-
Other audit services
We help clients with the application and use of foreign financial aid of EU and other funds and help prepare financial reports.
-
Audit calculator
The calculator will answer if the company's sales revenue, assets or number of employees exceed the limit of an inspection or audit.
-
Payroll and related services
We perform payroll accounting for companies whether they employ a few or hundreds of employees.
-
Tax accounting
Grant Thornton Baltic's experienced tax specialists support accountants and offer reasonable and practical solutions.
-
Reporting
We prepare annual reports in a timely manner. We help to prepare management reports and various mandatory reports.
-
Consolidation of financial statements
Our experienced accountants and advisors help you prepare consolidation tables and make the consolidation process more efficient.
-
Consultancy and temporary staff
Our experienced specialists advise on more complex accounting transactions, rectify poor historic accounting, and offer the temporary replacement of an accountant.
-
Outsourced CFO service
Our CFO service is suitable for companies of all sizes and in all industries. We offer services to our clients in the required amount and competences.
-
Assessment of accounting processes
We help companies to implement accounting practices that are in compliance with local and international standards.
-
Accounting services for small businesses
We offer affordable service for small businesses. We help organize processes as smartly and cost-effectively as possible.
-
Cryptocurrency accounting
We keep up with blockchain technology to serve and advise crypto companies. We are supported by a network of colleagues in 130 countries.
-
Trainings and seminars
Our accountants have experience in all matters related to accounting and reporting. We offer our clients professional training according to their needs.
-
Business advisory
We offer legal support to both start-ups and expanding companies, making sure that all legal steps are well thought out in detail.
-
Fintech advisory
Our specialists advise payment institutions, virtual currency service providers and financial institutions.
-
Corporate advisory
We advise on legal, tax and financial matters necessary for better management of the company's legal or organizational structure.
-
Transaction advisory
We provide advice in all aspects of the transaction process.
-
Legal due diligence
We thoroughly analyze the internal documents, legal relations, and business compliance of the company to be merged or acquired.
-
In-house lawyer service
The service is intended for entrepreneurs who are looking for a reliable partner to solve the company's day-to-day legal issues.
-
The contact person service
We offer a contact person service to Estonian companies with a board located abroad.
-
Training
We organize both public trainings and tailor made trainings ordered by clients on current legal and tax issues.
-
Whistleblower channel
At Grant Thornton Baltic, we believe that a well-designed and effective reporting channel is an efficient way of achieving trustworthiness.
-
Business model or strategy renewal
In order to be successful, every company, regardless of the size of the organization, must have a clear strategy, ie know where the whole team is heading.
-
Marketing and brand strategy; creation and updating of the client management system
We support you in updating your marketing and brand strategy and customer management system, so that you can adapt in this time of rapid changes.
-
Coaching and development support
A good organizational culture is like a trump card for a company. We guide you how to collect trump cards!
-
Digital services
Today, the question is not whether to digitize, but how to do it. We help you develop and implement smart digital solutions.
-
Sales organisation development
Our mission is to improve our customers' business results by choosing the right focuses and providing a clear and systematic path to a solution.
-
Business plan development
A good business plan is a guide and management tool for an entrepreneur, a source of information for financial institutions and potential investors to make financial decisions.
-
Due diligence
We perform due diligence so that investors can get a thorough overview of the company before the planned purchase transaction.
-
Mergers and acquisitions
We provide advice in all aspects of the transaction process.
-
Valuation services
We estimate the company's market value, asset value and other asset groups based on internationally accepted methodology.
-
Forensic expert services
Our experienced, nationally recognized forensic experts provide assessments in the economic and financial field.
-
Business plans and financial forecasts
The lack of planning and control of cash resources is the reason often given for the failure of many businesses. We help you prepare proper forecasts to reduce business risks.
-
Outsourced CFO service
Our CFO service is suitable for companies of all sizes and in all industries. We offer services to our clients in the required amount and competences.
