April 2024

Privacy Notice

Since privacy and data protection are at the core of our business, it is of paramount importance to us that when processing personal data, we do so in a lawful and responsible manner. With personal data we mean any piece of information relating to an identified or identifiable person (‘data subject’) that allows us to identify a person directly or indirectly. Processing personal data refers to any operation or set of operations performed on personal data, such as collection and storing of personal data.

The standard for our personal data processing operations is the relevant national and international regulations and we adhere to the rules and principles set forth in the European General Data Protection Regulation (GDPR).

We want to be transparent about our data processing. You can find more information about Privaon’s data processing from the chapters below. We may update this Privacy Statement sometimes. If we make any substantial changes to our processing, we openly seek to inform you.

Privaon as a Controller and Processor

Privaon acts as a controller for the personal data concerning our business contacts. They are for example the representatives of our corporate clients, potential corporate clients, and other stakeholders such as suppliers and their representatives. If you are our business contact, this statement explains how Privaon processes your personal data.

Read more

Privaon as a controller

Controller refers to a company or other party in charge of processing and determines how the personal data is processed.

Privaon as a processor

Processor refers to a company or other party which is processing personal data on behalf of the controller and according to the instructions received from the controller.

Privaon acts as processor for some of the personal data that we process in the context of providing our cloud-based tools and services. For example, when a corporate company uses Privaon’s cloud-based eLearning service, we process the data on behalf of our customer and according to their instructions. Our corporate customer remains the controller for the personal data.

Contact information

If you have any questions or comments, please contact us by calling or emailing

Privaon Oy Hevosenkenkä 3, A-tower 8th floor
02600 Espoo, Finland

[email protected]

+358 50 328 1446

Collection and Use of Personal Data

Our core business is not the collection of your personal data. Therefore, we process only the minimum amount of personal data necessary to operate our business, to offer and provide our services. We will only process your personal data for predefined purposes, and we make sure that we have legal grounds for it.
Read more

We process personal data for the following purposes:

  • To provide our services. This includes processing contact information, billing information and other information which you have provided to us in the context of requests or the provision of services.
  • To market and advertise our products. This includes processing, for example, contact information, information about purchases, your requests and information about your preferences. We may obtain your personal data also from publicly available sources, such as from your company’s website, LinkedIn or Fonecta Finder.
  • To conduct market research. This includes processing the necessary contact information and the answers you have provided for us. The contact details of the potential participants are collected from our business contacts and from publicly available sources.

The process is based on our interest in establishing new business relationships and maintaining existing ones. Our annual marketing research is based on our interest in gaining insights from customers, potential customers, and other stakeholders. With regards to electronic direct marketing, we process your data only if you have given your consent for it.

More information

As we are a company dependent on business operations, we do marketing for our business contacts. We keep records of our clients’ and potential clients’ details to market and provide more information about our products and services This could mean for example invitations to our events and other marketing activities to promote our services.

We use online advertising networks, social media companies and other third-party services to send marketing communication and display ads on other websites and services you may use. You can ask us to remove your data from these channels at any time by contacting us. You can unsubscribe from our mailing list by using the unsubscribe link in the relevant email.

Disclosures and Data Sharing

We use third-party service providers to provide our services and to help operate our business efficiently. . As a responsible company, we always use various contractual and other arrangements to ensure that our service providers process your personal data in accordance with the laws and good data processing practices. Some of our service providers or their support functions are located outside the EU and EEA (European Economic Area).

Read more

To ensure confidentiality and an important level of protection for your data, we have a data processing agreement with every service provider we use for personal data processing. Our processors do not have the permission to process your information in any ways beyond the agreed services and Privaon remains the sole controller of such data. We have also conducted Privaon’s Privacy Impact Assessments (PIA) for most of our processors.

We may have to disclose certain information to the public or law enforcement authorities when this is required by law. We only do so based on an adequate legal warrant or subpoena issues by a Finnish or other relevant Court.

In mergers or acquisitions, the acquiring entity may obtain access to relevant customer data assets.

