Version 1.0 — Updated: May 30, 2025

1. Data Controller

Nordic Energy Innovation
Wredenkatu 2, 78250 Varkaus
Phone: +358 40 958 711 | Email: info@cetrium.eu

2. Data Protection Contact Person

Data Protection Officer
Email: info@cetrium.eu | Phone: +358 40 958 711

Nordic Energy Innovation does not need to appoint a statutory data protection officer. An EU representative is also not required as the company is based in Finland.

3. What Personal Data We Process and Why

Purpose Data Categories Source Legal Basis (GDPR Art. 6)
Customer service and inquiry handling Name, contact details, company information, communication history Data subject Legitimate interest 6(1)(f) — you expect a response to your inquiry
Quote and contract management Contact details, project information, contract history Data subject Contract 6(1)(b) — performance of contract
B2B direct marketing (product updates and news) Email address, name, interaction history Data subject Legitimate interest 6(1)(f); you can withdraw consent at any time
Website analytics and performance Pseudonymized cookie identifiers, visit data Your device/browser Consent 6(1)(a) via cookie banner
Billing and accounting Billing information, payment details, accounting records Customer contract Legal obligation 6(1)(c) — accounting law

4. Cookies and Similar Technologies

We use cookies to improve the functionality of our website and analyze user experience. The use of cookies is based on your consent, which you can give or deny through the cookie banner.

5. Recipients and Processors

Service Role Hosting Region / Safeguards
Web hosting provider Processor EU data centers
Email service Communication EU data centers; GDPR compliant
CRM system Customer management EU ↔ US under Standard Contractual Clauses (SCCs)
Accounting firm Bookkeeping Finland; professional confidentiality obligation

6. International Transfers

Some service providers may be located outside the EU. Personal data transfers are based on EU Commission adequacy decisions or Standard Contractual Clauses, supplemented by risk assessments.

7. Retention Periods

Data Category Retention Period Trigger Duration
Customer data End of customer relationship 5 years from end of customer relationship
Billing and accounting records End of financial year 10 years according to accounting law
Marketing consents Last interaction 24 months, then deletion
Contact requests Request processing 18 months
Web analytics data Event timestamp 26 months

Longer retention is possible if necessary for the establishment, exercise, or defense of legal claims.

8. Security Measures

  • All traffic is protected with SSL/TLS encryption
  • Servers are located in secure EU data centers (Google - Hamina)
  • Two-factor authentication for administrator accounts
  • Regular security assessments and updates
  • Staff training on data protection matters
  • Daily encrypted backups
  • Access control management and monitoring

9. Your Rights

Under GDPR Articles 15-22, you may request:

  • access to your personal data (right of access)
  • rectification or completion of data
  • erasure of data ("right to be forgotten")
  • restriction of processing
  • to object to direct marketing or profiling
  • data portability from one system to another
  • withdrawal of your consent

10. How to Exercise Your Rights

Send an email to info@cetrium.eu and provide sufficient information to verify your identity. We aim to respond within 30 days of your request.

11. Right to Lodge a Complaint

You may contact the Office of the Data Protection Ombudsman (PO Box 800, 00521 Helsinki, tietosuoja@om.fi, phone 029 566 6700) or your local EU supervisory authority if you believe that the processing of your personal data is not lawful.

12. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that would have legal or similarly significant effects on you.

13. Children

Our service is aimed at business professionals. We do not knowingly process personal data of individuals under 16 years of age. If you believe a child has provided personal data, contact us and we will delete the information immediately.

14. Updates

We may update this privacy policy from time to time. Minor editorial changes take effect immediately. If we make material changes — such as new processing purposes, data categories, or service providers — we will publish a prominent notice on our website at least seven (7) days in advance.

Questions about our privacy practices?

We are committed to transparency in our personal data processing activities. If you have questions or concerns about the processing of your personal data, please contact:

Data Protection Officer

Data Protection Officer

Jussi Pirhonen

+358 50 490 2477

jussi@tovari.fi