Website use
We may process the country code supplied with the request, browser language, requested page and limited technical request data needed to deliver and protect the service. A language you select is stored locally in your browser.
GDPR · Retroo Company
This policy explains how GG Ventures Oy processes personal data on the Retroo Company website, in commercial enquiries, email correspondence, recruitment and the protected investor portal. Last updated: 28 August 2026.
Controller
GG Ventures Oy, operating under the Retroo Company brand, is the controller of the personal data described in this policy.
Personal data
We may process the country code supplied with the request, browser language, requested page and limited technical request data needed to deliver and protect the service. A language you select is stored locally in your browser.
We process the name, company, email, telephone number, country, city, planned investment range, experience, preferred contact method, message, language and consent record submitted in the form.
When you email us, we process your contact details, correspondence and any documents or other information you choose to send. The event form first prepares a message in your own email application and does not send its contents to the website server before you send the email.
For authorised users, we may process name, email, username, role, location permissions, login timestamps, authentication and session records, support messages, uploaded documents and audit records. Passwords are not stored in readable form; hashes and salts are used.
Purposes and legal bases
Investment-enquiry data is processed on the basis of the consent given with the form, which you may withdraw by contacting us. Business, event and recruitment communications may be processed to take steps at your request before entering into a contract; communications with company representatives and service security may also rely on legitimate interests. Portal data is processed to provide the requested portal service and for legitimate interests in secure access and business administration. Data may also be processed where necessary to comply with a legal obligation.
Sources and recipients
We normally receive data directly from you. Portal account and access information may also be supplied by an authorised company administrator or arise from the relevant business, investment or contractual relationship. Technical security information is generated when the website or portal is used.
Personal data may be accessed, to the extent required for their tasks, by authorised GG Ventures Oy employees and administrators; hosting, cloud-storage, security, information-technology and email providers; authorised portal users within their assigned location and permissions; necessary professional advisers; and public authorities where disclosure is required by law. We do not sell personal data.
International transfers
Our service providers may process data in countries where they operate. If personal data is transferred outside the European Economic Area, an adequacy decision, the European Commission's standard contractual clauses or another lawful transfer mechanism and any required supplementary safeguards are used as applicable. You may request information about the relevant safeguard using the contact details above.
Retention
Investment enquiries are retained for evaluation and necessary follow-up and are deleted or anonymised when no longer needed unless another lawful reason requires retention. Business correspondence, event enquiries and recruitment materials are kept as long as needed to handle the matter and document the relationship or legal claims where reasonably necessary. Portal account and operational data is retained while the account, access right or related business purpose remains active and thereafter only for an applicable legal, security or claims-related period. Uploaded documents follow the retention requirements of the underlying document or relationship.
The portal authentication cookie has a maximum lifetime of 12 hours, and the server rejects the session after 30 minutes of inactivity. Language preference remains in the browser until changed or removed with site data. Rate-limiting records cease to be used after their configured security period and are removed during application cleanup.
Your rights
To exercise a right, email info@retroocompany.com. We may need to verify your identity before completing the request.
Security and decisions
We use access controls, role- and location-based permissions, encrypted connections, secure session cookies, password hashing, request-size limits, rate limiting and audit records. No storage or transmission method can be guaranteed to be completely risk-free.
We do not use the data described in this policy for solely automated decisions that produce legal or similarly significant effects. Required form fields are needed to submit and answer the enquiry; without them the form cannot be submitted or we may be unable to respond.
External sites and changes
The site links to external services and public information sources. Those services receive information only when you follow the relevant link and operate under their own privacy and cookie policies. We may update this policy when services, processing activities or legal requirements change; the current version and date will be published on this page.