---
title: "Privacy Policy"
product: "Delivery Zone"
version: "1.4"
last_updated: "2026-08-02"
effective_date: "2026-08-02"
status: "current"
frontend_route: "/legal/privacy"
regulation: "GDPR (EU 2016/679), Finnish Data Protection Act (1050/2018)"
---
Privacy Policy — Delivery Zone
Version: 1.4
Last updated: 2026-08-02
Effective date: 2026-08-02
---
1. Who Is Responsible for Your Data (Data Controller)
GN-Projects Solutions Oy (Business ID: 3636596-8, Niittumäentie 13, 04350 Nahkela, Finland)
("Delivery Zone", "we", "us") is the data controller for personal data collected when you
use the Delivery Zone service.
Contact for privacy matters: [email protected]
---
2. What Data We Collect
We collect the following categories of personal data:
2.1 Account Data
Email address, display name, a securely hashed password (plaintext never stored), email
verification status and timestamp, MFA status and enablement timestamp.
2.2 Organisation Data
Organisation name and your role within it (e.g., Owner, Member).
2.3 API Usage Logs
For each API request: the postcode queried, timestamp, HTTP response status, organisation ID,
and API key prefix (not the secret). We do not log end-consumer names, full addresses, or
payment data submitted by your end customers.
API usage logs are used for billing, security, rate limiting, troubleshooting, and abuse
prevention, including detection of prohibited bulk extraction or dataset reconstruction. They
are not used to create marketing profiles of your end customers.
2.4 Billing Data
Subscription plan and status, Mollie customer ID. Payment card details are processed and
stored exclusively by Mollie and are never stored on our servers.
2.5 Security and Audit Data
A one-way SHA-256 hash of the IP address at account registration (for fraud prevention and
terms-acceptance audit). Timestamps for login events, token issuance and revocation events,
email verification events, and MFA activation events. Raw IP addresses associated with login
and refresh-token operations may be stored in security records for token protection, fraud
prevention, and audit purposes, and are retained according to the Security / audit logs
retention period in Section 5. This data is used for fraud prevention, abuse detection, and
security audit purposes.
2.6 Communication Data
Content of emails or support messages you send to us.
2.7 Authentication Cookies
HttpOnly, Secure session cookies (dz_access, dz_refresh) used solely for authentication.
See our Cookie Policy.
2.8 Business-Access-Request Data
If you submit a business-access request or business/partnership opportunity through our public
request form (for example, because your organisation is established outside the EU, or because
automatic EU business verification could not be completed), we collect: your company's legal
name, business registration number, tax/VAT/GST number where provided, registered address where
provided, company website where provided; your name, role, business email address, and telephone
number where provided; a description of your intended use of the service; optional estimates of
expected usage volume, number of organisations or locations, and estimated commercial value; and
any free-text message you provide. We also record the outcome of our internal review, including
business-verification evidence and sanctions/tax/insurance/payment-provider/contract review
status, and the specific messages we send you about your request.
Some notes we record while reviewing your request are for our own internal use and are never
shared with you; we only share the specific messages we choose to send you directly (for example,
a request for more information about your business).
This data is used solely to review and respond to your request, to verify your business, and — if
we approve onboarding — to activate and administer the resulting account. Submitting a request
does not create a customer relationship, a contract, or checkout access, and does not add you to
any marketing list; we do not use this data for marketing unless you separately opt in.
