Privacy Notice

Effective from: 9 August 2026

Scope: This notice applies to the finbe.fi website, enquiries made through the website or by email, and contact details of business-customer and cooperation-partner representatives. Separate service-specific privacy notices will be provided for Brainwave Balance, Brainwave Companion and other services that process personal data before personal-data processing begins in the relevant service.

Controller

FinBe Oy

Website: https://www.finbe.fi

Privacy enquiries: tiina@finbe.fi

Purposes and legal bases

We process personal data to respond to enquiries, manage customer relationships and cooperation discussions, provide services, and ensure the technical security and reliability of the website.

Processing related to enquiries and pre-contractual measures is based on Article 6(1)(b) GDPR. Managing customer and stakeholder relationships and maintaining website security are based on legitimate interests under Article 6(1)(f). Compliance with legal obligations is based on Article 6(1)(c). Electronic direct marketing is based on consent where required by law.

Personal data processed

We may process a person's name, job title, organisation, email address, telephone number, the content of an enquiry and related communications, and information necessary for managing a customer or cooperation relationship.

The web server may process technical log data such as IP address, time, requested page, browser or device information and error data. We do not request health data or other special-category data in website enquiries.

Special-category personal data

FinBe does not request health data, biometric data or other special-category personal data through the website's general enquiry channels.

Such information should not be sent by ordinary email or through the website's general contact channel.

Sources of data

Data are primarily obtained directly from the person when they contact us. A business contact's details may also be obtained from their employer, public professional sources, or an existing customer or cooperation relationship.

Recipients and processors

Only persons whose duties require it process data on behalf of FinBe Oy. Contracted hosting, domain, email, backup and IT providers may process technical data. The website hosting provider is Zoner Oy.

Data may be disclosed to authorities where required by law. Personal data are not sold.

Transfers outside the EEA

FinBe Oy aims to use processing located within the EEA. If a provider processes data outside the EEA, the transfer will rely on a lawful transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, with supplementary safeguards where necessary.

Retention

Enquiries are retained while the matter is handled and generally for no longer than 24 months after the latest contact, unless longer retention is necessary for a contract, legal claim or statutory obligation. Customer and contractual data are retained during the relationship and thereafter according to applicable accounting, liability and limitation periods. Technical logs are retained only as long as necessary for security and troubleshooting.

Data subject rights

Depending on the circumstances, a data subject has the right of access, rectification, erasure, restriction, objection to processing based on legitimate interests, and data portability where the legal requirements are met. Consent may be withdrawn at any time without affecting processing carried out before withdrawal.

Requests may be sent to tiina@finbe.fi. Identity may need to be verified. A data subject may lodge a complaint with the Office of the Data Protection Ombudsman in Finland: https://tietosuoja.fi/en.

Automated decision-making

Personal data relating to website enquiries are not used for automated decision-making or profiling that produces legal or similarly significant effects concerning an individual.

FinBe's services do not make automated employment or personnel decisions.

Any automated processing, data sources, purpose of processing and user rights will be described separately in the relevant service-specific privacy notice.

Security

Data are protected through access controls, technical safeguards, maintained systems, backups and contractual arrangements with providers. Absolute security cannot be guaranteed, but detected incidents are handled in accordance with applicable law.

Changes

This notice will be updated if the processing or applicable requirements change. The current version will be published on this page.