Hydrohex

Legal · Business customers

Privacy Policy

Last updated: 6th July 2026

We value your fundamental right to privacy. As a company based in the European Union, we adhere to our obligations under the General Data Protection Regulation (GDPR). In this document, we inform you about our processing of your personal data if you’re a business customer (or a representative of one).

The document is structured in two parts:

  • Part 1 — general information about personal-data processing.
  • Part 2 — specific processing practices for business customers.

We may update this policy periodically. Minor changes appear in this document; significant changes affecting your rights are communicated by email or notification.

If you have any questions or concerns regarding the processing of your personal data at Hydrohex, please don’t hesitate to contact us:

Contact

Hydrohex Oy Ltd · Privacy team
privacy@hydrohex.com

Part 1

General information

Categories of personal data

Regularly processed

  • Name, contact details and position
  • Messages and correspondence
  • Financial information and public records (e.g. to fulfil our financial due diligence or to make sure that you are entitled to represent your company)
  • Payment information and history

Occasionally processed

  • Technical identifiers (device IDs, IP addresses, geolocation)
  • Video, sound recordings and photographs (e.g. if we record a video seminar that you attend, or if we record a customer service phone call)
  • Preferences and activity (e.g. if we take notes of your customer service interactions and our customer relationship activity with you)
  • Social media content and other public information (e.g. if we take notes of your company’s online presence or check your information for marketing purposes)

Mandatory data categories

Some categories of personal data are mandatory in the sense that without certain data, we cannot provide our services to you or carry out other critical processes related to our customer relationship. In some cases we may also have a legal duty to process certain categories of your personal data.

Part 2 clearly identifies the mandatory data for each purpose.

Data sources

Primary sources include direct communication with you. Secondary sources include:

  • Public records and business registers
  • Marketing registers
  • Company-provided information
  • Social media and internet sources
  • Technical sources (cookies, scripts, databases)

Data-retention principles

Hydrohex follows data-minimisation principles, retaining personal data only as long as necessary for the stated purposes and legal bases under GDPR. Data is destroyed or irreversibly anonymised once its purpose expires. Part 2 specifies retention periods for each purpose.

Sharing personal data with third parties

As a commercial service provider, we like most other companies have to outsource some of the processing of your data to trusted partners. Because of that, we transfer certain categories of personal data to third parties.

We always make sure that all transfers are protected by a contractual arrangement between us and our trusted partners as required by the GDPR.

Partners fall into the following categories:

Website, data storage and technical operations

  • Web hosting companies
  • Content-management services and content delivery networks
  • Cloud storage providers
  • Online collaboration tools

Communications and deliveries

  • Email and messaging services
  • Chatbox service providers
  • Video-call platforms
  • Postal and delivery services

Financial service providers

  • External accountants and auditors
  • Accounting-software providers
  • Banks and payment processors

Professional advisers

  • Law firms
  • Business consultants

Customer and contract management

  • Customer-management services
  • Digital-signature services
  • Calendar and booking services

Public authorities

  • Information lawfully requested by authorities

Transfers outside the EU / EEA

Personal data is normally processed within the EU / EEA. When data is transferred outside these regions, Hydrohex ensures protection through appropriate safeguards. Some of your personal data are transferred to the following countries:

  • United States: the EU–US Data Privacy Framework or Standard Contractual Clauses (SCCs) issued by the European Commission.
  • United Kingdom: covered by the European Commission's adequacy decision for the UK, which recognises the UK as ensuring an adequate level of data protection — so personal data can be hosted and processed there without additional safeguards. Some of our systems and hosting are located in the UK.

Your rights under GDPR

According to the GDPR, you have various rights as we process your personal data. These are:

Right of access

You may request whether Hydrohex processes your personal data and obtain a copy of some or all of the data. You also have a right to ask for more information regarding the third-party recipients of your personal data as well as our protective measures applicable to the transfers of your data to our trusted partners and outside the EU/EEA. A copy of your data will be deliverd electronically. Repeated or manifestly unfounded requests may be refused or incur an administrative fee.

Rectification

You may request correction or completion of inaccurate or incomplete data. We will investigate your request without undue delay, and accommodate it if we can be sufficiently certain that the request is justified.

Erasure (“right to be forgotten”)

You may request deletion of your personal data, though Hydrohex may refuse or postpone the request where an ongoing business relationship requires your personal data to perform our services, or if we have a legal duty or a legitimate interest to retain some of your data (we have described these in more detail in Part 2).