-
Reorganization
Our experienced reorganizers offer ways to overcome the company's economic difficulties and restore liquidity in order to manage sustainably in the future.
-
Restructuring and reorganisation
We offer individual complete solutions for reorganizing the structure of companies.
-
Corporate taxation
We advise on all matters related to corporate taxation.
-
Value added tax and other indirect taxes
We have extensive knowledge in the field of VAT, excise duties and customs, both on the national and international level.
-
International taxation
We advise on foreign tax systems and international tax regulations, including the requirements of cross-border reporting.
-
Transfer pricing
We help plan and document all aspects of a company's transfer pricing strategy.
-
Taxation of transactions
We plan the tax consequences of a company's acquisition, transfer, refinancing, restructuring, and listing of bonds or shares.
-
Taxation of employees in cross-border operations
An employee of an Estonian company abroad and an employee of a foreign company in Estonia - we advise on tax rules.
-
Tax risk audit
We perform a risk audit that helps diagnose and limit tax risks and optimize tax obligations.
-
Representing the client in Tax Board
We prevent tax problems and ensure smooth communication with the Tax and Customs Board.
-
Taxation of private individuals
We advise individuals on personal income taxation issues and, represent the client in communication with the Tax and Customs Board.
-
Pan-Baltic tax system comparison
Our tax specialists have prepared a comparison of the tax systems of the Baltic countries regarding the taxation of companies and individuals.
-
Internal audit
We assist you in performing the internal audit function, performing internal audits and advisory work, evaluating governance, and conducting training.
-
Internal Audit in the Financial Services Sector
We provide internal audit services to financial sector companies. We can support the creation of an internal audit function already when applying for a sectoral activity license.
-
Audit of projects
We conduct audits of projects that have received European Union funds, state aid, foreign aid, or other grants.
-
Prevention of money laundering
We help to prepare a money laundering risk assessment and efficient anti-money laundering procedures, conduct internal audits and training.
-
Risk assessment and risk management
We advise you on conducting a risk assessment and setting up a risk management system.
-
Custom tasks
At the request of the client, we perform audits, inspections and analyzes with a specific purpose and scope.
-
External Quality Assessment of the Internal Audit Activity
We conduct an external evaluation of the quality of the internal audit or provide independent assurance on the self-assessment.
-
Whistleblowing and reporting misconduct
We can help build the whistleblowing system, from implementation, internal repairs and staff training to the creation of a reporting channel and case management.
-
Information security management
We provide you with an information security management service that will optimise resources, give you an overview of the security situation and ensure compliance with the legislation and standards.
-
Information security roadmap
We analyse your organisation to understand which standards or regulations apply to your activities, identify any gaps and make proposals to fix them.
-
Internal audit of information security
Our specialists help detect and correct information security deficiencies by verifying an organization's compliance with legislation and standards.
-
Third party management
Our specialists help reduce the risks associated with using services provided by third parties.
-
Information security training
We offer various training and awareness building programmes to ensure that all parties are well aware of the information security requirements, their responsibilities when choosing a service provider and their potential risks.
-
ESG advisory
We help solve issues related to the environment, social capital, employees, business model and good management practices.
-
ESG audit
Our auditors review and certify sustainability reports in line with international standards.
-
Sustainable investments
We help investors conduct analysis of companies they’re interested in, examining environmental topics, corporate social responsibility and good governance practices.
-
Sustainable tax behaviour
Our international taxation specialists define the concept of sustainable tax behaviour and offer services for sustainable tax practices.
-
ESG manager service
Your company doesn’t necessarily need an in-house ESG manager. This role can also be outsourced as a service.
-
Recruitment services – personnel search
We help fill positions in your company with competent and dedicated employees who help realize the company's strategic goals.
-
Recruitment support services
Support services help to determine whether the candidates match the company's expectations. The most used support services are candidate testing and evaluation.
