Privacy policy

Date of preparation: 17.9.2025
Last updated: 17.9.2025

1. Data controller

Noxam Group Oy
Business ID: 3340306-8
Address: Puustellinrinne 3, 00410 Helsinki
Phone number: +358 505 399 311
Email address: noxam@noxam.fi

Possible joint controllers: None.

2. Data protection officer

Samuel Olha
Address: Puustellinrinne 3, 00410 Helsinki
Phone number: +358 505 399 311
Email: samuel.olha@noxam.fi

3. Purposes and legal bases for processing

We process personal data for the following purposes and legal bases:

  • Customer relationship management, maintenance, and development – contract (GDPR 6(1)(b))
  • Communication and marketing – consent (GDPR 6(1)(a)) or legitimate interest (GDPR 6(1)(f))
  • Service development – legitimate interest (GDPR 6(1)(f))
  • Website traffic analysis and statistics – consent (GDPR 6(1)(a), cookies)

When relying on our legitimate interest, our interest includes, for example, the secure and efficient provision of services, prevention of misuse, and targeting customer communications to B2B contacts. A summary of the balancing test is available upon request.

4. Basis for data collection and processing

Data is collected and processed to fulfill contracts made with customers and to develop business and services.

5. Processed personal data

  • Company name and business ID
  • Contact person’s name, email, and phone number
  • Visiting and billing address
  • Services ordered by the customer and related delivery information
  • Usage log data: IP address, time, browser type, operating system, visited pages and time, referring site

6. Data retention periods

Personal data is retained only as long as necessary:

  • For the duration of the customer contract + up to 24 months after its end
  • Marketing lists, until you withdraw your consent
  • Log data for 12 months
  • Personal data in accounting records for the periods required by accounting law (receipts 6 years; financial statements 10 years)
  • Or for another separately agreed written period

7. Regular sources of data

  • Information provided when ordering services and products
  • Data collected during website use
  • Contact forms and customer surveys
  • Google Analytics analytics

8. Recipients and data transfers

We use service providers (e.g., website maintenance, cloud services, analytics tools).
Data may be transferred outside the EU/EEA, e.g., to Google servers in the United States. For transfers, we use the EU Commission’s standard contractual clauses (SCC) and, if necessary, additional safeguards. For Google, transfers may also be based on the EU–U.S. Data Privacy Framework adequacy decision.

More information about transfer safeguards and a copy of the key terms is available upon request.

We do not disclose data for direct marketing to third parties. We may disclose data to authorities as required by applicable law.

9. Cookies

We use necessary cookies for website functionality and consent-based cookies (e.g., Google Analytics). Non-essential cookies are only enabled with your prior consent.

On your first visit, we display a cookie banner where you can accept all, reject all, or select categories. You can change or withdraw your consent at any time.

Data collected by these cookies is transferred to and stored on Google’s servers, some of which may be located outside the EU and subject to local data protection laws.

More information in our cookie policy.

10. Managing and deleting cookies

You can block or disable cookies in your browser settings. Please note that some website functions may not work without cookies.

More information in our cookie policy.

11. Data subject rights

You have the right to:

  • Access your data (GDPR 15)
  • Request rectification (16) or erasure (17)
  • Restrict processing (18)
  • Object to processing (21), especially for direct marketing
  • Transfer data from one system to another (20)
  • Withdraw consent at any time

You can exercise your rights by submitting a written, signed request to the person responsible for registry matters. Data inspection is free once per year.

You also have the right to lodge a complaint with the Data Protection Ombudsman: www.tietosuoja.fi

12. Automated decision-making

We do not make automated individual decisions or profiling.

13. Mandatory data provision

Some data is necessary to fulfill the contract. If the data is not provided, we cannot deliver the service.

14. Data security

We protect data with appropriate technical and organizational measures (e.g., encryption, access control, logging).

Begär en kostnadsfri offert

Fyll i detta korta formulär för att få en personlig offert utan förpliktelser – snabbt och enkelt.
Eller kontakta oss direkt: 050 4750279 / noxam@noxam.fi
Jag är intresserad av följande tjänster:*

Request a free quote

Fill out this short form to receive your personalised, no-obligation quote — quickly and easily.
Or contact us directly 0505 399 311 / noxam@noxam.fi
I am interested in the following services:*

Pyydä ilmainen tarjous

Täytä lyhyt lomake, niin saat henkilökohtaisen tarjouksen nopeasti – ilman sitoumuksia.
Tai ota yhteyttä meihin suoraan 0505 399 311 / noxam@noxam.fi
Olen kiinnostunut seuraavista palveluista:*