How Transtar Networks collects, uses, and protects personal data, under EU law.
Transtar Networks Oy (business ID 3407638-8, Hitsaajankatu 6 A 40, 00810 Helsinki, Finland) is the controller of the personal data described in this policy, processed in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable EU data protection law. Where Transtar processes personal data on behalf of a customer, the Data Processing Agreement governs that processing.
We collect account and contact data (name, business email, organisation, role), authentication data, and usage data (logs, interactions with the Services). We collect data you submit when you contact us or apply to our programmes. We do not intentionally collect special categories of personal data.
We process personal data to provide and operate the Services (performance of a contract), to communicate with you and respond to enquiries (legitimate interests), to comply with legal obligations, and, where required, on the basis of your consent (which you may withdraw at any time).
We share personal data only with vetted subprocessors who process it on our behalf under a data processing agreement — currently Google Cloud, Microsoft Azure, and Amazon Web Services, operating within EU regions for customer data. We do not sell personal data. We may disclose data where required by law.
Personal data is processed within EU regions. We do not transfer personal data outside the EU in our standard operations. Where a transfer is ever necessary, it is governed by an appropriate mechanism under Chapter V GDPR, including Standard Contractual Clauses.
We retain personal data only as long as necessary for the purposes described, to comply with legal obligations, or to resolve disputes. When no longer needed, data is deleted or anonymised.
Under the GDPR, you have the right to:
You may exercise these rights by contacting us. You also have the right to lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu).
We use only essential cookies required to operate the site and any analytics cookies for which we have a lawful basis. You can control cookies through your browser settings.
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, least-privilege access control, and audit logging. See our Compliance & Trust page for detail.
We may update this policy from time to time. Material changes will be communicated through the Services or by notice. The "last updated" date reflects the latest revision.