Our
Privacy Policy
Privacy Policy
This privacy policy describes what personal data the Parvi & Co. Oy collects, how the data is processed, for what purposes the data is used, and to whom the data may be disclosed. The privacy policy also provides information about the obligations the Company complies with when processing personal data.
The Company pays particular attention to data protection and, in all processing of personal data, complies with the EU General Data Protection Regulation (2016/679) (the “GDPR”) as well as other applicable data protection legislation and good data processing practices.
This privacy policy applies to all services offered by the Company. In addition to customers’ personal data, this privacy policy also applies to the processing of the personal data of potential customers. Furthermore, the privacy policy applies to the processing of the personal data of representatives of the Company’s corporate customers, business partners, service providers, and subcontractors.
Personal data means all information relating to a natural person (the “data subject”) from which they can be directly or indirectly identified, as defined in the GDPR. Information from which the data subject cannot be directly or indirectly identified is not personal data.
2. Data Controller and Contact Person
Data controller: Parvi & Co. Oy
Business ID: 1756760-1
Address: Lapinlahdenkatu 1 B
Email: otso.karvinen@parvi.ai
Contact person: Otso Karvinen
Contact details: as stated above
3. Purposes and Legal Basis of the Processing of Personal Data
Personal data is processed for purposes including the following:
- ordering, maintaining, developing, quality assurance, and communications relating to the Company’s products and services
- business planning and product development
- personalized customer service relating to the services, targeted customer communications, and monitoring the use of the services
- marketing and the targeting of marketing to customers and potential customers
- ensuring the security of the services and preventing misuse
- invoicing
- job applications, recruitment, or other similar situations in which we need contact information
The legal basis for processing data subjects’ personal data is the contractual relationship between the Company and the data subject, based on the ordering or provision of a product or service offered by the Company. The processing of personal data is also based on statutory obligations, such as accounting obligations. Processing for the management of the customer relationship and for marketing is based on the Company’s legitimate interest.
Electronic direct marketing and subscribing to the companies’ newsletters are based on the consent given by the data subject or on the companies’ legitimate interest. The data subject has the right to withdraw their consent at any time (see the data subject’s rights below).
4. Categories of Personal Data Processed, Data Content, and Data Sources
The Company collects from data subjects only such personal data as is relevant and necessary for the purposes of use described in this privacy policy. The following data is processed regarding data subjects:
4.1. Contact details: name, address, telephone number, email address
4.2. Identification data (only if absolutely necessary): date of birth
4.3. Data relating to the customer relationship: account number, invoicing and payment details, and other data identifying the customer relationship
4.4. Customer transaction data and contract data: information about the contract between the Company and the data subject, or between the Company and the entity the data subject represents; sales contracts; customer feedback; and contacts between the data subject and the Company, complaints, and other transaction data
4.5. Consents given by the data subject: data concerning the consent given by the data subject to electronic direct marketing, the withdrawal of consent, and any objections made by the data subject
4.6. Behavioral data and technical identification data: monitoring of the data subject’s online behavior and of the Company’s services, for example by means of cookies or similar technical identifiers. The data collected may include, for example, the user’s IP address, pages visited, browser type, network address, and the time and duration of the session.
Providing the data referred to in sections 4.1–4.4 above is necessary for fulfilling the obligations arising from the contract between the Company and the data subject and from legislation, as well as for providing the Company’s services. Providing the data referred to in section 4.5 is voluntary.
Personal data is primarily collected from the data subjects themselves, for example in connection with making an offer, concluding a contract, or during the customer relationship. The data subject may also have provided data to the Company, for example, by subscribing to an electronic newsletter, on social media services, or on the Company’s website.
The Company may use external service providers for marketing purposes, which process data subjects’ contact details for marketing.
Personal data may also be collected from the entity on whose behalf the data subject acts. In addition, where permitted by law, data may also be collected from and updated using registers maintained by third parties.
The Company’s subcontractors, contractors, and business partners provide the Company with data subjects’ personal data in situations required by legislation and contractual obligations.
The Company uses various services for visitor tracking on its online services, including Google Analytics, which make use of browser cookies and other identifiers. Further information about these can be found in the privacy policies of each service used.
5. Retention of Personal Data
The Company retains personal data for as long as is necessary to fulfil the purposes defined in this privacy policy, unless legislation requires the personal data to be retained for longer (for example, responsibilities and obligations relating to special legislation, accounting obligations, or reporting obligations), or unless the Company needs the data to establish, exercise, or defend a legal claim, or to resolve a similar dispute.
The retention period and retention criteria vary by category of personal data, depending on the purpose of use of the particular data category.
Personal data is processed for the duration of the customer and contractual relationship and for a necessary period after the end of the customer and contractual relationship. Data concerning potential customers is primarily retained for a period of 1 year.
