Privacy Policy
This Privacy Policy explains how Quarrionthitai (“we”, “us”) processes personal data when you use our website and related contact channels. We operate from Finland and aim to meet the requirements of the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Data controller
The controller responsible for processing personal data is:
Quarrionthitai
Pohjoinen Makasiinikatu 9
00130 Helsinki
Finland
Email: callback@quarrionthitai.world
Phone:
+358 9 315 87230
2. Categories of personal data we collect
Depending on how you interact with us, we may process:
- Identity and contact data: name, email address, telephone number if you provide them.
- Message content: text you include in forms or email correspondence.
- Technical data: IP address, browser type and version, device type, operating system, referring URLs, time zone, and similar server log information.
- Usage data: pages viewed, approximate time on page, and interaction events when analytics tools are active and permitted.
- Cookie and similar technologies data: identifiers stored on your device when you accept optional cookies. See our Cookie Policy for details.
3. Sources of personal data
We receive personal data directly from you (for example when you submit a contact form), automatically when you browse our site, and, if you consent, through analytics or marketing technologies described in the Cookie Policy.
4. Purposes and legal bases for processing
4.1 Website operation and security
We process technical data to deliver pages, protect against abuse, troubleshoot errors, and maintain secure connections. Legal basis: legitimate interests (Article 6(1)(f) GDPR) in operating a secure website, balanced against your rights.
4.2 Responding to enquiries
We process identity, contact, and message content to read and reply to your requests. Legal basis: steps prior to a contract or legitimate interests in responding to outreach; where consent is required for specific communications, we will ask separately.
4.3 Analytics
If you enable analytics cookies, we process usage data to understand aggregate traffic patterns and improve content structure. Legal basis: consent (Article 6(1)(a) GDPR), where required.
4.4 Marketing
If you enable marketing cookies or sign up for optional communications where offered, we may process relevant data to deliver or measure such communications. Legal basis: consent (Article 6(1)(a) GDPR) or, where applicable, legitimate interests with an opt-out.
4.5 Legal compliance
We may process data where necessary to comply with legal obligations, respond to lawful requests from public authorities, or establish or defend legal claims. Legal basis: legal obligation (Article 6(1)(c) GDPR) or legitimate interests (Article 6(1)(f) GDPR), as applicable.
5. Recipients and processors
We use trusted service providers who process data on our instructions, such as hosting providers, email delivery services, and analytics or marketing platforms if you consent. We require processors to implement appropriate confidentiality and security measures under written agreements where required by law.
5.1 Advertising and measurement (including Google services)
If you consent to analytics or marketing cookies, data may be processed by providers such as Google Ireland Limited (Google Analytics, Google Ads conversion measurement, or similar products). Processing may include online identifiers, device information, and interaction data. Google publishes privacy information at https://policies.google.com/privacy. We configure such tools to respect your choices and applicable EU and Finnish requirements, including consent where required for non-essential cookies and similar technologies.
We use advertising only to direct visitors to this informational website. We do not sell personal data. Aggregated or pseudonymous statistics may be used to understand whether campaigns reach relevant audiences.
6. International transfers
If personal data is transferred outside the European Economic Area, we ensure appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or other mechanisms recognized under GDPR, unless an adequacy decision applies.
7. Retention periods
- Contact form and email enquiries: typically up to twenty-four (24) months after the last message in a thread, unless a longer period is needed for legal claims or compliance.
- Server logs: typically up to ninety (90) days, unless longer retention is required for security investigations.
- Analytics and marketing records tied to cookies: according to the lifespan stated in our Cookie Policy and your choices, generally not longer than twenty-four (24) months for analytics aggregates where feasible.
- Legal holds: data may be retained longer where required by law or for the establishment, exercise, or defence of legal claims.
8. Security measures
We apply administrative, technical, and organisational measures appropriate to the risk, including HTTPS encryption for site delivery, access controls for internal systems, vendor review, and staff confidentiality expectations. No method of transmission or storage is completely secure; we work to reduce risk in line with industry practice.
9. Your rights under GDPR
Subject to conditions in applicable law, you may have the right to:
- Access your personal data and obtain certain information about processing.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”) in certain cases.
- Restriction of processing in certain cases.
- Data portability for data you provided where processing is based on consent or contract and is automated.
- Object to processing based on legitimate interests, including profiling under certain conditions.
- Withdraw consent at any time where processing is consent-based, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with a supervisory authority, in Finland the Office of the Data Protection Ombudsman (https://tietosuoja.fi/en/).
To exercise your rights, contact us using the details in Section 1. We may need to verify your identity before responding.
10. Automated decision-making
We do not use automated decision-making, including profiling, which produces legal or similarly significant effects concerning you, unless we notify you separately and provide a lawful basis.
11. Children
This website is directed at adults. We do not knowingly collect personal data from children without appropriate parental authority. If you believe we have received such data, please contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy to reflect legal, technical, or organisational changes. The “Last updated” date will change accordingly. Material changes will be highlighted on this page or through another appropriate notice where required.
13. Contact
For privacy questions or requests: callback@quarrionthitai.world or write to the postal address above.