-
Implementation of human resource management processes
We either assume a full control of the launch of processes related to HR management, or we are a supportive advisory partner for the HR manager.
-
Audit of HR management processes
We map the HR management processes and provide an overview of how to assess the health of the organization from the HR management perspective.
-
HR Documentation and Operating Model Advisory Services work
We support companies in setting up HR documentation and operational processes with a necessary quality.
-
Employee Surveys
We help to carry out goal-oriented and high-quality employee surveys. We analyse the results, make reports, and draw conclusions.
-
HR Management outsourcing
We offer both temporary and permanent/long-term HR manager services to companies.
-
Digital strategy
We help assess the digital maturity of your organization, create a strategy that matches your needs and capabilities, and develop key metrics.
-
Intelligent automation
We aid you in determining your business’ needs and opportunities, as well as model the business processes to provide the best user experience and efficiency.
-
Business Intelligence
Our team of experienced business analysts will help you get a grip on your data by mapping and structuring all the data available.
-
Cybersecurity
A proactive cyber strategy delivers you peace of mind, allowing you to focus on realising your company’s growth potential.
-
Innovation as a Service
On average, one in four projects fails and one in two needs changes. We help manage the innovation of your company's digital solutions!
This Whistleblowing Notice explains how personal data is collected, processed, and protected when you report concerns related to unlawful, unethical, or improper conduct within our legal entity.
Whistleblowing Privacy Notice applies in all countries where Grant Thornton Baltic OÜ operates, in line with our Whistleblowing Policy.
Every Grant Thornton Baltic OÜ (hereinafter GT) employee, trainee, volunteer, apprentice, contractor, consultant, applicant, shareholder, member of the management, administrative or supervisory board member, legal representative, partner, supplier, business contact must read this Whistleblowing Privacy Notice before reporting wrongdoings.
Important note: Speaking-up about wrongdoings, although encouraged by GT, remains purely voluntary. If your report contains personal data of yourself or others, please make sure it is limited to what is necessary to understand or resolve the case.
What concerns can you raise?
You can raise a compliance concern if you reasonably suspect a breach of laws, policies, and/or other GT obligations.
The nature of compliance concerns could include but are not limited to fraud, abuse, environmental issues, bribery, other breach of law or any other topic addressed in the GT`s Whistleblowing Policy. In order to assist in the investigation, those reporting potential violations are encouraged to identify themselves.
1. Who is responsible for your personal data
Grant Thornton Baltic OÜ, Pärnu mnt 22, 10141 Tallinn, Estonia (“GT”, “we”, “us”, “our”) will as data controller operate GT’s Whistleblowing solution to ensure that you know how to raise a compliance concern if you observe or suspect a wrongdoing and provide a remediation framework for serious and sensitive compliance concerns that could have an adverse impact on GT’s business.
2. Personal data we process
Below you will find a description of the personal data we will collect and process about you as well as the purpose on which basis we are processing the personal data when you use the Whistleblowing line.
In principle, the GT Whistleblowing line can be used, to the extent permitted by law, without providing your personal data. You may, however, voluntarily disclose your personal data as part of the Whistleblowing process.
Processed Personal data will generally be limited to:
- identity, location and contact details of the reporting person (if the report mentions such information).
- Whistleblowing report data: information related to the reported issue, including the nature of the alleged misconduct, unlawful activity, or regulatory breach.
- Third party data: personal data of individuals mentioned in the report (e.g., employees, contractors, or other stakeholders).
- Actions to be taken/already taken in relation with people mentioned in the report to either protect them and/or stop the wrongdoings.
- Special categories of data: In principle, we do not request or process any special categories of personal data (also known as sensitive personal data), e.g. information on racial and/or ethnic origin, religious and/or ideological convictions, trade union membership or sexual orientation. Due to free format of the reporting, however, such special categories of personal data may be voluntarily disclosed by you. Please do not reveal any sensitive personal data about yourself or anyone else if not strictly necessary for us to understand or resolve the case or protect you.
