Software Privacy Policy
Updated 17 April 2025
Combined register description and notification document of Epic Invoicing Oy under sections 10 and 24 of the Finnish Personal Data Act (523/1999).
Data Controller
Epic Invoicing Oy
Email: support@eemel.com
Name of the Register
Customer register of Epic Invoicing Oy.
Purpose of the Register
Customer data is processed to operate the business software, deliver services, and manage and develop customer relationships. Such data may also be used to identify data subjects, manage risk, and fulfil obligations under law or instructions from authorities.
Data Subjects
A data subject (person or company) has, or has had, an existing or potential customer relationship with the controller, or a registration arising from a legal obligation.
Data Content
Basic user information, such as:
- Name
- Business ID
- Contact persons
- VAT registration status
- Email addresses
- Mobile phone numbers
- Product used
Other information received in connection with use of the service and information required to fulfil legal obligations.
Regular Disclosure of Data
Data may be disclosed to authorities to fulfil statutory rights of access. Otherwise, data is disclosed only with the data subject's consent or authorisation.
Sources of Personal Data
Data is collected from the data subject themselves, associations, companies, or public authority information systems.
Transfers Outside the EU/EEA
Data is not transferred outside the EEA, except where staff or third parties located outside the EEA need the data to provide the service. Where transfers occur, we ensure data protection complies with the law.
Principles of Register Protection
Use of the register is strictly instructed, and user identification and access rights are carefully controlled. Data is protected with appropriate measures.
Right of Access and How to Exercise It
Every data subject has the right to inspect their own data. Inspection is free of charge if more than one year has passed since the previous inspection. The request must be delivered to the controller by personally signed or verified document, or in person.
Correction of Data
The controller will correct incorrect, unnecessary, incomplete or outdated data at the data subject's request without undue delay.
