Privacy Policy

Aivan Oy (business ID 2153004-3, “Aivan” or “we”) is committed to protecting the privacy of your personal data, and with this privacy notice we want to demonstrate how we collect and use personal data as part of our business operations and what rights data subjects have in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR, 2016/679).
Please note that this privacy notice may be amended from time to time.

Controller and contact information

Aivan Oy
Business ID
Henry Fordin katu 6 B, 00150 Helsinki, Finland

Personal data collected and processed as well as purpose and legal basis for processing personal data

Aivan processes personal data for the following purposes:

Contact form

We process personal data of contact persons in order to carry out and to fulfill requirements concerning our customer service, including receiving and processing contacts, answering questions and evaluating the customer relationships, and to maintain the security of our web server.

The legal basis for processing of contact person personal data is Aivan’s legitimate interest to carry out the contact process. With regard to contact form, we process the following personal data:

  • Name and contact details
  • Subject
  • Message as other data which the contact person decides to disclose to Aivan

In addition, our web server keeps a log of the messages sent for one year. The log contains the return addresses and topics of sent messages.

Job applicants

We process personal data of job applicants in order to carry out and to fulfill requirements concerning our recruitment procedures, including receiving and processing job applications, evaluating the job applicants and managing employee relationships.

The legal basis for processing of job applicants’ personal data is Aivan’s legitimate interest to carry out the recruitment process or to carry out other measures related to entering into an employment agreement between Aivan and the job applicant. With regard to job applications, we process the following personal data:

  • Name and contact details
  • Date of birth
  • Basic information related to the employment relationship, such as job applicant’s applications, CV, picture, skills, i.e., special abilities and language skills
  • Information related to suitability for work, such as information regarding education and work experience
  • Other data which the job applicant and employee decides to disclose to Aivan

Website visitor

While visiting our website ( we process user analytic data to compile user interactions, prevent attacks on our website and provide better user experience. We process the following data from all website users by using Matomo Analytics and, if you agree to the use of cookies, Google Analytics:

  • Anonymized, partial IP address
  • Date, time and duration of the visit
  • Name and version of your web-browser

Our web server keeps a log of all requests to resources and stores the following information for one year:

  • Date and time of the request
  • IP address from which the request was made
  • Other information sent with the request such as browser and operating system information

Regular sources of personal data

Personal data is collected from contact persons when they connect us by submission of the contact form. In terms of job applications, personal data is collected from the job applicants in connection with the submission of the job application.

Data disclosures

Personal data is processed within Aivan, for the purposes mentioned above and only by such personnel who have the right to do so due to their position or in order to perform their duties. Such personnel are HR professionals as well as administrative and IT personnel.

Aivan uses third party service providers to process personal data for IT services, HR, and administration. Such service providers are processors of personal data who process personal data on behalf of Aivan and in accordance with the instructions of Aivan. Aivan ensures that personal data processed by the service providers are processed in accordance with appropriate confidentiality and data processing agreements and applicable data protection legislation.

Personal data is primarily stored in the EU/EEA, but processors outside the EU/EEA may have access to personal data when providing their services to Aivan. In cases where such disclosure occurs, Aivan must ensure that the European Commission has taken a decision on the adequate level of protection of personal data in the country of destination, use standard contractual clauses or other equivalent arrangements approved by the European Commission and comply with other appropriate safeguards for the disclosure or transfer of personal data outside the EU/EEA.

Retention and deletion of personal data

Personal data will be retained for as long as it is necessary to fulfill the purpose of processing. When we no longer need to process your personal data for its original purpose, the data will be either anonymized or deleted. However, data retention may be extended, if necessary, to fulfill legal obligations and requirements.

In terms of job applications, the retention time is 1 year from the end of the recruitment process. Personal data processed for statutory bookkeeping and related obligations shall be retained for at least 10 years.

In the light of applicable data protection legislation, Aivan continuously evaluates its need to process personal data, and undertakes all reasonable measures to ensure that the personal data processed is accurate and up to date.

Principles of how the personal data is secured

Aivan processes your personal data lawfully, fairly and in a transparent manner, collects it for specified, explicit and legitimate purposes, and will not further process personal data in a manner that is incompatible with said purposes mentioned in this privacy notice. Aivan will only process adequate and relevant personal data, limited to what is necessary in relation to the purposes for which it is processed.

Aivan uses appropriate technical and organizational measures designed to protect the personal data that are collected and processed. The measures used provide an adequate level of security for the processing of the personal data of the data subjects. All personnel at Aivan as well as third-party service providers involved in the processing of your personal data are required to treat it strictly confidentially.

Data subjects’ rights

You, as a data subject, have a right to receive information on whether your personal data are being processed and if data are processed, you have a right to access your data. You also have the right to ask for the data to be rectified or deleted or for the processing to be restricted within the limitations set out in and in accordance with applicable data protection legislation. Further, you may have the right to object to certain use of your personal data if it is processed for other purposes than for the performance of a contract or for compliance with legal obligations. You have the right to receive the personal data you have provided to us yourself in a structured and commonly used format and to transmit those data to a third party.

Any request shall be made to the point of contact provided above, by a personally signed or otherwise comparably verified document. We will do our best to implement your request. However, sometimes we must refuse your request, in which case we shall inform you of the basis of such refusal. As the processing of personal data is partly based on legal obligations of Aivan and partly for the performance of a contract, any failure to provide personal data may prevent Aivan from fulfilling its legal obligations or tasks related to the contractual relationship.

If Aivan intends to process personal data for a purpose other than that for which the personal data were originally collected, Aivan shall inform the data subjects of that purpose and provide any other relevant additional information prior to the processing.

In case you consider that our processing of personal data does not meet the requirements of the General Data Protection Regulation or other applicable legislation, you may contact the Finnish Data Protection Authority ( to confirm the appropriateness of the processing of your personal data.


When you visit our website, we ask you whether you allow cookies for analytics purposes. If you disagree, we will set a cookie containing that choice, so that your choice is remembered throughout your visit and next time you visit our site on the same device. If you wish to change your preference, you can delete the cookie that is stored on your device, and you will be asked the question again on your next visit.

Cookies are small text files placed on your device when you visit a website. They are used for example to save settings and choices you make so that your preferences are remembered on your next visit.

In the case that you agree to the use of traffic analysis cookies, we will use Google Analytics, a web analytics service provided by Google, Inc. (“Google”). The information generated by an Google analytics script with the help of the cookie about your use of the website will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators, and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf.

The cookie that contains your preference regarding analytics cookie use is stored on your device for one year. You can delete the cookie manually yourself before this time. Google Analytics retains data related to website usage for 14 months, at the time of writing.

Please note that this retention period can change and may be adjusted based on our needs or changes in regulations. We will update this policy to reflect any modifications to our data retention practices.

We are using following tools that use cookies for analytics:

Google Analytics 4

Updating policy

This privacy policy was last edited on March 26, 2024, and will be updated when changes occur.