Restriction of processing

You may request temporary suspension of processing if you believe a GDPR violation exists. You may also ask us that we do not erase or otherwise process your personal data if you need the data e.g. in a legal dispute and the erasure or other processing would jeopardise your interests in that regard.

Objection to processing

You may object to processing based on legitimate interests or direct marketing. We will accommodate requests where possible, though significant legitimate interests may prevail. If we cannot accommodate a request, we will explain our reasons and inform you of your right to lodge a complaint with the relevant data protection authority. Where we have contacted you for direct marketing, you may also object our processing of your personal data for that purpose, and we will comply without undue delay.

Withdrawal of consent

As explained in detail in Part 2, we sometimes process your personal data on the basis of your consent. If that’s the case, you may, at any time, withdraw your consent for that processing. We will accommodate your request without undue delay, however we may continue the processing if we have another legal basis to do so. Please note that withdrawing consent will not affect the prior processing of your personal data.

Right to lodge complaints

You may file a complaint with the relevant data-protection authority over an alleged GDPR breach.

To exercise any of these rights, contact us using the details above.

Cookies and tracking

Hydrohex uses cookies and similar technologies on its websites and services in compliance with applicable laws. Detailed information appears in our cookie policy.

Part 2

Processing of business-customer data

As a business customer (or a representative of one), your personal data is processed in the context of our business relationship. Below we set out the purposes and legal bases for that processing, along with the categories of personal data involved and their retention periods.

Purposes and legal bases

GDPR requires every processing activity to have a legal basis. Hydrohex relies on the following bases:

Contract (including preparation)

Processing necessary to perform a customer contract.

Legal obligation

Processing required by commercial or regulatory duties (financial records, compliance).

Consent

Processing based on your explicit consent within defined limits (cookies, statistics).

Legitimate interest

Processing justified after balancing your rights against our legitimate business interests. Contact us for details.

Processing purposes and legal bases

PurposeLegal basisExamples
Performing servicesContractIn order to perform our services as contracted, we need to process some of your personal data.
Legitimate interestAs we perform our services to you, we have a justified interest in processing some of your personal data, e.g. to improve our services.
Maintaining and developing our customer relationshipContractApart from performing our services, we do a number of things to maintain our contractual relationship with you.
Legitimate interestTo improve our customer experience, we may conduct case studies about our customer relationship.
Billing and debt collectionContractAs we perform our services to you, we bill you as agreed in our contract. To send an invoice, we need to process some of your personal data.
Legal obligationWe have legal duties to keep records of our business transactions. For instance, our invoices must contain certain information which may be your personal data.
Accounting and taxationContractTo keep records of our sales and business transactions, we store and retain information about our dealings with you.
Legal obligationWe have a legal duty to keep records of our business transactions. For instance, we must store and retain our invoices for a number of years.
Risk management and protecting interestsContractTo manage mutual risks and protect the interest of you and us, we need to keep records of our due diligence processes, contractual relationships and business dealings.
Legal obligationIn some cases, we may have to process certain background information as a legal duty. For instance, we may have to check and store information about economic sanctions.
Legitimate interestTo manage risks and to protect various business interests, we process certain categories of personal data. For instance, we keep records of our contractual relationships and business dealings for a number of years in case a legal dispute arises.
CommunicationsContractAs part of our customer relationship with you, we often have discussions and correspondence with you. We store and retain these if they are relevant to our contractual relationship.
ConsentIn some cases, for instance if you contact us using a medium that processes certain technical identifiers, we may ask for your consent for processing the identifiers.
Legal obligationIn some cases, we have a legal obligation to store and retain our communications with you. This may be the case for instance if we must include our correspondence as an exhibit in our financial records.
Legitimate interestIn some cases, we store and retain our communications for various legitimate interests such as improving our customer service and training our staff.
Sales and marketingConsentIn some cases, to process your personal data for sales and marketing purposes, we ask for your consent. This is the case for instance when we use cookies and similar technologies for such purposes.
Legitimate interestAs a commercial service provider, we have a justified reason for instance to approach you with the purpose of discussing our offering with you.
Technical functioning and securityContractSome of the services that we provide to you under our contract process personal data for technical reasons. For instance, to offer you our online services, we need to ensure the proper technical functioning and security of the platform.
ConsentIn some cases we offer you technical functions that do not strictly relate to our contractual relationship. This is for instance if you access our website for unrelated reasons.
Legitimate interestIn some cases we have a justified reason to ensure the proper functioning and security of our services. In those cases we process certain technical personal data as part of our legitimate interests.

