Your counter, your data. Always.
What we collect, why we collect it, who we share it with and how you get it back. Written in plain English first, then in the version the Data Protection Ombudsman would ask for.
Summary
We host your data in the European Union. We use it to run the till, seal the record, work out the VAT and hand the result back to you and your accountant. We do not sell personal data, we do not buy contact lists, and we do not run advertising trackers. You can export everything and leave whenever you like.
Fizzy handles two very different kinds of data: the personal data of the people who visit our site and buy from us, and the sales data of businesses that run Fizzy on their counters. We are responsible for the first. For the second, our customer decides what happens and we act on their instructions. This policy explains both.
Who we are
Fizzy is a product of Fidanet Solution Oy, business ID 3497432-1, registered at Marinkallio 6b, 02320 Espoo, Finland. For questions about this policy or about your personal data, write to legal@fizzy.fi.
Our two roles
- Controller. For our website, marketing, sales conversations, support correspondence, recruitment and billing, we decide why and how personal data is processed.
- Processor. For the data inside a customer's Fizzy account, including their sales records, staff accounts and customer information, the customer is the controller. We process it on their documented instructions under a Data Processing Agreement. If you are a shopper or an employee of a Fizzy customer, address your request to that business first, and we will support them in answering it.
What we collect
Contact and business details
Name, email address, phone number, company name and business ID, and what you told us about your operation.
Correspondence
Demo requests, support messages, and the notes we keep so the next conversation does not start from zero.
Contract and billing data
Plan, invoices, payment status, and the records accounting law requires us to keep.
Website usage
Basic technical data such as IP address, browser and pages viewed, kept minimal on purpose. See the Cookie Policy.
Recruitment data
If you apply to us: your application, CV and our notes on it.
We do not buy contact lists, we do not sell personal data, and we do not run advertising trackers on this site.
Why we process it
- To answer you and run a demo, on the basis of steps taken at your request before entering a contract.
- To provide and support the service and invoice for it, on the basis of performing our contract with you.
- To keep our own books and meet tax and accounting obligations, on the basis of legal obligation.
- To secure the service, investigate abuse, and improve the product, on the basis of our legitimate interest in running a safe and functioning platform.
- To send product updates or occasional relevant messages to business contacts, on the basis of legitimate interest, with an unsubscribe link in every message and consent used where the law requires it.
Sales data inside the product
A sealed sale in Fizzy is primarily commercial data: items, amounts, VAT, tender and timing. It also carries the staff identity of the person who made the entry, which is precisely what makes the record auditable. Because the ledger is append-only by design, entries cannot be edited or deleted without destroying the audit trail our customers are legally required to keep. Corrections are appended instead. Deletion requests that would break a statutory sales record are handled by the customer as controller, within what tax and accounting law permits.
AI and model training
Ask Fizzy answers from your own sealed ledger using curated, versioned rules. Your sales data is not used to train a general model, and it is never pooled with another customer's data. Every figure the assistant returns traces back to a rule and the rows behind it.
Sharing and sub-processors
We keep the list of third parties short. In categories, they are: cloud hosting and backup, payment processing through Worldline, email and messaging delivery, error monitoring, and our own accounting provider. Each is bound by a written agreement and processes data only on our instructions. The current, named sub-processor list is maintained for customers and is available on request through the Trust Center or from legal@fizzy.fi. Customers under a DPA are told before a sub-processor changes.
We also disclose data where a law, a court, or a tax authority requires it. We do not hand over customer data on an informal request.
International transfers
Fizzy is hosted in the European Union, and customer data stays in the EU in normal operation. Each tenant is isolated from every other. If a transfer outside the EEA ever becomes necessary, it will be covered by an appropriate transfer mechanism such as the European Commission's standard contractual clauses, and customers under a DPA will be informed.
Retention
- Enquiries that go nowhere: deleted within a reasonable period once it is clear there is no interest.
- Customer relationship data: for the life of the contract, then for as long as claims can still be made.
- Accounting and tax records: for the statutory retention period, which in the Nordic countries generally runs several years from the end of the financial year.
- Sales data in a customer account: for as long as the customer keeps it and the law requires them to. On termination, the customer gets an export and, after the agreed window, the data is deleted.
- Recruitment data: for the duration of the process, and longer only with the candidate's agreement.
Your rights
Under the GDPR you can ask us for access to your personal data, correction of it, erasure, restriction of processing, portability, and you can object to processing based on legitimate interest. You can withdraw consent at any time where processing rests on consent. Write to legal@fizzy.fi and we will answer within one month.
If you believe we have handled your data badly, tell us first, we would rather fix it. You also have the right to complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, Lintulahdenkuja 4, 00530 Helsinki, tietosuoja.fi), or to the supervisory authority in your own country.
Security
Encryption in transit, access limited to the people who need it, tenant isolation, and an append-only ledger that makes silent alteration impossible rather than merely discouraged. Card data is handled by Worldline and does not touch our servers or your device. The Trust Center describes the security model in more detail.
Cookies and tracking
We use a small number of strictly necessary cookies to keep you signed in, remember your language and theme, and protect against cross-site request forgery. We do not place advertising or cross-site tracking pixels. Every cookie is named and explained on the Cookie Policy page.
Children
Fizzy is a tool for businesses and the people who work in them. We do not knowingly process the personal data of children under 16. If you believe we have, write to us and we will delete it.
Changes to this policy
When this policy changes materially, we update the date in the rail and tell customers before the change takes effect. Older versions are available on request.
Contact and complaints
Fidanet Solution Oy · Marinkallio 6b, 02320 Espoo, Finland · legal@fizzy.fi
We aim to write our legal documents in language a shop owner can read without a lawyer. If something here is unclear, tell us and we will rewrite it. That is part of the job, not a favour.