Privacy Policy — Oksidia Oy customer register

Last updated 18th September 2026

Name of the personal data register

Oksidia Oy customer register

Controller

Oksidia Oy — Business ID: 2452164-4 Viipurintie 4, 13200 Hämeenlinna, Finland +358 50 565 9403 Email: info@oksidia.fi Contact person: Tuomas Oksanen, tuomas@oksidia.fi

About the processing of personal data

We comply with the laws that apply to us, and we do not process the personal data of our customers or of their customers without a legal basis under data protection legislation. We process only the data that is necessary in order to manage the customer relationship, to provide high-quality services, or to develop our operations — including informing you about new products and features in the service.

This privacy policy applies to the processing of personal data of the customers (“customer”, “customers”) of the services provided by Oksidia, and describes the main principles and purposes of Oksidia’s processing of personal data. Customers may be companies or representatives of customer companies. Our products and services may contain links to third-party websites or services. Those websites and services are covered by their own privacy practices. Oksidia is not responsible for the privacy practices of third parties or for the data processing carried out in their operations. We recommend paying attention to third parties’ privacy practices and to any changes in them.

Sources of data

Oksidia regularly obtains the data it processes from the customer themselves, in connection with registration, an order, a request for a quotation, or the deployment of services.

  1. Oksidia stores the information that the user provides when registering, ordering services, requesting a quotation, or deploying services. This information typically includes, for example, information about the company, the name of the company’s contact person, and contact details such as an email address and telephone number.
  2. In order to use the service, the customer must provide the personal data necessary for managing the customer and billing relationship and for general communication. It is the responsibility of the customer and the user to ensure that only necessary sensitive personal data is processed in the customer’s own registers when the service is used, and that there is a legal basis under data protection legislation for processing that data. Oksidia processes this data solely as a processor on behalf of the user, on the basis of a separate request.
  3. Publicly available information.

Legal basis and purpose of processing personal data

We process personal data for the following purposes:

  1. We process data in order to provide the service. This processing is based primarily on the agreement and the customer relationship between the customer and Oksidia. Personal data is collected when the customer registers, orders services, requests a quotation, or deploys services.
  2. Data stored in Oksidia’s customer register may be used to manage the customer relationship and contacts, and for marketing purposes. To that extent, processing is based on our legitimate interest in providing you with relevant information as part of the service and in marketing our service.
  3. Our aim is to provide a high-quality service. Data may therefore also be used to analyse markets, users, and services in order to develop and improve the quality of our services. This processing is based on our legitimate interest in growing and developing.

We do not use personal data contained in invoices for direct marketing.

Disclosure of personal data

We may disclose your personal data to third parties in the following cases:

  1. Oksidia may use subcontractors to provide its services. Our trusted service providers act on our behalf and for our account, and have no independent right to use personal data. We make sure that our subcontractors use personal data only in accordance with our instructions. Appropriate information security and confidentiality obligations have been placed on our subcontractors.
  2. We may disclose personal data where legislation requires it, for example in order to comply with requests from the competent authorities.
  3. Where we believe in good faith that disclosure is necessary in order to safeguard our rights, to investigate fraud, or to protect our customers.

Content of the register

The data in the register includes:

  • the official names of organisations
  • business IDs
  • postal and billing addresses
  • billing details
  • agreements
  • the first name, surname, email address, and role of organisations’ contact persons

Transfers of personal data outside the EU/EEA

Oksidia may use subcontractors in its operations. Personal data may be transferred outside the EU/EEA to the extent necessary in order to provide the services. In that case we use approved, established mechanisms — such as the standard contractual clauses approved by the European Commission — that allow personal data to be transferred to our subcontractors in third countries.

Retention of personal data

Personal data is retained only for as long as is necessary to fulfil the purposes set out in this privacy policy. After that we delete the data, unless we are obliged to retain it under the law or under rights and obligations arising from an agreement between the parties. A significant part of our processing of personal data is carried out on behalf of users and in accordance with their instructions, so we follow their instructions on retention.

Information security

The controller maintains an information security management system certified to ISO 27001:2022, subject to regular internal review and periodic external audit.

Access to the register is limited to those Oksidia personnel whose role requires it, using individual accounts protected by multi-factor authentication. Access rights are reviewed twice a year. Personnel who process personal data are bound by confidentiality obligations and complete information security training annually.

Third-party services used to process personal data are subject to a documented security assessment before they are adopted. Suspected information security incidents are handled under a documented incident management process overseen by Oksidia’s ISMS board.

Cookies

Cookies are files that a user’s device receives and sends when the customer uses Oksidia’s services. Oksidia may use cookies and similar methods in order to provide the functionality of the services, to develop their quality, and to improve the user experience. By using our services and accepting the use of cookies in their browser settings, the customer accepts Oksidia’s use of cookies. The customer may refuse the use of cookies by changing their browser settings. This may, however, affect the user experience of the services.

The user’s rights and the quality of personal data

Users have the right to prohibit Oksidia from processing data concerning them for the purposes of direct advertising, distance selling, and other direct marketing, as well as for market and opinion research. Oksidia recommends that users submit any such prohibition in writing to the Oksidia contact person named in this privacy policy.

Users have the right to data portability, that is, to receive the personal data concerning them in a structured and commonly used format and to transfer it to another controller.

Users have the right to check the data stored about them and, on request, to receive copies of it. A request for access must state the details needed in order to locate the data, and must be made in writing in a request signed by the user. Requests can be addressed to the contact person named in this privacy policy.

If the customer considers that their statutory rights have been infringed, the customer may lodge a complaint with a data protection authority in the European Union. In Finland, the supervisory authority is the Data Protection Ombudsman (Tietosuojavaltuutettu). You can find the Data Protection Ombudsman’s contact details at http://www.tietosuoja.fi/fi/.

Oksidia seeks, as far as it is able, to ensure the quality of the personal data it processes. Oksidia rectifies, deletes, or supplements personal data that is incorrect, unnecessary, incomplete, or out of date, either on its own initiative or at the request of the data subject. The customer is, however, responsible for the accuracy of the information they provide. The customer is also responsible for notifying us if the information they have provided changes. To have their data corrected, customers are advised to contact the contact person named in this privacy policy.

Changes to this privacy policy

Oksidia may make changes to this privacy policy and to the related information. Oksidia recommends that users review this privacy policy regularly in order to be aware of any changes made to it. Our privacy policy always shows the date on which it was last updated, so that you can follow the changes.