Legal
Privacy
What we hold, where it is kept, who else touches it, and how long it stays. Written from how the system actually works, not from a template.
Last updated 29 August 2026
Who is responsible
Totalhost Oy, Y-tunnus 3630955-2, Espoo, Finland, is the controller for the personal data described on this page. For anything on this page, write to totalhost@totalhost.fi.
This website
This website sets no cookies and stores nothing in your browser. There is no consent banner because there is nothing here to consent to.
We do count visits — which pages get opened and how often — using Cloudflare Web Analytics. It works without cookies and without a device fingerprint, so it cannot follow you between sites and cannot identify you, and it is why no consent is required for it. That counter is the only request this site makes to anything outside this domain; the typefaces are served from here rather than from a font service, and there are no tracking pixels, no advertising tags and no social embeds.
The provider that serves the site also keeps ordinary request logs, including IP addresses, in order to deliver and protect it. Those logs are the provider's, are short-lived, and are not joined to anything else we hold.
What we hold when you are a client
Five kinds of thing, and nothing beyond them:
- You and your company. Name, email address, the form you operate in, your VAT status and filing period, and the addresses and identifiers of the properties you have us keep books for.
- The accounting material you send us. The receipt or invoice file itself, its filename, type, size and checksum, and the values read off it — date, total, VAT, counterparty — together with how confident that reading was.
- The books. Entries, periods, VAT figures, statements, per-property profit, and the invoices we send you.
- A record of who did what. Which action, on which record, by whom, when, and from which IP address. It records which fields changed, never the values they changed to or from.
- Identification records. A bookkeeping service is required by law to identify its clients. That means how and when you were identified, the same for anyone acting on your behalf, the beneficial owners of your company — name, role, date of birth, ownership share — the dates and outcomes of politically-exposed-person and sanctions checks, and a risk assessment with its reasoning.
We do not collect data about your guests, and we do not connect to your booking accounts.
Why we hold it
- To do the work you engaged us for — keeping your books, producing your figures, invoicing you. Legal basis: our contract with you.
- Because the law requires it — the Finnish Accounting Act for the material and the books, the VAT Act for the figures, and the Act on Preventing Money Laundering and Terrorist Financing for the identification records. Legal basis: legal obligation.
- To keep the service secure and its history honest — the audit record and the access controls. Legal basis: our legitimate interest in a bookkeeping system that can be trusted and audited.
We do not sell data, we do not share it for advertising, and nothing here is used to make automated decisions about you.
Where it is kept, and who else touches it
The service runs in the European Union. Three processors are involved, each for one job:
- Amazon Web Services — the application, the database, the stored receipt files, the address your receipts are emailed to, and sign-in. Frankfurt, Germany (eu-central-1).
- Microsoft Azure Document Intelligence — reads the text and figures off a receipt file so that a bookkeeper has something to check. The file is sent, read, and the result returned. EU region.
- Cloudflare — serves this website. It carries these public pages only; no client data passes through it.
Client data is not transferred outside the EU/EEA. If that ever has to change, this page changes first.
How long it stays
Accounting material and the books are kept for the periods the Accounting Act sets: six years from the end of the year in which the accounting period ended for vouchers and receipts, and ten years for financial statements and accounting records. Identification records are kept for five years after the client relationship ends, as the money laundering act requires. Database backups are held for fourteen days and then overwritten.
One consequence is worth stating plainly: the ledger is append-only and receipts are never deleted. A correction is a reversing entry, not an edit; a receipt we decline is marked rejected and the file stays. That is what makes the books auditable, and it means we cannot erase financial records on request while their retention period runs. Data that is not part of the accounting record can be corrected or removed in the ordinary way.
Your rights
You can ask what we hold about you and get a copy; have inaccurate details corrected; ask for data to be erased or its use restricted, within the limits the retention rules above impose; object to processing we base on legitimate interest; and receive the data you gave us in a portable form.
Write to totalhost@totalhost.fi and we will answer within a month. If you think we have handled your data wrongly you can complain to the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi) — though we would rather you told us first.
Changes to this page
If what we do with data changes, this page is updated before the change takes effect, and the date at the top changes with it. Clients are told directly about anything that materially affects them.