Privacy Policy

Last updated: 7 August 2026

1. Who is responsible for your data

Cipherworks Digital Security Agency Oy (“we”, “us”) is the controller of personal data processed through this website.

  • Business ID: 3563371-3
  • Address: Roomankatu 5, 00560 Helsinki, Finland
  • Email: contact (at) cipherpunks.fi
  • Telephone: +358 400 835744

This policy covers the website at cipherpunks.fi. The site operates under the cipherpunks.fi domain; the company behind it is Cipherworks Digital Security Agency Oy.

We have not appointed a Data Protection Officer. Our processing does not meet the thresholds in Article 37 of the GDPR that would require one.

2. What we collect, and why

a) Technical server logs

Our web server automatically records your IP address, browser user-agent string, the pages you request, and the date and time of each request. This happens for every visitor and cannot be disabled without taking the site offline.

  • Why: to operate the website, diagnose faults, and detect and investigate attacks against it.
  • Legal basis: our legitimate interest in keeping the service running and secure (Article 6(1)(f)).
  • Retention: access logs are kept for the current calendar month and the preceding month, then automatically deleted. In practice this means a maximum of approximately two months.

b) Information you send us

If you email or telephone us, we receive whatever you choose to tell us — typically your name, contact details, and the substance of your enquiry.

  • Why: to respond to you and, where relevant, to take steps toward a contract.
  • Legal basis: steps taken at your request prior to entering a contract (Article 6(1)(b)), and our legitimate interest in responding to business enquiries (Article 6(1)(f)).
  • Retention: enquiry correspondence is kept for 12 months, unless it leads to a contract, in which case it is retained for the period required by accounting and contractual obligations.

We operate no customer relationship management system and send no newsletters or marketing email.

3. What we do not do

  • No analytics. We use no analytics service of any kind. We do not measure, profile or track visitors.
  • No tracking or advertising cookies. None are set, by us or by anyone else.
  • No third-party scripts. No content loads from external services. Our typefaces are served from our own server, so no font provider ever receives your IP address.
  • No social media pixels or embeds. Links to external sites are ordinary links; nothing loads until you choose to click.

4. Cookies

This website sets no cookies for ordinary visitors.

Because we set no analytics, advertising or profiling cookies, no cookie consent banner is required. If other sites ask your permission to track you, this one does not need to, because it does not track you. You are welcome to verify this in your browser’s developer tools.

Cookies are set only when a member of our own staff signs in to the site’s administration area. Those are strictly necessary for authentication and are exempt from the consent requirement under the Finnish Act on Electronic Communications Services.

5. Who else can access your data

Our website and email are hosted by:

Planeetta Internet Oy
Firdonkatu 2 T 105, 00520 Helsinki, Finland

Planeetta processes personal data only on our instructions, as our processor under Article 28 of the GDPR. The processing terms form a binding annex to their general terms of service. Planeetta is part of the Loopia Group.

We use no other processors. We do not sell personal data and we do not share it for marketing purposes.

We may disclose data where we are legally required to do so, for example in response to a lawful request from an authority.

6. Transfers outside the EU/EEA

Our hosting and email are provided from Finland. We do not routinely transfer personal data outside the European Economic Area.

Our hosting provider reserves the right, under its terms of service, to transfer personal data outside the EEA where it uses safeguards required by the GDPR. Any such transfer would be made under those safeguards.

7. Your rights

Under the GDPR you may ask us to:

  • access the personal data we hold about you;
  • rectify it if it is inaccurate or incomplete;
  • erase it, where the conditions in Article 17 are met;
  • restrict how we process it;
  • port it to another controller, where Article 20 applies;
  • object to processing based on our legitimate interests, including on grounds relating to your particular situation.

To exercise any of these, email contact (at) cipherpunks.fi. We will respond within one month. We may ask you to confirm your identity first.

8. Complaints

If you believe we have handled your personal data unlawfully, you may lodge a complaint with the Finnish supervisory authority:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)

  • Street address: Lintulahdenkuja 4, 00530 Helsinki
  • Postal address: PL 800, 00531 Helsinki, Finland
  • Switchboard: +358 29 566 6700
  • Registry: +358 29 566 6768
  • Email: tietosuoja (at) om.fi
  • Online form: tietosuoja.fi

We would welcome the chance to address your concern first, but you are not required to contact us before contacting the authority.

9. Changes to this policy

If we change how we handle personal data we will update this page and revise the date above. Material changes will be described here rather than made silently.