Promentor Solutions Logo
Home
Growth & Restructuring Customer-facing Teams International Employees International Students Courses & Content
About Contact Blog
Suomi English
login
Home
Services
Growth & Restructuring Customer-facing Teams International Employees International Students Courses & Content
About Contact Blog
EN | FI
login Login

Privacy Policy

Privacy Policy

Last Updated: June 10, 2026

At Promentor, we are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website, submit inquiries through our contact forms, or interact with our services, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.


1. Data Controller

The entity responsible for processing your personal data (the "Data Controller") is:

  • Company Name: Promentor Solutions Oy
  • Business ID / Registration Number: 0701901-1
  • Address: Olarinluoma 7 A, 02200 Espoo, Finland
  • Email Address: privacy@promentor.fi
  • Contact Person: Juha Telkkinen, CEO

2. Personal Data We Collect

We collect and process personal data that you provide directly to us, as well as data collected automatically through technology when you browse our website.

A. Data You Provide to Us

When you fill out and submit our website's Contact Form, we collect the following personal data:

  • Full Name (Required)
  • Email Address (Required)
  • Phone Number (Optional)
  • Company/Organization Name (Optional)
  • Message/Enquiry Details (Required) — The text of your message, which may contain other personal details you choose to share.
  • GDPR Consent Log — We record the timestamp and text of the consent you gave when submitting the form ("I agree that Promentor may store and process my personal data to respond to this enquiry, as described in the Privacy Policy.").

B. Data Collected Automatically (Cookies and Tracking)

When you browse our website, we use cookies and tracking technologies to collect standard internet log information and details of visitor behavior patterns. This includes:

  • IP Address (anonymized/truncated where applicable)
  • Device and Browser Information (device type, operating system, browser version, language settings)
  • Usage Data (pages visited, time spent on pages, referral source, interaction with elements)
  • Consent Selection Logs (whether you accepted or declined cookies, and for which categories)

These technologies are managed using Cookie Script and Google Tag Manager.


3. Purposes and Legal Bases for Processing

Under GDPR, we must have a valid legal basis to process your personal data. The table below details why and on what legal basis we process your data:

Purpose for Processing Categories of Personal Data Legal Basis under GDPR
Responding to Enquiries & Lead Management: To receive, process, and answer your requests submitted via the contact form, and manage prospective business relationships in our CRM. Name, email address, phone, company, message, consent timestamp. Consent (Art. 6(1)(a) GDPR): You explicitly consent to this processing by checking the agreement box on the contact form.
Website Analytics & Optimization: To analyze website usage, compile statistics, and optimize user experience, performance, and features. IP address, device/browser details, usage statistics, cookies. Consent (Art. 6(1)(a) GDPR): You choose to accept performance/analytical cookies via our Cookie Script banner.
Consent Compliance & Auditing: To document and maintain records of consent selections made for cookies and forms (as required by GDPR compliance audits). IP address (anonymized), consent choices, timestamp, consent statement text. Legal Obligation (Art. 6(1)(c) GDPR): To comply with our legal requirement to document consent under GDPR.
Security & Technical Stability: To detect and prevent security threats, fraud, abuse, and to ensure the website and serverless functions operate reliably. Server logs, IP address, user-agent details. Legitimate Interest (Art. 6(1)(f) GDPR): Our legitimate interest in keeping our website and services secure and functional.

4. Recipients of Your Personal Data (Third-Party Processors)

To operate our website and services, we share your data with selected third-party service providers (data processors) who act on our behalf. These processors are contractually bound to process your data only in accordance with our instructions and GDPR requirements:

  1. Pipedrive Inc. (CRM Platform):
    • Purpose: Lead management, communication tracking, and CRM storage.
    • Data Shared: Contact form submissions (Name, email, phone, company, message, consent details).
    • Privacy Info: Data may be stored in Pipedrive's European databases, or transferred under strict legal safeguards (e.g. Standard Contractual Clauses) if processed internationally.
  2. Cookie-Script (Consent Management):
    • Purpose: Displaying the cookie consent banner, collecting, and documenting your cookie preferences.
    • Data Shared: Anonymized consent selections, timestamps, and cookie identifiers.
    • Privacy Info: Provided by Objectis Ltd (Lithuania, EU).
  3. Google Ireland Limited (Google Tag Manager):
    • Purpose: Deploying tracking, analytics, and performance scripts. GTM does not store personal data itself but acts as a trigger mechanism for tags (e.g., Google Analytics).
    • Data Shared: Pseudonymized technical logs, device details.
  4. Vercel Inc. (Web Hosting & Serverless Functions):
    • Purpose: Hosting the website infrastructure and processing backend submissions (API routes).
    • Data Shared: Standard server connection logs (IP address, user-agent) and transient form payload data.
  5. Storyblok GmbH (Content Management System):
    • Purpose: Content management and rendering pages dynamically.
    • Data Shared: Page routing requests (does not receive personal data from contact forms).

5. International Data Transfers

Some of our service providers (such as Pipedrive, Vercel, and Google) are headquartered or operate infrastructure outside the European Economic Area (EEA), primarily in the United States.

To ensure your personal data receives an adequate level of protection when transferred outside the EEA, we ensure that:

  • The recipient country has been deemed to provide an adequate level of protection by the European Commission; or
  • We use standard contractual clauses (SCCs) approved by the European Commission; or
  • The recipient participates in the EU-U.S. Data Privacy Framework.

6. How Long We Keep Your Data

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, or to comply with legal, regulatory, or reporting obligations:

  • Contact Form Submissions: Kept in our CRM (Pipedrive) for up to 24 months after our last active contact, unless a client contract or business relationship is established, in which case it is governed by our client data retention rules.
  • Consent Documentation Logs: Retained for up to 6 years (or until the limitation period for potential regulatory claims expires) to serve as audit proof of consent.
  • Cookies & Analytics Data: Retention periods are managed by Cookie Script and typically expire within a maximum of 24 months (many expire at the end of your browser session).

7. Your Rights Under GDPR

As a data subject located in the EU/EEA, you have the following rights regarding your personal data under the GDPR:

  • Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): You have the right to request that we correct any inaccurate or incomplete personal data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): You have the right to request the deletion of your personal data under certain conditions.
  • Right to Restrict Processing (Art. 18): You have the right to ask us to limit the processing of your personal data.
  • Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format to transmit it to another controller.
  • Right to Object (Art. 21): You have the right to object to the processing of your personal data based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3)): If processing is based on your consent (e.g. contact form submissions or cookies), you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing before the withdrawal.

To exercise any of these rights, please contact us at privacy@promentor.fi. We will respond to your request within 30 days.

Right to Lodge a Complaint

If you believe that our processing of your personal data violates the GDPR, you have the right to file a complaint with a data protection supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto):

  • Website: https://tietosuoja.fi
  • Email: tietosuoja@om.fi

8. Data Security

We implement appropriate technical and organizational measures to prevent your personal data from being accidentally lost, used, accessed, altered, or disclosed in an unauthorized way.

  • All communication between your browser and our website is encrypted using Secure Sockets Layer/Transport Layer Security (HTTPS).
  • Access to database systems containing personal data is restricted to authorized personnel who require access to perform their duties.
  • Data sent from our contact form is securely transmitted to Pipedrive CRM via encrypted API protocols.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. We encourage you to review this page periodically. Any updates will become effective immediately upon posting.

Promentor Solutions Logo
© 2026 Promentor Solutions Oy. All rights reserved. | Privacy Policy
LinkedIn Instagram Facebook