Get Started

GDPR & Privacy

Clear information about how we handle personal data.

This privacy notice explains how Vemelo Oy processes personal data when you visit our website, contact us, or use our services. It follows the EU GDPR and Finnish data protection law.

Last updated: August 2026

Aligned with EU GDPR requirements Prepared under Finnish data protection law Your rights are clearly explained
Data Controller Vemelo Oy, Espoo, Finland
Legal Framework EU GDPR and Finnish law
Your Rights Access, correction, erasure, and more
01

Data Controller

The data controller responsible for the processing of personal data described in this notice is Vemelo Oy (Business ID 3649128-6), Matinniitynkuja 7 A 14, 02230 Espoo, Finland.

For privacy-related requests, contact us at info@vemelo.com.

02

Personal Data We Collect

Depending on how you interact with us, we may process the following categories of personal data:

  • Contact details such as name, email address, phone number, and company name
  • Information you provide in contact forms, project inquiries, or email correspondence
  • Technical website data such as IP address, browser type, device information, and pages visited
  • Communication records related to customer relationships, support, or project delivery
03

Purposes and Legal Bases

We process personal data only when we have a valid legal basis under Article 6 of the GDPR:

  • Responding to inquiries and preparing proposals: performance of pre-contractual steps or legitimate interest
  • Delivering agreed services and managing customer relationships: performance of a contract or legitimate interest
  • Operating, securing, and improving our website: legitimate interest
  • Complying with legal obligations: legal obligation
  • Marketing communications where applicable: consent, which you may withdraw at any time
04

Data Retention

We retain personal data only for as long as necessary for the purposes described in this notice.

Contact and inquiry data is generally retained for up to 24 months unless a longer retention period is required to manage an ongoing customer relationship, resolve a dispute, or comply with applicable law.

Technical logs are retained for a limited period required for security, troubleshooting, and service reliability.

05

Recipients and Processors

We do not sell personal data. We may share data with trusted service providers who process data on our behalf, such as hosting, email, analytics, or project management tools.

These processors act only according to our instructions and under appropriate data processing agreements as required by the GDPR.

06

International Transfers

We aim to process and store personal data within the European Economic Area (EEA).

If data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or another lawful transfer mechanism under the GDPR.

07

Your Rights

Under the GDPR and Finnish data protection law, you have the following rights where applicable:

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interests
  • Right to withdraw consent at any time, without affecting prior lawful processing
08

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu).

More information is available at tietosuoja.fi.

09

Changes to This Notice

We may update this privacy notice when our processing activities, services, or legal requirements change. The latest version will always be published on this page.

Privacy questions?

Contact us about access requests, corrections, or any other privacy matter. We respond within the time limits set by applicable law.

info@vemelo.com