Last updated 18th September 2026
Name of the personal data register
Oksidia Oy customer register
Controller
Oksidia Oy — Business ID: 2452164-4 Viipurintie 4, 13200 Hämeenlinna, Finland +358 50 565 9403 Email: info@oksidia.fi Contact person: Tuomas Oksanen, tuomas@oksidia.fi
About the processing of personal data
We comply with the laws that apply to us, and we do not process the personal data of our customers or of their customers without a legal basis under data protection legislation. We process only the data that is necessary in order to manage the customer relationship, to provide high-quality services, or to develop our operations — including informing you about new products and features in the service.
This privacy policy applies to the processing of personal data of the customers (“customer”, “customers”) of the services provided by Oksidia, and describes the main principles and purposes of Oksidia’s processing of personal data. Customers may be companies or representatives of customer companies. Our products and services may contain links to third-party websites or services. Those websites and services are covered by their own privacy practices. Oksidia is not responsible for the privacy practices of third parties or for the data processing carried out in their operations. We recommend paying attention to third parties’ privacy practices and to any changes in them.
Sources of data
Oksidia regularly obtains the data it processes from the customer themselves, in connection with registration, an order, a request for a quotation, or the deployment of services.
Legal basis and purpose of processing personal data
We process personal data for the following purposes:
We do not use personal data contained in invoices for direct marketing.
Disclosure of personal data
We may disclose your personal data to third parties in the following cases:
Content of the register
The data in the register includes:
Transfers of personal data outside the EU/EEA
Oksidia may use subcontractors in its operations. Personal data may be transferred outside the EU/EEA to the extent necessary in order to provide the services. In that case we use approved, established mechanisms — such as the standard contractual clauses approved by the European Commission — that allow personal data to be transferred to our subcontractors in third countries.
Retention of personal data
Personal data is retained only for as long as is necessary to fulfil the purposes set out in this privacy policy. After that we delete the data, unless we are obliged to retain it under the law or under rights and obligations arising from an agreement between the parties. A significant part of our processing of personal data is carried out on behalf of users and in accordance with their instructions, so we follow their instructions on retention.
Information security
The controller maintains an information security management system certified to ISO 27001:2022, subject to regular internal review and periodic external audit.
Access to the register is limited to those Oksidia personnel whose role requires it, using individual accounts protected by multi-factor authentication. Access rights are reviewed twice a year. Personnel who process personal data are bound by confidentiality obligations and complete information security training annually.
Third-party services used to process personal data are subject to a documented security assessment before they are adopted. Suspected information security incidents are handled under a documented incident management process overseen by Oksidia’s ISMS board.
Cookies
Cookies are files that a user’s device receives and sends when the customer uses Oksidia’s services. Oksidia may use cookies and similar methods in order to provide the functionality of the services, to develop their quality, and to improve the user experience. By using our services and accepting the use of cookies in their browser settings, the customer accepts Oksidia’s use of cookies. The customer may refuse the use of cookies by changing their browser settings. This may, however, affect the user experience of the services.
The user’s rights and the quality of personal data
Users have the right to prohibit Oksidia from processing data concerning them for the purposes of direct advertising, distance selling, and other direct marketing, as well as for market and opinion research. Oksidia recommends that users submit any such prohibition in writing to the Oksidia contact person named in this privacy policy.
Users have the right to data portability, that is, to receive the personal data concerning them in a structured and commonly used format and to transfer it to another controller.
Users have the right to check the data stored about them and, on request, to receive copies of it. A request for access must state the details needed in order to locate the data, and must be made in writing in a request signed by the user. Requests can be addressed to the contact person named in this privacy policy.
If the customer considers that their statutory rights have been infringed, the customer may lodge a complaint with a data protection authority in the European Union. In Finland, the supervisory authority is the Data Protection Ombudsman (Tietosuojavaltuutettu). You can find the Data Protection Ombudsman’s contact details at http://www.tietosuoja.fi/fi/.
Oksidia seeks, as far as it is able, to ensure the quality of the personal data it processes. Oksidia rectifies, deletes, or supplements personal data that is incorrect, unnecessary, incomplete, or out of date, either on its own initiative or at the request of the data subject. The customer is, however, responsible for the accuracy of the information they provide. The customer is also responsible for notifying us if the information they have provided changes. To have their data corrected, customers are advised to contact the contact person named in this privacy policy.
Changes to this privacy policy
Oksidia may make changes to this privacy policy and to the related information. Oksidia recommends that users review this privacy policy regularly in order to be aware of any changes made to it. Our privacy policy always shows the date on which it was last updated, so that you can follow the changes.