---
3. Why We Process Your Data — Legal Bases (GDPR Article 6)
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Providing the service, managing your account and subscription | Contract performance (Art. 6(1)(b)) | Necessary to perform the service you signed up for |
| Billing and payment | Contract performance (Art. 6(1)(b)) | Required to operate the subscription |
| Security monitoring, fraud prevention, rate limiting | Legitimate interests (Art. 6(1)(f)) | Our legitimate interest in protecting the platform and our customers |
| Audit logging of API usage | Legitimate interests (Art. 6(1)(f)) | Billing accuracy, dispute resolution, and abuse prevention |
| Reviewing business-access requests, including business verification and sanctions/tax/insurance/payment/contract review | Legitimate interests (Art. 6(1)(f)); pre-contractual steps taken at your request (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) where sanctions-law compliance requires it | Deciding whether we can offer the service to a specific business before any account or contract exists |
| Retaining billing records | Legal obligation (Art. 6(1)(c)) | Finnish Accounting Act (Kirjanpitolaki 1336/1997) requires 7-year retention |
| Sending transactional emails (verification, billing alerts) | Contract performance (Art. 6(1)(b)) | Necessary to deliver the service |
| Authentication cookies | Strictly necessary (ePrivacy Directive) | No consent required for authentication-only cookies |
| Optional product newsletters or announcements | Consent (Art. 6(1)(a)) | Only where you have opted in; withdrawable at any time |
We rely on legitimate interests only where our interests are not overridden by your fundamental
rights. We have assessed this balance internally. You have the right to object (see Section 6).
---
4. Who We Share Data With
We do not sell your personal data. We share data with:
- Cloudflare and Scaleway SAS — our sub-processors, engaged to operate the service
(application hosting, CDN, edge security, database hosting, key management, and
transactional email delivery). Full details are in our
- Mollie B.V. — for payment processing, subscription management, and invoicing. For
payment processing carried out under Mollie's merchant terms, Mollie generally acts as an
independent controller of your payment data, not as our processor — Mollie is
responsible for its own processing of that data under its own privacy notice.
Business-access-request and business-opportunity data (Section 2.8) is processed using the same
sub-processors listed above and is reviewed internally by designated Delivery Zone platform
administrators. We do not share it with any additional external recipient.
We may disclose personal data to law enforcement agencies, regulatory authorities, or courts if
required by Finnish or EU law, or in response to a valid legal order. We will notify you of
such requests where legally permitted to do so.
We do not transfer your personal data to any country outside the EU/EEA except as described in
Section 8 below.
---
5. Data Retention
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data | While your account is active. Self-service account deletion is processed immediately (see below), except for the records listed below that we retain for longer. | Service delivery and dispute resolution |
| API usage logs | Up to 12 months, automatically purged on a monthly schedule | Billing, security, and abuse investigation |
| Security / audit logs | Up to 12 months, automatically purged on a monthly schedule | Fraud prevention and security monitoring |
| Billing records, invoices, credit notes, and billing profile history | At least 7 years from transaction date; we do not currently operate an automated deletion ceiling for these records | Finnish Accounting Act legal obligation and payment-reconciliation integrity |
| Payment-provider (Mollie) identifiers and webhook/payment event records | Retained indefinitely; required to reliably reconcile subscription and payment state | Billing accuracy and fraud prevention |
| Terms-acceptance evidence (version and timestamp) | Retained indefinitely, including after account deletion; the originating IP address is erased on account deletion | Legal/compliance evidence of contract formation — not GDPR consent |
| Email verification / MFA tokens | Until used or expired; used or expired tokens are not separately purged and are removed only if the account itself is deleted | Security hygiene |
| Communication data (support emails) | Up to 3 years, to the extent handled within tools covered by this policy | Dispute resolution |
| Business-access-request or business-opportunity submissions that are never verified by email | Automatically marked "expired" 7 days after submission if the verification email is not confirmed; the request record and its review history are kept for audit and duplicate-request detection | Anti-abuse, audit, and duplicate-request detection |
| Business-access-request or business-opportunity submissions that are rejected, withdrawn, expired, or closed | Personal contact details (contact name, email, phone, registered address, website, and any free-text message) are automatically removed 18 months after the request was last updated. The business's legal name and registration number are kept (not personal data) for duplicate-request detection, and the review/audit trail is preserved. | Data minimisation, balanced against duplicate-detection and audit needs |
| Business-access requests with an approved onboarding decision that is later revoked | Retained in full, including contact details, without automatic minimisation. Data belonging to an approved, active organisation is retained as part of that organisation's account data (see above) for as long as the account remains active. | Compliance, sanctions, and audit evidence for a business relationship that was formally approved |
These business-access-request retention periods were verified against the current
retention-purge implementation on 2026-08-02
(api/workers/api/src/services/retention.ts — the businessAccessRequestUnverifiedExpiryDays
(7-day) and businessAccessRequestTerminalMinimisationDays (548-day / 18-month) categories,
run on the same scheduled job as the other retention categories in this table).
