Privacy Policy
Last updated: June 5, 2026.
This is the privacy and data protection policy of Safety Builder Oy in accordance with the EU General Data Protection Regulation (GDPR). This policy explains how we collect, process, and protect the personal data of our clients and website users.
1. Data Controller
Company: Safety Builder Oy
Business ID: 2708418-7
Email: info@safetybuilder.fi
Phone number: +358 40 706 4124
2. Contact Person for Data Protection Matters
Name: Timo Heikkilä
3. Name of the Register
Safety Builder Oy's customer, marketing, and website user register.
4. Legal Basis and Purpose of Processing Personal Data
We process personal data for the following purposes:
- Customer Relationship Management and Service Delivery: Fulfilling contracts and communicating with clients.
- Responding to Contact and Quote Requests: Processing messages received through the website's forms.
- Marketing and Communication: Informing users about our services (provided the user has given consent or there is a legitimate interest).
- Website Development: Improving the website's user experience and compiling anonymous visitor statistics.
The legal basis for processing data is either a contract between the data controller and the client, a legal obligation, a legitimate interest (e.g., direct marketing to corporate clients), or the explicit consent given by the user.
5. Data Content of the Register
The following data may be stored in the register:
- Basic Information: Name, company/organization, position or job title.
- Contact Information: Phone number, email address, postal address.
- Contact Details: Messages sent via forms, details of quote requests, and other additional information provided by the client.
- Technical Information: IP address, cookie data, and website usage details (e.g., pages visited).
6. Regular Sources of Data
Data is regularly collected:
- When the user fills out forms on the website (such as "Request a Quote" or "Contact Us").
- In connection with establishing and managing a customer relationship (via email, phone, meetings).
- Through website cookies and other analytics tools.
7. Regular Disclosures of Data and Transfer of Data Outside the EU or EEA
We do not sell or rent your personal data to third parties. Data may be disclosed to:
- Subcontractors and Service Providers (e.g., IT partners, invoicing software, Webflow platform) who process data on our behalf and in accordance with our instructions.
- Authorities to fulfill statutory and legal obligations.
As a rule, data is not transferred outside the EU or the EEA. If the service providers used (such as cloud services) transfer data outside the EU/EEA, we ensure an adequate level of data protection by using Standard Contractual Clauses (SCC) approved by the European Commission.
8. Principles of Register Protection
Due diligence is exercised in the processing of data, and data processed by means of information systems is appropriately protected:
- Access to data is restricted only to those individuals who require it to perform their job duties.
- Systems, devices, and databases are protected by firewalls, passwords, and other technical measures.
- Manual material (if any) is stored in locked premises.
9. Data Retention Period
We retain personal data only for as long as is necessary to fulfill the purposes specified in this policy:
- Customer data is retained for the duration of the customer relationship and for a necessary period after its termination (e.g., 6 years as required by the Accounting Act).
- Quote request and contact data is retained for as long as managing the matter requires, or until the user requests its deletion.
10. Rights of the Data Subject
You have the right to:
- Access the data concerning yourself that is stored in the register.
- Request the rectification of incorrect or outdated data.
- Request the erasure of your data ("the right to be forgotten") if there is no longer a legal basis for processing it.
- Object to or restrict the processing of your data (for example, direct marketing).
- Withdraw your consent at any time, if the processing is based on consent.
If you wish to exercise your rights, please send a written request to the data controller's contact person (Section 2). You also have the right to lodge a complaint with the Data Protection Ombudsman if you believe we are violating data protection legislation.
