1 / Controller
Legit AI Oy ("Legit", "we") is the data controller for personal data processed via this website. Address: Fleminginkatu 10, 00530 Helsinki, Finland. Privacy contact: privacy@wearelegit.ai (or aku@wearelegit.ai).
2 / What we collect
We process only the personal data you actively provide — typically your name, email address, and the content of any message you send via email or our contact form. We do not buy, sell, or share your data with third parties for marketing.
3 / Hosting and processors
This site is hosted on Vercel using infrastructure located in the European Union. We rely on a small set of operational processors:
- Vercel Inc. — hosting (EU region)
- Google Workspace — corporate email and document collaboration
- LinkedIn — public profile presence (no data exchanged from this site)
We do not run third-party advertising or tracking cookies on this site.
4 / Cookies and browser storage
This site uses a small amount of browser storage strictly necessary for functionality — for example, remembering your language and your selection on the human/agent gate. No analytics, advertising, or tracking cookies are loaded. Strictly necessary storage does not require consent under the ePrivacy Directive; the on-site notice is informational.
5 / Legal basis (GDPR)
- Legitimate interest (Art. 6(1)(f)) — replying to inquiries and operating the site.
- Consent (Art. 6(1)(a)) — any optional communications you opt into.
- Contract (Art. 6(1)(b)) — where processing is necessary to deliver a service to you.
6 / Retention
Inquiry data is kept for as long as needed to handle the conversation and reasonable follow-up, and is deleted on request or after a reasonable period. Backups follow our providers' standard retention schedules.
7 / Your rights
Under the GDPR you have the right to access, rectify, restrict, object to, and request deletion of your personal data, as well as the right to data portability. To exercise these rights, email privacy@wearelegit.ai. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuojavaltuutettu.fi).
8 / International transfers
Where a processor we rely on accesses data from outside the EEA, the transfer is governed by EU Standard Contractual Clauses or equivalent safeguards.
9 / Changes
We may update this policy occasionally. The "last updated" date above reflects the most recent revision.