Updated 4 September 2026

This privacy notice explains what information is collected about you on this website and in the course of our customer relationship, what it is used for, and how long it is retained. It has been written to be easy to read, not merely to comply with legal requirements.

In brief

  • The site does not set tracking cookies and does not use Google Analytics, the Facebook pixel or any other external tracking tools.
  • We have implemented our own visitor tracking system, which does not store IP addresses, browser identifiers or session IDs. It therefore does not process any personal data.
  • Data is only collected when you fill in a form or are a customer.
  • Data will not be sold, rented or disclosed to third parties for marketing purposes.
  • Customers’ websites are hosted in Finland, in a data centre in Helsinki. No data is transferred outside the EU or the EEA.

1. Data controller

Bastinet
, company registration number 2492063-7
, Teknologiantie 18, 90590 Oulu
, info@bastinet.fi
, 046 804 5468

The contact person for data protection matters is Sebastian Rantala. No separate data protection officer has been appointed, as the law does not require this for an organisation of this size.

This privacy notice applies to the website bastinet.fi. If you are a visitor to our client’s website, the data controller for that site is the company itself, not Bastinet. We maintain the site on its behalf, as agreed in the terms and conditions.

2. What information is collected

Contact and quote request form

Name, email address, telephone number, company name, the service you are enquiring about, the content of your message, the time it was sent and the page from which the form was submitted.

Order

In addition to the above: business registration number, product ordered, price at the time of ordering, version of the accepted terms and conditions, and the IP address of the shipment.

The IP address is only recorded when an order is placed, not when you contact us. The reason for this is that an order constitutes a binding contract, and the time and address of dispatch serve as proof of its formation. Without these details, it would be difficult to prove retrospectively that a contract had been formed, to the benefit of either party.

Customer relationship

Names and contact details of contact persons, invoicing details, contracts, correspondence relating to the assignment and notes on the progress of the work.

Server log data

The server logs the IP address, time, requested URL and browser identifier for every page request. This is standard behaviour for server software, and the logs are required for troubleshooting faults and defending against attacks. Log data is not linked to form data, nor is it used for marketing purposes.

Visitor analytics

The site automatically tracks which pages are viewed and which links are clicked. The tracking records the time, the page URL, the item clicked, the referring page and whether the device was a mobile phone or a computer.

The tracking system does not record IP addresses, browser identifiers or session IDs, nor does it store anything on your device. Individual visitors cannot be identified, nor can their visits be linked to one another. It does not therefore constitute personal data, and the tracking does not require consent.

The decision was a conscious one: a ready-made analytics service would have been easier, but it would have meant a cookie banner and the transfer of visitor data to a third party.

3. What is the data used for and on what basis?

  • Responding to enquiries and providing quotations. Basis: processing your request, i.e. activities prior to entering into a contract.
  • Order fulfilment and customer relationship management. Basis: contract.
  • Invoicing and bookkeeping. Basis: statutory obligation.
  • Technical maintenance and data security of the service. Basis: legitimate interest in keeping the service operational and secure.
  • One reminder regarding an incomplete order form. Basis: legitimate interest. A maximum of one reminder will be sent, and each will contain a link allowing you to delete your details immediately.

Your data will not be used for automated decision-making or profiling. We will not send you a newsletter or marketing emails without your explicit consent.

4. How long is data retained?

InformationRetention period
An enquiry that does not result in a customer12 months
Incomplete order form30 days
Offer not accepted12 months
Server credentials, if any have had to be disclosedwill be removed as soon as the work is completed
Orders, contracts and invoicing details6 years (Accounting Act)
Customer data following the termination of the customer relationship24 months
Server log dataup to 12 months
Visitor analytics dataNo personal data; stored indefinitely

Once the retention period has expired, the data will be deleted or anonymised so that it can no longer be used to identify an individual.

5. To whom is data disclosed?

Data will not be sold, rented or disclosed to third parties for marketing purposes. Data will only be processed by those parties necessary for the provision of the service:

  • Data centre. The servers are under our control and are located within the EU; our customers’ websites are in Finland. The data centre operator does not process the data for its own purposes nor does it have access to the content.
  • Accountancy and auditing. Invoicing details for statutory accounting.
  • Debt collection. Only if an invoice remains unpaid despite several reminders.
  • Subcontractors. If a subcontractor is used for a project, they will only see the information required to carry out the work and are bound by a duty of confidentiality.
  • Public authorities. Only where required by law.

No data is transferred outside the EU and the EEA.

6. Cookies

The website does not set any tracking or marketing cookies on visitors’ devices, and therefore does not display a cookie banner. The absence of a banner is not an oversight: it is not needed because no cookies are set.

Technical cookies are used in only two situations: when the site administrator logs into the control panel, and when the site is previewed before publication. Neither of these applies to ordinary visitors.

Furthermore, the site does not load any external fonts, maps, video services or share buttons that would send information about your visit elsewhere. All parts of the site are hosted on its own server.

7. Data security

  • All traffic is encrypted (HTTPS).
  • Form data is stored in a database that is not accessible via the internet.
  • Access to the control panel is restricted to authorised users only.
  • Backups are taken daily and stored securely.
  • The form does not ask for the customer’s server credentials. If it is necessary to provide them, this is done via a one-off link; the details are encrypted and deleted immediately once the work is complete.

If, despite this, a data breach occurs and is likely to pose a risk to your rights, you and the Office of the Data Protection Commissioner will be notified within the timeframe required by law.

8. Your rights

You have the right to:

  • to find out what information we hold about you and to obtain a copy of it
  • Correct incorrect information
  • requests the deletion of data insofar as retention is not required by law
  • restrict or object to processing based on a legitimate interest
  • to receive the information you have provided in a machine-readable format
  • You can withdraw your consent at any time

Requests can be sent by email to info@bastinet.fi. A response will be provided within one month. There is no charge for making a request. You may be asked to verify your identity before any information is disclosed, to ensure that the information is not disclosed to the wrong person.

9. Right of appeal

If you believe that your personal data has been processed incorrectly, you can lodge a complaint with the supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman, tietosuoja.fi.

We hope you’ll get in touch with us first — most matters can be sorted out with a single email.

10. Changes to this policy

This policy will be updated whenever there are changes to how data is processed. The date of the last update is shown at the top of the page. Customers will also be notified of any significant changes by email.

The terms and conditions governing the contractual relationship are set out separately in the terms and conditions.