Privacy Policy

Privacy Policy

Last updated: 18 August 2026

This Privacy Policy explains how Nordisys collects, uses, stores, and protects personal data when you visit our website, contact us, request a quote, or use our services.

1. Who we are

Nordisys
Y-tunnus: 3633932-1
Location: Turku, Finland
Email: hello@nordisys.fi
Website: https://nordisys.fi

Nordisys is the data controller for the personal data processed through this website and our business communication.

2. What personal data we collect

We may collect the following personal data:

  • name

  • email address

  • phone number, if provided

  • business name

  • website address, if provided

  • message or project details submitted through the contact form

  • email communication and quote requests

  • IP address and technical browser information

  • cookie and analytics data, depending on your cookie choices

We only collect data that is needed to respond to enquiries, provide services, improve the website, protect the website, and manage business communication.

3. Contact forms and enquiries

When you submit a contact form or request a quote, we collect the information you provide so we can reply to your message, understand your project, prepare a quote, and communicate with you about possible services.

This may include your name, email address, phone number, company name, current website, selected service type, and message.

The legal basis for this processing is our legitimate interest in responding to business enquiries and, where relevant, taking steps before entering into a contract.

4. Client and project communication

If you become a client, we may process personal data needed to manage the project, deliver the agreed services, send invoices, provide support, and keep necessary business records.

This may include project messages, website access details, business information, invoices, and service-related communication.

The legal basis for this processing is contract performance, legitimate interest, and legal obligations such as accounting and tax record requirements.

5. Cookies and analytics

Our website may use cookies and similar technologies.

Some cookies are necessary for the website to function properly. Other cookies, such as analytics or marketing cookies, are used only if you give consent through the cookie banner.

Cookies may be used to:

  • keep the website working properly

  • remember cookie choices

  • improve website performance

  • understand how visitors use the website

  • measure traffic and page performance

You can accept, reject, or customize non-essential cookies through the cookie banner. You can also change your cookie choices later through the cookie settings link or icon on the website.

For more details, please see our Cookie Policy.

6. Website security and technical logs

For security and maintenance purposes, our website, hosting provider, security tools, or server systems may process technical data such as IP address, browser type, device information, pages visited, timestamps, and error logs.

This information helps us keep the website secure, prevent spam, detect technical issues, and protect against misuse.

The legal basis for this processing is our legitimate interest in website security and reliable service operation.

7. Embedded content and third-party services

Pages on this website may include embedded content or links from third-party websites, such as videos, maps, fonts, analytics tools, booking tools, social media platforms, or other external services.

Embedded content from other websites behaves in the same way as if you visited those websites directly. These third-party services may collect data, use cookies, and track your interaction according to their own privacy policies.

We are not responsible for the privacy practices of third-party websites or services.

8. Who we share data with

We do not sell personal data.

We may share or process data with trusted service providers when necessary, such as:

  • website hosting providers

  • email providers

  • analytics providers

  • spam protection or security tools

  • payment or invoicing tools

  • project management or communication tools

  • legal, accounting, or administrative service providers if needed

These providers may process data only as needed to provide their services or as required by law.

9. International transfers

Some third-party service providers may process data outside Finland or the European Economic Area.

If personal data is transferred outside the EEA, we aim to use appropriate safeguards, such as European Commission adequacy decisions, standard contractual clauses, or other legally accepted transfer mechanisms.

10. How long we keep data

We keep personal data only for as long as necessary for the purpose it was collected.

Typical retention periods:

  • contact form enquiries: up to 24 months

  • project and client communication: as long as needed for the project and support relationship

  • invoices and accounting records: as required by Finnish law

  • technical logs: usually for a limited period needed for security and maintenance

  • cookie consent records: as needed to manage consent choices

We may keep some information longer if required for legal, accounting, dispute resolution, or security reasons.

11. Your rights

Under applicable data protection law, you may have the right to:

  • request access to your personal data

  • request correction of inaccurate data

  • request deletion of your data

  • request restriction of processing

  • object to processing based on legitimate interest

  • withdraw consent where processing is based on consent

  • request data portability where applicable

  • lodge a complaint with a data protection authority

To use your rights, contact us at:

contact@nordisys.com

If you believe your data protection rights have been violated, you may contact the Finnish Data Protection Ombudsman.

12. How we protect data

We use reasonable technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure.

These measures may include secure website hosting, access control, updates, backups, security tools, and limiting access to data where appropriate.

No website or online service can be guaranteed to be completely secure, but we take reasonable steps to protect the information we process.

13. Children’s privacy

Our website and services are intended for businesses and adults. We do not knowingly collect personal data from children.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The latest version will be available on this page with the updated date.

15. Contact

If you have questions about this Privacy Policy or how we process personal data, contact:

Nordisys
Email: hello@nordisys.fi
Location: Turku, Finland
Y-tunnus: 3633932-1