Privacy Policy
Introduction
XMLdation Oy and its group companies (together, "XMLdation", "we", "us", or "our") are committed to protecting your personal data and respecting your privacy. We process personal data in accordance with Regulation (EU) 2016/679 (the "General Data Protection Regulation" or "GDPR") and any other applicable data protection legislation. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have.
This policy should be read alongside our Cookie Policy, which provides further detail on the individual cookies and tracking technologies we deploy, including vendor identities and cookie lifetimes. A link to the Cookie Policy is provided in Section 9.
The processing of personal data within the XMLdation Service and customer-branded XMLdation Services is governed by the applicable Data Processing Agreement (DPA) and, where relevant, the Customer Agreement.
The use of cookies within the XMLdation Service is governed separately by the applicable Customer Agreement and the General Terms and Conditions for Use of the XMLdation Service.
Table of Contents
The Privacy Policy covers the following:
- Controller
- Contact information and DPO
- Name of register
- What is the legal basis for and purpose of the processing of personal data?
- What data do we process?
- From where do we receive data?
- To whom do we disclose data and do we transfer data outside EU or EEA?
- How do we protect the data and how long do we store them?
- How do we use cookies and for what purposes?
- What are your rights as a data subject?
- Who can you be in contact with?
- Changes in the Privacy Policy
1. Controller
The data controller responsible for the processing of personal data described in this Privacy Policy is:
XMLdation Oy (Business ID: [2281265-9]), Peltokatu 26, 33100 TAMPERE, Finland
XMLdation Oy's group company, XMLdation Ireland Limited (Company Registration No.: [448531]), may act as a joint controller or as a separate independent controller in respect of personal data processed in connection with its own customer relationships and services. Where XMLdation Ireland acts as a separate controller, it will make available its own privacy notice or notify data subjects accordingly. Where it acts as a joint controller with XMLdation Oy, the allocation of responsibilities between the joint controllers is set out in a separate arrangement, a summary of which is available upon request.
2. Contact information
For any question, request, or concern relating to this Privacy Policy or the processing of your personal data, please contact us:
By post: XMLdation Oy Peltokatu 26 33100 Tampere Finland
By email: privacy [at] xmldation-dot-com
XMLdation has designated a Data Protection Officer. The DPO can be contacted:
By post: XMLdation Oy Peltokatu 26 33100 Tampere Finland
By email: privacy [at] xmldation-dot-com
3. Name of register
CUSTOMER AND MARKETING REGISTER
4. What is the legal basis for and purpose of the processing of personal data?
We process personal data only where we have a lawful basis under Article 6 GDPR (and, where applicable, Article 9 GDPR for special category data). The table below maps each processing purpose to its specific legal basis, and — where the basis is legitimate interests — identifies the legitimate interests pursued.
|
Processing purpose |
Legal basis (Art. 6 GDPR) |
|
Delivery and development of products and services |
Art. 6(1)(b) — performance of a contract |
|
Fulfilment of contractual obligations, rights, and promises |
Art. 6(1)(b) — performance of a contract |
|
Invoicing and financial administration |
Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — compliance with a legal obligation (e.g. Finnish Accounting Act) |
|
Customer relationship management and communications |
Art. 6(1)(f) — legitimate interests: Maintaining and developing business relationships with existing customers and contacts |
|
Organising marketing events |
Art. 6(1)(f) — legitimate interests: Promoting XMLdation's products and services to existing and potential customers |
|
Behavioural analysis and profiling |
Art. 6(1)(f) — legitimate interests: Understanding user behaviour and preferences to improve our services and communicate with customers and prospects more relevantly |
|
Direct and electronic marketing to existing customers |
Art. 6(1)(f) — legitimate interests: Direct marketing of similar products and services to existing customers, subject to your right to object at any time (see Section 10) |
|
Direct and electronic marketing to potential customers |
Art. 6(1)(a) — consent (where required); Art. 6(1)(f) — legitimate interests: Identifying and engaging potential business contacts |
|
Targeted advertising on our and third-party online services |
Art. 6(1)(a) — consent |
|
Processing dietary and allergy information |
Art. 9(2)(a) GDPR — explicit consent |
Categories of data subjects:
- Customer contact persons
- Newsletter subscribers
- Potential customers’s contact persons
- Information of company and company’s contact persons such as name and Business ID of the company and names, contact details, country of residence, language of use, role/title and professional interests of the contact persons;
- Information related to the account and licenses of the data subject such as account identities, software license information, access rights data;
- Information related to event participation and trainings such as the name, date and location of the events and trainings attended, dietary or allergy information. Dietary and allergy information is collected solely on the basis of your explicit consent (Art. 9(2)(a) GDPR) and is used exclusively for catering purposes at the relevant event. It is deleted promptly after the event concludes;
- Information submitted by the data subject him-/herself to XMLdation such as web form submissions, online discussion forum posts and profile information, feedback;
- Information related to the behavior of the data subject in the services and website, which is used for profiling purposes described in section 4 above such us the sites and services visited, the duration of visits/use, actions taken on the sites and in services;
- Technical information about the data subject’s end devices such as IP address, MAC address and operating system;
- cloud hosting and infrastructure services;
- customer support and technical maintenance;
- marketing automation and email marketing services;
- CRM and sales enablement platforms;
- hardware and network connectivity.
