Privacy Policy
Last updated: 27 August 2026
This page explains what personal data we collect, why we collect it, where it comes from, how long we keep it, and what you can do about it. We've tried to write it so it's easy to read. If anything is unclear, email valtteri.taube@ostracon.ai.
Did we contact you? Start here.
If you got a message from us on LinkedIn or by email and you're wondering why, here are the short answers.
Why did you contact me?
We think your company might benefit from our services. You have a role where you make or influence decisions about marketing, sales or AI, so we reached out to you at work.
Where did you get my details?
From your public LinkedIn profile, your company's website, and business information services that collect data from public sources. We only collect work-related information: your name, job title, employer, work email and LinkedIn profile.
How do I make it stop?
Reply "no thanks" to the message, or email valtteri.taube@ostracon.ai. We'll delete your data and put your email address on a block list so we don't contact you again. You don't need to give a reason.
The rest of this page has the full details.
Who is responsible for your data
Ai Agency Ostraconai Oy ("Ostracon")
Bulevardi 21, 00180 Helsinki, Finland
Business ID 3461802-8
Contact for anything about your data: Valtteri Taube, valtteri.taube@ostracon.ai
Why we use your data, and on what legal grounds
The law says we need a valid reason for everything we do with your data. We rely on three reasons:
- Legitimate interest means we have a real business reason, and we have checked that it doesn't outweigh your rights. This covers most of our sales and marketing.
- Consent means you said yes — for example by subscribing to our newsletter or accepting cookies. You can take it back at any time.
- Contract means we need the data to do the work you or your company has ordered from us.
| What we do | Legal ground |
|---|---|
| Find companies and decision-makers who might need our services | Legitimate interest |
| Contact you at work on LinkedIn or by email | Legitimate interest |
| Keep a record of how you've interacted with us (website, newsletter, LinkedIn), so we know whether and when it makes sense to get in touch | Legitimate interest |
| Keep in touch with clients and manage our work together | Contract, legitimate interest |
| Send you our newsletter | Consent |
| See whether you open the newsletter and what you click | Legitimate interest |
| Answer messages sent through our website contact form | Legitimate interest |
| Understand which companies visit our website | Consent (cookie banner) |
| Improve our website | Consent (cookie banner) |
| Keep notes from meetings with you | Legitimate interest |
We don't sell or rent your data to anyone.
What data we collect
We only collect information about you in your professional role. We don't collect information about your private life. We never collect sensitive data such as health, religion, political opinions or union membership.
Basic work details
- Name
- Job title and employer, and changes to them (for example when you change jobs)
- Work email address, and whether it's still valid
- Work phone number, if we need it to reach you
- Your LinkedIn profile address, and the location and current roles shown on your profile
- Information about the company you work for: industry, size, revenue, business ID, website
How you've interacted with us
- Visits to ostracon.ai: which pages, how many times, how long, and where you came from. We mainly identify the company, not the person. Only if you accept cookies.
- Newsletter opens and link clicks, if you're a subscriber
- Reactions and comments on Ostracon's LinkedIn posts
- Messages we've sent you and your replies
- Public news and buying signals about your company (for example a new funding round or a new hire)
Meeting notes
- A short summary of meetings we've had with you, and a link to the transcript. Our meeting assistant joins our video calls and tells everyone that the meeting is being recorded and transcribed. If you'd rather not be recorded, just say so and we'll remove it from the call.
Things we work out ourselves
- Whether you fit the type of customer we work with, and why or why not
- Where we originally found your details
Where the data comes from
- Your public LinkedIn profile — name, title, employer, location and current roles. Nothing else from your profile is saved.
- Business information services that gather data from public sources: the Finnish Trade Register, financial statements, company websites, news and job postings.
- Contact data services that provide work email addresses and phone numbers from public and professional sources.
- Our own website, if you've accepted cookies.
- Our newsletter tool, if you're a subscriber.
- LinkedIn, when you react to or comment on our posts.
- Meetings you've had with us.
- You, when you email us, fill in our contact form or talk to us.
Who else sees your data
Our team. Only the people at Ostracon who need the data for their work.
Service providers. We use other companies' tools to run our sales and marketing. They handle data only on our instructions and under a written contract. The types of tools we use:
- Business information and contact data services
- An email validity checker
- A LinkedIn messaging tool
- A newsletter tool
- A website visitor identification tool
- A meeting recording and transcription tool
- Our database and our customer relationship system (CRM)
- Our internal chat tool
- An AI model that runs the steps of our sales system and drafts suggestions for our team. The AI provider doesn't train its models on your data and keeps it for at most 30 days.
If you'd like to know exactly which companies these are, email us and we'll tell you.
Authorities, if the law requires it.
Data outside the EU
Our main database is in Frankfurt, Germany, inside the EU. Some of the tools we use are run by US companies. When data goes to the US, we rely on one of the two mechanisms the EU accepts: the EU–US Data Privacy Framework, or the European Commission's standard contractual clauses. The US tools are used for specific tasks, such as sending a message or transcribing a meeting, and they only get the data they need for that task. All data is encrypted on the way and in storage.
How long we keep your data
| Data | How long |
|---|---|
| Your details, if we haven't contacted you yet | 12 months from when we added you, then deleted |
| Your details, if we have contacted you | 24 months from the last contact or sign of interest, then deleted |
| Interaction history (website visits, newsletter opens, LinkedIn reactions) | 3 years from the event |
| Meeting summaries | 3 years from the meeting |
| Newsletter subscription | Until you unsubscribe |
| Client contact details and contract information | For as long as we work together, and afterwards for as long as bookkeeping law requires |
| Block list (only your email or LinkedIn address, and the date) | Kept permanently — this is what stops us from adding you back by accident |
If you ask us to delete your data, we do it right away.
Your rights
You have the right to:
- Know what data we have about you and get a copy of it.
- Correct anything that's wrong.
- Have your data deleted.
- Object to marketing. This is an absolute right: you don't need a reason, and we can't refuse. We stop contacting you and delete your data.
- Restrict how we use your data while something is being sorted out.
- Take your data with you in a machine-readable format, where our use of it is based on consent or a contract.
- Withdraw your consent at any time, for example by unsubscribing from the newsletter or changing your cookie settings. This doesn't affect what happened before you withdrew it.
- Complain to the authority. In Finland that's the Office of the Data Protection Ombudsman, tietosuoja.fi.
How to use your rights: email valtteri.taube@ostracon.ai. We'll reply within one month at the latest. We may need to check that you are who you say you are.
What happens when you object or ask for deletion: we delete your data from our database and CRM, and put your email or LinkedIn address on our block list. We check the block list before every new addition and every message, so you won't come back into our system.
How we protect your data
- Data is stored in the EU (Frankfurt), encrypted.
- Only our own system, using a secret key, can read the database. There's no public access and no browser access.
- Only the people at Ostracon who need the data have access.
- The system only makes changes that can be undone. Deleting or merging data always needs a person's approval.
- If a data breach ever happens, we report it to the Data Protection Ombudsman within 72 hours and tell you if it puts you at risk.
Cookies
We use cookies on ostracon.ai only if you accept them. You can see what we use and change your choices on our cookies page.
Changes to this page
We update this page when our tools or practices change. The date at the top tells you when it was last updated.
Contact
Ai Agency Ostraconai Oy
Bulevardi 21, 00180 Helsinki, Finland
Business ID 3461802-8
valtteri.taube@ostracon.ai