect data, and request the deletion of data (taking into account statutory retention obligations). All requests regarding data protection must be addressed in writing to: office@vullot.com