Privacy Policy
1. Controller Information
Lontive Oy acts as the data controller for personal data processed through its website and connected business systems.
Company website: www.lonteva.fi
Contact for privacy matters: info@lonteva.fi
2. What Data We Process
Depending on the service and integration, we may process:
- Basic contact details (name, email, company, phone).
- CRM-related business data (deal stage, owner, activity notes).
- LinkedIn account and organization data you authorize via OAuth.
- Email address and consent status submitted through marketing self-assessment tools, such as the delegation self-assessment.
- Technical logs required for service security and diagnostics.
3. Purposes and Legal Basis
We process personal data to provide and improve customer communication, CRM workflows, and automation services.
- Service delivery and customer relationship management.
- Operational security, auditing, and incident resolution.
- Business process automation based on your configuration.
4. Data Sources and Third Parties
Data may be received directly from users and integrated services such as HubSpot and LinkedIn, according to granted permissions.
We do not sell personal data. Data may be shared with service providers only as needed to deliver agreed services.
5. LinkedIn Community Management Integration
When an authorized administrator connects a LinkedIn organization Page to Lontive, we process LinkedIn organization information, Page posts, aggregate engagement, member comments and reactions, and the identifiers required to manage those interactions. We use this data only to provide Page management and aggregate Page analytics to authorized users associated with the relevant Page.
We do not use LinkedIn member data or derivatives for advertising, sales prospecting, lead creation, CRM enrichment, recruiting, audience building, account-based marketing, or mass messaging. We do not provide a public LinkedIn social feed and do not export, sell, distribute, or otherwise transfer LinkedIn member data to customers or other third parties.
We minimize the personal data requested and displayed. The current Community workflow does not require a commenter’s name, profile photo, headline, email address, phone number, or other contact information. If profile data for a member who has not authenticated into the application is temporarily received, it is removed within 24 hours. Member social activity, including comments and related metadata, is removed within 48 hours. Profile data for an authenticated organization is retained for no more than eight weeks, social content of that organization for no more than six months, and aggregate Page administration and reporting data for no more than one year. A shorter applicable limit takes precedence.
OAuth access and refresh tokens are stored server-side with access controls and are not exposed in application responses, logs, or monitoring views. Tokens and locally stored integration data are removed when access is revoked, the integration is disconnected, or a valid deletion request requires removal. Requests concerning access, deletion, revocation, or other privacy rights can be sent to info@lonteva.fi.
6. Delegation Self-Assessment Tool
The delegation self-assessment (lonteva.fi/vision/delegoinnin-testi/) lets a visitor complete a short quiz in the browser without registration. Completing the quiz itself does not require any personal data.
If a visitor chooses to receive their result by email, we process the email address provided, the consent given, and the self-assessment result (a friction profile and per-dimension scores, not linked to any other account or system). We use this data to send the requested result by email and, based on the same consent, to contact the visitor later about Vision Platform - for example once enough test responses have accumulated to share updated benchmark data.
Legal basis: consent (GDPR Article 6(1)(a)). Consent can be withdrawn at any time by contacting info@lonteva.fi; withdrawal does not affect the lawfulness of processing carried out before withdrawal. Submitted email addresses are stored outside the public web server directory, with access limited to authorized personnel, until consent is withdrawn or the data is no longer needed for the stated purpose.
7. Retention Period
Data is retained only for as long as necessary for the processing purpose, contractual obligations, and legal requirements.
8. Your Rights
You may have the right to request access, correction, restriction, deletion, and portability of your personal data, subject to applicable law.
To exercise your rights, contact us by email.
9. Security
We apply reasonable technical and organizational safeguards, including access controls and audit logging, to protect personal data.
10. Changes to This Policy
We may update this policy when services, integrations, or legal requirements change. The latest version is always published on this page.