- EU–US Data Privacy Framework (DPF): for transfers to US-based processors and recipients that are certified under the DPF.
- Standard Contractual Clauses (SCCs): as adopted by the European Commission pursuant to Art. 46(2)(c) GDPR, for transfers to processors and recipients not covered by an adequacy decision or the DPF.
- Adequacy decisions: where the European Commission has determined that the destination country ensures an adequate level of data protection (Art. 45 GDPR).
- ensure website functionality;
- maintain security;
- analyze website usage;
- improve user experience;
- measure marketing effectiveness.
- Right of access: You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data together with supplementary information about how it is processed, including the purposes, categories of data, recipients, retention periods, and your available rights.
- Right of rectification: You have the right to request correction of inaccurate personal data and, taking into account the purposes of processing, completion of incomplete personal data.
- Right to erasure: You have the right to request deletion of your personal data in certain circumstances, for example, where the data is no longer necessary for the purposes for which it was collected, where you have withdrawn consent on which processing was based, or where you have exercised a valid right to object.
- Right to restriction of processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, for example, while the accuracy of data you have contested is being verified, or where you have objected to processing pending verification of whether our legitimate interests override yours.
- Right to data portability: Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have it transmitted to another controller where technically feasible..
- Object to direct marketing: You have an unconditional right to object at any time to the processing of your personal data for direct marketing purposes, including profiling carried out for direct marketing purposes. We will cease such processing immediately upon receipt of a valid objection. You may also opt-out of newsletters or direct promotional communications at any time via the provided "unsubscribe" links.
- Right to object to processing based on legitimate interests and profiling: You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests, including profiling based on those interests. Where you object, we will cease the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.
- Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact privacy@xmldation.com or, for cookie consent, use the cookie settings tool on our website.
Automated processing and profiling
We use automated decision-making (inc. profiling) to identify your online behavior and purchase habits and to build profiles based on this information. We use this information to target marketing and develop our services.
As a consequence of this profiling you may receive marketing content tailored to your interests, and certain content, offers, or advertisements you encounter on our website or on third-party platforms may be selected based on your profile. This profiling does not produce legal effects concerning you, nor does it otherwise significantly affect you in a similarly significant way by automated means alone.
You have the right to object to this profiling at any time on grounds relating to your particular situation. Please see Section 10 for details.
5. What data do we process?
We process the following categories of personal data of our customers, their employees and other data subjects (including individuals participating in our trainings and events) in connection with the Customer and Marketing register:
6. From where do we receive data?
We receive personal data concerning customers primarily from the following sources: directly from you, from the customer company you work for and from our group companies.
We receive personal data concerning potential customers primarily from the following sources: directly from you, our group companies, search engines, newspapers and other news sources, professional social media networks, contact information providers and company websites.
For the purposes described in this privacy policy, personal data may also be collected and updated from publicly available sources and based on information received from authorities or other third parties within the limits of the applicable laws and regulations. Data updating of this kind is performed manually or by automated means.