Some of our service providers or their support functions are in the United States. When the processing involves transferring personal data outside EU or EEA, we use appropriate legal mechanisms to ensure the same level of data protection as in the EU. The measures we rely on are the model contractual clauses issued by European Commission.

Data Security

Privaon has appropriate security policies and procedures in place to protect personal data from loss, misuse, or unauthorized access.
Read more

We guarantee that your data is kept confidential and secure. All the employees authorized to process your data are committed to confidentiality. We have role-based access control, meaning that each employee is given access to resources and personal data based on the employee’s needs and job description. All networks and services used by our employees are protected with appropriate security measures.

We have a procedure to manage data breaches which allows us to assess the possible risks, notify the relevant authorities and alert you in case your personal data may have been affected. We regularly educate all employees to ensure the protection of your personal data.

Your Rights

You have several rights concerning your personal data, such as the right to access, update, delete and have a copy of such data. We seek to ensure that you can exercise your rights efficiently. You can exercise your rights by contacting us via phone or email.

Read more
  • When you have given your consent for the processing, and you do not want us to continue processing your data, you have a right to withdraw your consent at any point. You can unsubscribe from the mailing list by using the unsubscribe link in the relevant email.
  • When we process your data, we have taken your rights and interests into consideration. Especially when we process your data based on our legitimate interests, for example for marketing and research purposes. We have assessed the processing, and we ensure that it will not cause any significant intrusion into your privacy, or any other undue impact on your interests and rights. If you wish to hear more about the assessments conducted, please contact us. You have the right to object to such processing at any time by contacting us.
  • You have the right to obtain confirmation if your personal data is being processed and if you wish, receive a copy of such data. You have also the right to obtain confirmation if we are not using your personal data. This right is known as the right to access.
  • We want to ensure that your personal data is correct and up to date. You can always contact us to have your data corrected, updated, and completed. This right is known as the right to rectification.
  • In principle, you have the right to have your personal data erased in part or in full. f you request the erasure of your personal data, we will assess whether we can erase such data. Please note that we may have a legal right or obligation to keep your data for a certain period. This right is known as the right to erasure or the right to be forgotten.
  • If you object to processing, contest the lawfulness of the processing or the accuracy of the data, or if you need your data in legal proceedings, you have the right to ask us to restrict the processing of your personal data until the matter has been solved. This right is known as the right to restriction of processing.
  • If the processing of your data has been based on your consent or contract, you have right to receive your data in machine readable format and have it transferred to another controller. This right is known as the Right to data portability.
  • If you consider that the processing of personal data relating to you infringes the GDPR, you have the right to lodge a complaint with your local data protection authority.

If you wish to exercise your rights, or have any other question relating to the processing of your data or this privacy statement, please contact us by calling +358 50 328 1446 or sending us an email [email protected].

Cookies

We use cookies and other similar technologies to collect data on the usage of our website. By analysing our website usage, we aim to maintain and further develop our websites. For example, we get information on which service pages you go to, what blog texts you might be interested in and how you navigate between the pages. To develop our website, it is important to know what kind of website content is most efficient and functional. The collected data also helps us to provide more personalized services and marketing to you. We can for example create target audiences and send them more relevant and personalized communication such as advertising and messages. You can always disable cookies altogether in the browser settings or you can delete cookies from the browser and disable all targeted advertising and communication based on your previous visits on our website.

You can read more about our cookie policy from the cookie icon at the bottom left.

Retention Periods

We have determined retention periods based on the purpose of the process and the applicable legislation. For example, accounting laws require us to store your personal data for a certain period. We review the personal data we collect (e.g., the information of our business contacts) regularly to ensure that the personal data we have is up to date and is not retained longer than needed or required by the relevant laws.

Read more

When not limited by applicable legislation, the retention periods are defined as follows:

  • We retain your personal data for two years after the termination of the service agreement unless no other retention times are defined in the agreement.
  • If you are listed as a potential customer, your personal data is erased when we have no reason to assume that you would be interested in our services. This usually takes place if we have not been in touch with you for the past 12 months.

If you wish to have more detailed information about our retention times, please contact us by email [email protected] or call us +358 50 328 1446.