ComplianceCoded

Privacy Policy

ComplianceCoded / compliancecoded.com · eucra.fi · eucra.dev

Last updated 7 August 2026. This policy applies to compliancecoded.com and to the information sites eucra.fi and eucra.dev, both operated by Floness Oy. The eucra sites are covered separately in section 9.

1. Controller

Floness Oy (Finnish business ID 3433883-5)
Registered in Hämeenlinna, Finland
Email: [email protected]

The contact person for privacy matters is Harri Puolitaival.

2. What data we collect and from where

We collect personal data only when you interact with us through this website. The data comes from you directly and from your technical use of the site.

Email contacts. When you contact us via the email links on this site, we process your name, email address, the content of your message and any other information you choose to provide, such as your company name.

Contact and lead forms. Through our forms we process the details you submit: name, email address, company, the content of your message and which content package you are interested in.

Meeting bookings. When you book a meeting through our scheduling calendar, we process your name, email address, the time slot you select and any additional information you provide with the booking.

Newsletter and downloadable materials. When you subscribe to our newsletter or download a resource (for example a guide or checklist), we process your email address, your name and company if provided, and information about your subscription and email opens.

Technical use of the site. Using the site generates technical data: IP address, browser and device information, pages visited and time of visit. This data is processed to deliver the site and to ensure its security (Cloudflare), and with your consent for visitor analytics (Google Analytics, see section 7).

3. Why we process data and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Responding to enquiries and arranging meetingsSteps prior to entering into a contract, and legitimate interest
Sales and marketing of our services to businessesLegitimate interest (B2B)
Sending the newsletter and requested materialsConsent, which you can withdraw at any time
Website visitor analyticsConsent (cookie banner)
Website security and reliabilityLegitimate interest

We do not carry out automated decision making or profiling that produces legal effects concerning you.

4. Who receives the data

We do not sell your personal data or share it with third parties for their marketing purposes. We use service providers that process data on our behalf under a contract:

  • Cloudflare, Inc.: content delivery, security and technical protection of the site
  • Google Ireland Ltd: visitor analytics (Google Analytics 4), only with your consent
  • Our email and office software provider: handling of enquiries
  • Our scheduling calendar provider: meeting bookings
  • Our newsletter tool provider: sending the newsletter

We have entered into GDPR-compliant data processing agreements with these providers. We disclose data to authorities only where required by law.

5. Transfers outside the EU

Some of our service providers (Cloudflare and Google) may also process data in the United States. These transfers are safeguarded by the EU-US Data Privacy Framework and, where applicable, the European Commission's Standard Contractual Clauses. Otherwise data is processed within the EU and EEA.

6. How long we keep the data

  • Enquiries and sales discussions: up to 24 months from the last contact, unless the discussion leads to a customer relationship
  • Customer relationship data: for the duration of the relationship and thereafter as required by accounting and other legislation
  • Newsletter subscriber data: until you unsubscribe
  • Analytics data (Google Analytics): up to 14 months
  • Technical logs: for a short period for security purposes

7. Cookies and analytics

The site uses two kinds of cookies and similar technologies:

  • Necessary: cookies required for the site to function and stay secure (for example Cloudflare's security cookies and remembering your cookie choice). These do not require consent.
  • Analytics: Google Analytics 4 cookies used to measure visitor numbers and site usage. These are set only if you give consent in the cookie banner.

You can withdraw or change your cookie choices at any time in the site's cookie settings. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

8. Your rights

You have the right to:

  • know whether we process your personal data and receive a copy of it
  • have inaccurate data corrected
  • have your data erased
  • restrict processing
  • object to processing based on legitimate interest, including direct marketing
  • receive the data you have provided in a machine-readable format (data portability)
  • withdraw your consent at any time

To exercise your rights, send a request to [email protected]. We will respond within one month. Every newsletter also contains an unsubscribe link.

If you believe we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman, tietosuoja.fi/en.

9. eucra.fi and eucra.dev

eucra.fi (in Finnish) and eucra.dev (in English) are free information sites about the EU Cyber Resilience Act (CRA), operated by Floness Oy. The controller, your rights and the retention periods are the same as above.

  • The sites collect nothing about you. They are static sites: there are no forms, no accounts and no other way to send us personal data. The interactive test runs entirely in your browser and your answers are never sent anywhere.
  • The sites set no cookies of their own. Your cookie choice is stored in your browser's own storage, not in a cookie. If you choose "no cookies", the choice lasts only for the tab and we ask again on your next visit.
  • Analytics only with consent. If you allow all cookies, the site loads Google Tag Manager and through it Google Analytics 4, the same way compliancecoded.com does (see section 7). Nothing is loaded until you save your choice.
  • Moving to compliancecoded.com. The sites link to compliancecoded.com, and those links carry campaign tags (utm parameters) that tell us which page a visitor came from. They do not identify you.

10. How we protect the data

We protect personal data with appropriate technical and organisational measures. Site traffic is encrypted (HTTPS), access to data is limited to those who need it for their work, and we only use service providers with whom a data processing agreement is in place.

11. Changes to this policy

We update this policy when our processing practices or the services we use change. The current version is always available on this page, with the date of the latest update shown at the top.

This policy applies to the compliancecoded.com, eucra.fi and eucra.dev websites. Personal data processed when you use the ComplianceCoded service as a customer is governed by a separate data processing agreement (DPA), under which Floness Oy acts as a processor.

Suomeksi