7. To whom do we disclose data and do we transfer data outside EU or EEA?
Processors (service providers)
We engage service providers acting as processors who process personal data on our behalf in accordance with our written instructions. All processors are bound by data processing agreements concluded in accordance with Article 28 GDPR, which require processors to implement appropriate security measures, process data only on our documented instructions, and not engage sub-processors without our prior written authorisation. Processors we engage include providers of:
website analytics services; and
Group companies
We disclose personal data to group companies. Data may be disclosed to authorities under compelling provisions.
Public authorities
We may disclose personal data to public authorities where required to do so by a mandatory provision of law.
International transfers
Some of our processors and group companies are located outside the EU/EEA, including in the United States of America. Categories of third-country recipients include cloud infrastructure providers and marketing platform providers.
Where we transfer personal data outside the EU/EEA, we rely on one or more of the following transfer mechanisms to ensure an adequate level of protection:
8. How do we protect the data and how long do we store them?
Security measures
We implement appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Only those of our employees, who on behalf of their working duties are required to process customer data, have access to the systems containing personal data. Each user has a personal username and password to the system. The information is collected into databases that are protected by firewalls, passwords and other technical measures. The databases and the backup copies of them are stored in locked premises and can be accessed only by certain pre-designated persons.
Retention periods
We store the personal data for as long as is necessary for the purposes for which it was collected (Art. 5(1)(e) GDPR). Our principal retention periods are:
|
Data category / Purpose |
Retention period |
|
Customer contact |
Duration of the customer relationship, and while the contact is still a prospective customer contact |
|
Invoicing and financial records |
As required by applicable law (currently 6 years under the Finnish Accounting Act) |
|
Prospective customer contact data |
Until the data is found to be outdated, or until the data subject has not engaged with any of our sales and marketing communications for a continuous period of 10 years, whichever occurs first |
|
Event/training participation data (excluding dietary information) |
Duration of the customer relationship or, for non-customer attendees, 3 years from the date of the event |
|
Dietary and allergy information |
Deleted promptly following the conclusion of the relevant event |
|
Behavioural and profiling data |
5 years from collection |
|
Website analytics data |
5 years from collection |
We regularly assess our data storage requirements against applicable law and business necessity. We take reasonable steps to ensure that no incompatible, outdated, or inaccurate personal data is retained, and we correct or erase such data without undue delay.
9. How we use cookies and for what purposes?
We use cookies and similar technologies to:
Non-essential analytics and marketing cookies are used only with your consent where required by applicable law. You may modify or withdraw cookie preferences at any time through the cookie settings functionality available on our website.
For full details of the cookies we use — including the names and lifetimes of individual cookies and the identities of third-party vendors — please see our Cookie Policy, available at: Cookie Policy
10. What are your rights as a data subject?
Under applicable data protection regulations (including GDPR), you have the following rights in relation to your personal data. These rights are subject to certain conditions and limited exceptions under applicable law.
How to exercise your rights and response timelines
To exercise your rights, please submit your request to: privacy [at] xmldation-dot-com
We will acknowledge your request without undue delay and will respond substantively within one (1) calendar month of receipt. Where your request is complex or numerous, we may extend this period by a further two (2) months; in such cases, we will notify you within the first calendar month and explain the reasons for the extension. We will not charge a fee for handling your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act, having notified you accordingly.
If we do not take action on your request, we will notify you within one calendar month of receipt, explain the reasons for our decision, and inform you of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy.
Right to lodge a complaint with a supervisory authority
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu; www.tietosuoja.fi) or another competent supervisory authority within the EU/EEA if you consider that the processing of your personal data infringes the GDPR or other applicable data protection law.
11. Who Can you Contact?
For all data protection queries, requests, or complaints, please use the contact details set out in Section 2. We will endeavour to address your concern promptly. If you remain dissatisfied following contact with us, you may lodge a complaint with the Finnish Data Protection Ombudsman or another competent EU/EEA supervisory authority, as described in Section 10.
12. Changes in the Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, applicable law, or best practice. The updated Privacy Policy will be published on our website with a revised "Last updated" date. Where changes are material, for example, where we introduce new processing purposes, change the legal basis for existing processing, or add new categories of recipients, we will notify you in advance by email or by a prominent notice on our website, and where required by law we will seek your consent before making the change. Continued use of our services following notification of a material change constitutes acknowledgement (but not consent, where consent is separately required) of the updated Policy. We encourage you to review this Privacy Policy periodically.
Last updated: 24/08/2026