Data categories and retention periods

Below is a list of our retention times for different categories of personal data under a given purpose. Once a specific retention period runs out, we will destroy the relevant personal data or anonymise it irreversibly, unless a different purpose with a longer retention period applies.

For instance, we keep personal data for the purposes of communications (like e-mails containing your name and e-mail address) for 1 year. Once the retention period runs out, we will destroy the relevant data unless we need to keep it for the purposes of risk management for 3 years. If so, we will continue to retain the data until the 3-year retention period runs out.

PurposeCategory of personal dataRetention period(s)Examples
Performing servicesName, contact details, position1 year from the end of performanceTo perform and deliver our services to you, we need to process your personal data. We will keep the data in an active dossier for 1 year in case there are for instance immediate issues that have to be fixed.
Messages and correspondence
Technical identifiers
Maintaining and developing our customer relationshipName, contact details, position1 year from the end of customer relationship, or 5 years from collection and storage, whichever is soonerTo maintain and develop our active relationship, we will process your personal data. We will store the data in your customer dossier, and if the customer relationship ends (or you no longer represent your company towards us), we will retain the data for a safety period of 1 year.
Messages and correspondence
Preferences and activity
Billing and debt collectionName, contact details, position1 year from the end of the current financial yearAs we bill you for our services, we process your personal data on invoices and in transaction records. We will retain that information for the current financial year and 1 year after that in order to keep our business records up to date.
Financial information and public records
Payment information and payment history
Accounting and taxationName, contact details, position1 year after the current financial year (except legally prescribed information); 6 years after the current financial year (legally prescribed information)As part of our annual accounting, we store and retain relevant personal data for the current financial year and 1 year after it. Some information, such as invoices and receipts, must be retained for a legally prescribed period, which is 6 years. During that period, we will only retain personal data which is necessary for that purpose.
Messages and correspondence
Financial information and public records
Payment information and payment history
Risk management and protecting interestsName, contact details, position3 years from collection and storageTo protect your and our legitimate interests, we retain personal data for 1 to 3 years from the last instance of active processing (except in case of cookies and similar technologies, whose retention periods are stated in our cookie policy). We do so so that for instance in case of a legal dispute about our contract or service, any critical evidence will not have been destroyed.
Messages and correspondence
Financial information and public records
Payment information and payment history
Video and sound recordings and photographs
Technical identifiers1 year from collection and storage (except as stated in cookie policy)
Social media content and other public information1 year from collection and storage
CommunicationsName, contact details, position1 year from the communicationWe retain personal data from our communications with you for 1 year in case we want to continue the discussion at a later time.
Messages and correspondence
Technical identifiers
Social media content and other public information
Sales and marketingName, contact details, positionFor the time beingAs we have a legitimate interest in approaching you to discuss our offering, we keep your name, contact details and position on file for the time being, however only as long as you represent the company that is or has been our customer. This means we may contact you some time in the future unless you prohibit us from doing so.
Messages and correspondence3 years from collection and storageIf we haven’t had any business dealings with you (or your company) for the past 3 years, we’ll erase or anonymise your personal data unless we continue to retain them under another purpose.
Video and sound recordings and photographs
Preferences and activity
Technical identifiers
Social media content and other public information
Consents and prohibitionsIf you have prohibited us from approaching you for sales and marketing purposes, we’ll make a note of it and retain it indefinitely (or until you instruct us otherwise).
Technical functioning and securityName, contact details, positionImmediatelyWe’ll destroy or anonymise your personal data immediately once they aren’t needed for the relevant purpose. Note however that our cookie management system stores cookies (which may include your personal data) in accordance with our cookie policy.
Technical identifiers1 year from the last active processingWe keep technical identifiers for 1 year from the last active processing (unless stated otherwise in our cookie policy) in case we need to investigate a technical or security issue in the future.
Consents and prohibitionsIf you have prohibited us from processing your personal data for non-necessary technical purposes, we’ll make a note of it and retain it indefinitely (or until you instruct us otherwise). Note however that our cookie management system stores your cookie and tracking preferences in accordance with our cookie policy.

Company information

Hydrohex Oy Ltd

Business ID: 2705400-9

Yliopistonkatu 23 A 4
20100 Turku
Finland

Privacy team · privacy@hydrohex.com

© Hydrohex Oy Ltd 2024. Available in English, Suomi, Svenska and Deutsch.