With respect to entities, the retention of the personal data of an entity’s representative is tied to how long the data subject in question acts as the entity’s representative towards the Company.
When personal data is no longer needed as defined above, the data is deleted within a reasonable time.
6. Parties Processing Personal Data and Recipients
Companies belonging to the same group as the Company may process personal data in accordance with data protection legislation.
In accordance with this privacy policy, the Company may outsource the processing of personal data to service providers or subcontractors. The Company ensures through adequate contractual obligations that personal data is processed appropriately.
Personal data may be disclosed to authorities in situations required and permitted by law.
The Company does not disclose data subjects’ personal data for direct marketing purposes.
If the Company is involved in a merger, a sale of business operations, or another corporate transaction, it may be required to disclose data subjects’ personal data to third parties.
Disclosure of data to third parties generally takes place via electronic data transfer connections, but data may also be disclosed by other means, such as by telephone or by letter.
7. Transfer of Personal Data Outside the European Union or the European Economic Area
Data is not transferred outside the European Union or the European Economic Area.
Should data be transferred outside the European Union or the European Economic Area, the Company ensures an adequate level of protection of personal data, among other things by agreeing on matters relating to the processing of personal data in the manner required by data protection legislation, such as by using the standard contractual clauses approved by the European Commission.
8. Principles of Personal Data Protection and Security of Processing
The Company processes personal data in a manner intended to ensure, in all situations, the appropriate security and protection of personal data, including protection against unauthorized processing and against accidental loss, destruction, or damage.
Appropriate technical and organizational safeguards are used in the processing of personal data to ensure this, including the use of firewalls, encryption technologies, and secure equipment facilities, appropriate access control and access management, and staff instructions.
Contracts and other documents retained as originals are kept in locked premises to which access is restricted solely to authorized parties. Paper printouts are destroyed in a data-secure manner.
All parties processing personal data are bound by a duty of confidentiality regarding matters relating to the processing of data subjects’ personal data, based on the Employment Contracts Act and the confidentiality clauses of their contracts.
In accordance with this privacy policy, the Company may outsource the processing of personal data to service providers, in which case the Company ensures through adequate contractual obligations that personal data is processed appropriately and lawfully.
9. Rights of Data Subjects
Data subjects have the rights guaranteed by data protection legislation.
The data subject has the right to obtain confirmation as to whether their personal data is being processed. The data subject has the right to check and see the data concerning them and, on request, the right to receive the data in writing or in electronic form.
The data subject has the right to demand the rectification of inaccurate or incorrect data. In addition, the data subject has the right, in accordance with applicable data protection legislation, to demand the erasure of their data. The Company also, on its own initiative, erases, rectifies, and supplements personal data that it has found to be incorrect, unnecessary, incomplete, or outdated with regard to the purpose of the processing.
The data subject has the right, in accordance with applicable data protection legislation, to demand the transfer of their data to another data controller.
In addition, the data subject has the right, subject to the conditions set out in data protection legislation, to request the restriction of the processing of personal data. Furthermore, in a situation where personal data suspected of being incorrect cannot be rectified or erased, or where there is uncertainty about an erasure request, the Company restricts access to the data.
The data subject has the right to object to the use of their data for certain types of processing. The data subject has the right to prohibit the disclosure and processing of their data for direct marketing purposes.
Requests concerning data subjects’ rights are made in person, in writing, or electronically, and are addressed to the contact person named in this privacy policy. Identity is verified before any data is provided. Requests for access are responded to within a reasonable time and, where possible, within one month of the submission of the request and the verification of identity.
If the data subject’s request cannot be granted, the refusal is communicated to the data subject in writing. The Company may refuse a request, such as a request for erasure, on the basis of a statutory obligation or a statutory right of the Company, such as an obligation or claim relating to the services.
Consent to electronic direct marketing can be withdrawn, or an objection to direct marketing lodged, by contacting the Company’s contact persons. In addition, the data subject can unsubscribe from the Company’s mailing list at any time by clicking the “Peru uutiskirjeen tilaus” / “Unsubscribe” link in the email.
10. Right to Lodge a Complaint with a Supervisory Authority
The data subject has the right to lodge a complaint with the data protection authority if the data subject considers that their personal data has been processed in violation of applicable legislation.
Office of the Data Protection Ombudsman Visiting address: Ratapihantie 9, 6th floor, 00520 Helsinki Postal address: P.O. Box 800, 00521 Helsinki Email: tietosuoja@om.fi Switchboard: +358 29 56 66700
11. Changes to the Privacy Policy
The Company continuously develops its services and may therefore need to change and update this privacy policy. Changes may also be based on changes in legislation. We recommend reviewing the contents of the privacy policy regularly. Changes will be announced on the Company’s website, and data subjects will be notified of material changes by email.
This privacy policy was published on August 20, 2026.
