Privacy policy
This is the Cordaxia Inc’s privacy policy in accordance with the EU General Data Protection Regulation (GDPR). Prepared on 1.12.2025. Last modified on 1.12.2025.
1.Data controller
Cordaxia Inc., Helsinki, Finland
2.Name of the register
Cordaxia.com website’s contact form register.
4.Legal basis and purpose of processing personal data
The legal basis for processing personal data in accordance with the EU General Data Protection Regulation is
- the person’s consent by sending the website’s contact form
The purpose of processing personal data is to communicate with customers, maintain customer relationships and marketing.
The data is not used for automated decision-making or profiling.
5.Data content of the register
The information stored in the register includes: the person’s name, email address, message and IP address of the network connection.
The IP addresses of website visitors and cookies necessary for the functioning of the service are processed on the basis of legitimate interest, e.g. for data security purposes and for collecting statistical data on website visitors in cases where they can be considered personal data. Separate consent is requested for third-party cookies, if necessary.
6. Source of information
The information stored in the register is obtained from the customer from messages sent via web form.
Information on contact persons at companies and other organizations may also be collected from public sources such as websites, directory services, and other companies.
7. Regular disclosure of data and transfer of data outside the EU or EEA
Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer.
Data may also be transferred outside the EU or EEA by the controller.
8. Principles of register protection
The register is processed with care and the data processed using information systems is protected appropriately. When register data is stored on Internet servers, the physical and digital security of the equipment is ensured in an appropriate manner. The controller shall ensure that stored data, server access rights, and other information critical to the security of personal data are treated confidentially and only by employees whose job description includes such tasks.
9. Right of access and right to request correction of data
Every person included in the register has the right to check their data stored in the register and to request the correction of any incorrect data or the completion of any incomplete data. If a person wishes to check the information stored about them or request a correction, the request must be sent in writing to the controller. If necessary, the controller may ask the person making the request to prove their identity. The controller will respond to the customer within the time limit specified in the EU Data Protection Regulation (usually within one month).
10. Other rights related to the processing of personal data
A person included in the register has the right to request the removal of personal data concerning them from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the person making the request to prove their identity. The controller will respond to the customer within the time limit specified in the EU General Data Protection Regulation (usually within one month).