You can delete your account through the dashboard settings (Settings → Danger Zone → Delete account). You can also submit a deletion request by contacting [email protected]. Self-service deletion via the dashboard is processed immediately: it disables account access, revokes API keys, and deletes or anonymises delivery zones, postcode rules, and personal account information. Email-based requests are processed within 30 days.
Billing records, invoices, credit notes, billing profile history, payment-provider identifiers, and terms-acceptance version/timestamp evidence are retained after account deletion as described in the table above and are not immediately erased.
---
6. Your Rights Under GDPR (Chapter III)
As a data subject, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17): Request deletion of your data,
subject to legal retention obligations.
- Right to restriction of processing (Art. 18): Request that we limit how we process your
data in certain circumstances.
- Right to data portability (Art. 20): Receive your personal data in a structured,
machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests. We will
cease processing unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw
it at any time without affecting the lawfulness of prior processing.
- Right not to be subject to solely automated decisions (Art. 22): We do not make
significant decisions about you through solely automated means.
To exercise any of these rights, contact us at [email protected]. We will respond within
30 days (extendable to 90 days for complex requests with notice).
You also have the right to lodge a complaint with the Finnish supervisory authority:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
PO Box 800, FI-00521 Helsinki, Finland
https://tietosuoja.fi/en/home
---
7. Cookies and Session Tokens
We use HttpOnly, Secure cookies strictly for authentication session management. We do not use
third-party tracking, advertising, analytics, or social media cookies. Because we use only
strictly necessary cookies, EU cookie law (ePrivacy Directive) does not require a consent
banner, but we explain our use transparently.
See our Cookie Policy for the full list of cookies used.
---
8. Data Transfers Outside the EU/EEA
We aim to store and process all personal data within the EU/EEA. Where a sub-processor
operates globally or processes personal data outside the EU/EEA, we rely on appropriate
transfer safeguards, such as adequacy decisions, the EU-U.S. Data Privacy Framework where
applicable, and/or Standard Contractual Clauses approved by the European Commission.
See the Subprocessors list for details on each provider.
---
9. Customer Data Processed via the API (B2B — Controller / Processor)
If you are a business customer using the Delivery Zone API to check delivery availability for
your end customers, you are the data controller for any personal data of your end customers
(e.g., delivery addresses linked to identifiable persons) that passes through our API.
Delivery Zone acts as a data processor in that context.
A Data Processing Agreement (DPA) is incorporated by reference into our Terms of Service. It is
available to read at /legal/dpa. If you require a countersigned copy, contact
---
10. Postcode Reference Data
Postcode and geographic reference data used by the service is licensed from a third-party
Finnish postcode data provider. This reference data is used solely for delivery zone
calculations within the Delivery Zone service and is not redistributed.
We are not the official Finnish postcode authority (Posti Group Oyj).
---
11. Security
We use reasonable technical and organisational measures to protect your personal data, including:
encrypted connections (TLS 1.2+), securely hashed passwords, securely hashed API key secrets,
HttpOnly/Secure authentication cookies, role-based access controls, and structured security
logging. See our Security Policy for more information.
---
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of
material changes by email at least 14 days before changes take effect. The current version
and effective date are always shown at the top of this document and at /legal/privacy.
---
13. Contact
Privacy enquiries and data subject requests: [email protected]
General legal matters: [email protected]