In any case, only personal data strictly necessary to understand, verify, clarify, and resolve reported facts will be processed. Personal data mentioned in unsubstantiated or out of scope reports or which are simply not necessary will be deleted and not considered, in particular, if sensitive.
3. Purpose of the processing and the legal grounds
GT processes personal data in order to manage in a safe and efficient manner all reports of wrongdoings made under the Whistleblowing Policy – which includes the:
- analysis, storage and follow up of reports including exclusion of irrelevant reports
- investigation of reported facts (where relevant)
- necessary actions to stop the wrongdoings, preserve evidence and defend GT’s rights and assets
- protect the privacy, rights and safety of the reporting person, witnesses and third parties mentioned in the report as well as the rights of the accused person.
Processing Personal data for the management of reports is based on:
- a legal obligation – to provide safe reporting channels to the personnel and business contacts. This legal obligation exists within the EU/EEA, based on their national legislation implementing the EU Directive about Whistleblowing, and in many other countries across the world;
- a legitimate interest of GT to give the possibility to our personnel and business contacts to speak up and report wrongdoings and for us to receive and investigate whistleblowing reports to ensure a lawful and compliant way to make business;
- the necessity, in extreme cases, to protect the vital interests of the reporting person or other persons;
- in residual cases, where sensitive personal data is provided in a report, consent is the legal ground, as reporting is voluntary as well as the provision of any personal data in there. If not necessary to the resolution of the case, it will be immediately deleted.
4. How we process personal data
GT is using a third-party service provider Zoho Corporation for our online Whistleblowing platform where the reports are hosted and managed.
5. Security, disclosure of personal data and international transfer of personal data
All persons authorised to inspect the data are expressly obliged to maintain confidentiality.
GT may also transfer your personal data to our external attorney or auditor in connection with the processing of the concern, including reporting the concern to relevant authorities, if necessary, and the police and/or courts in case of criminal investigation or lawsuit, local competent public authorities.
The board members, legal representative, line manager and HR department of the employer will be informed of the identity of the accused person only if wrongdoings are proved as well as the liability of the accused person, in order for the employer to take any necessary measures towards the concerned accused person. Works council will also be informed, if legally required.
We do not transfer personal data outside of the European Economic Area (EEA). If such a transfer becomes necessary, we will ensure that appropriate safeguards are in place, in accordance with GDPR, to protect your personal data.
6. Duration of storage
Personal data related to whistleblowing reports will be retained only for as long as is needed to fulfil our purposes of investigating compliance concerns and documenting our compliance with applicable laws, unless we are required under applicable law to keep your personal data for a longer period.
Different retention periods apply if legal proceedings or disciplinary measures are initiated.
The general principles are that: (i) only relevant personal data is kept, and (ii) personal data is not retained longer than necessary to fully manage a report (i.e. understand and analyse a report, investigate where necessary and resolve the concerned issue, which may include actions before courts and/or disciplinary actions).
More precisely, please note that:
- irrelevant reports (i.e. out of scope of the reporting policy or unfounded) or irrelevant personal data are archived immediately and deleted within five (5) years from the closing of investigation.
- reports for which no judicial or disciplinary procedure is necessary are deleted within five (5) years from the end of the verification/ investigation phase.
- reports leading to a litigation/disciplinary procedure are deleted once all statute of limitation periods have expired.
7. Which rights you have regarding your personal data
7.1. Reporting person
The privacy, rights and safety of the reporting person are ensured from the moment you make a report in good faith and during the entire reporting procedure.
If you are the reporter, you have the right to:
- The right to information and access – to know which personal data GT holds about you, obtain detailed information about how your data is used and who has access to it, you can obtain a copy of all your personal data, obtain its correction or rectification if incorrect or incomplete. There are some exemptions, which means you may not always receive all the personal data that we process, e.g. when there is an ongoing legal investigation.
- The right to object – you have the right to object to GT processing (using) your personal data. This effectively means that you can stop or prevent us from using your personal data. However, it only applies in certain circumstances, and we may not need to stop the processing of your personal data if we (i) have compelling legitimate grounds to process it that override your rights and freedoms, (ii) needs it to establish, protect or defend our rights or (iii) comply with applicable law.
- The right to erasure – you have the right to ask us to erase your personal data in certain circumstances provided that GT does not have to keep it for legal reasons.
- The right to rectification – you can also request GT to stop using your personal data until clarification (but not delete it), if you considers that your personal data have been used in violation of applicable data protection law. If you want to obtain any rectification, you can contact the respective member of the Compliance team via the Whistleblowing platform. You have the right to ask us to rectify personal data you think is inaccurate. You also have the right to ask us to complete personal data you think is incomplete.
- The right to restriction of processing – you have the right to ask us to restrict the processing of your personal data in certain circumstances.
7.2. Accused person
If you are the accused person, you have the right to:
- information and access – be informed of the reported accusations against you, within six (6) month/days maximum from receipt of a report. By exception, when such notification may seriously jeopardize the efficiency of the investigation, the protection of evidence or the entire reporting process, it must be provided as soon as those risks do not exist anymore.
- erasure – require the deletion or correction of any incorrect personal data about you (you will be able to exert these rights once informed about the reported accusations).
- object – you do not have the right to object to the use of your personal data, except if you demonstrate that the reported facts are inexistent or do not involve you, or if the concerned personal data are incorrect or unnecessary to the resolution of the case.
If you are the accused person, you have the right for your reputation, privacy protected, and identity kept confidential by those in charge of managing the reports as long as the liability of you is not proved. In this context, the identity of the accused person cannot be revealed to the line manager, legal representatives and board members of the employer of the concerned accused person, as long as the liability is not proved.
7.3. Witnesses and any other person mentioned in the reports
If you are a witness or other third party mentioned in a report, you have the right to:
- The right to information and access – to know which personal data GT holds about you, obtain detailed information about how your data is used and who has access to it, you can obtain a copy of all your personal data, obtain its correction or rectification if incorrect or incomplete. Also to have your identity protected and kept strictly confidential by GT and not revealed to anyone without your express prior consent, provided that the disclosure of your identity to local authorities or courts is not required by applicable law.
- The right to object – object to the use of your personal data based on legitimate interests or consent, for reasons linked to your personal situation, and in that case GT will have to delete and stop using it except if it has an overriding legitimate interest to keep it, as a legal obligation or the necessity to protect the vital interest of someone; Object to the use of your personal data, based on grounds linked to their personal situation that would overweight the legitimate interest of GT.
- The right to erasure – request the deletion of your personal data provided that GT does not need to keep it anymore for legal reasons. You can also request GT to stop using your personal data (but not delete it) until clarification before a court or supervisory authority, if you believe that your personal data have been used in violation of applicable data protection law.
The right to complaint – anyone, whose personal data is processed, has the right to complaint (including the reporter, the accused person and the witnesses or any other person mentioned in the reports). If you have any complaints about GT’s processing of your personal data, please contact our Data Protection officer by privacy@ee.gt.com.
If you are not happy with the way we handle your complaint, you may contact the respective Data Protection Authority.
8. Contact information
If you observe or suspect breach of laws, policies, and/or other GT obligations, You should report the compliance concerns through GT Whistleblowing report form available here.
If you have any questions or concerns about how we process your personal data, please contact us by email: privacy@ee.gt.com regarding your personal data.
9. Changes to the Privacy Notice
We may need to change this Privacy Notice from time to time to ensure it meets the possible changes in the process or the updated laws. When changes are made, we will update the "Last Updated" date at the top of this notice and communicated it in our Whistleblowing platform.
This document was last updated in November 2024.