Nomado Oy Privacy Policy


22.05.2026

1. DATA CONTROLLER

Company name: Nomado Oy
Company address: Aakkulantie 38, 36220 Kangasala
Company Registration Number: 3504224-3

2. ENQUIRIES REGARDING THE REGISTER

Email: [email protected]

3. REGISTER NAME

Nomado Oy Customer Register

4. PURPOSE OF PROCESSING PERSONAL DATA

The purpose of processing personal data in the register is to manage, administer, and maintain the customer relationship between Nomado Oy and the customer, as well as to manage the customer's contracts, billing information, and usage rights, verify customer transactions, develop customer service and business, marketing, analysis, and statistics, and conduct opinion and market research.

Using the data controller's services requires the provision of personal data. The processing of personal data is based on national legislation and the EU's General Data Protection Regulation (GDPR). The grounds for processing personal data include the customer's consent, the contract between the customer and Nomado Oy, and Nomado Oy's legitimate interest based on the customer's customer relationship. Personal data is processed only to the extent necessary for the data controller's business and for the provision of services.

Where the processing of personal data is based on the customer's consent, the customer has the right at any time to withdraw their consent by informing the data controller using the data controller's contact details. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal. As the use of the data controller's services requires the processing of the customer's personal data, the customer accepts that withdrawing consent given for the processing of personal data may prevent the customer from using the service.

5. REGISTER DATA CONTENT

Personal data is collected and processed from Nomado Oy's customers who provide their personal data when using Nomado Oy's services.

The register shall store the customer's name, address, telephone number, email address, as well as information on the services and products ordered and used by the customer, and order and invoicing details provided by the customer. 

For electronic services, the username, password and any other unique identifier are stored. In addition, for business customers, the company's business ID and contact person's contact details are registered in the register.

The register also includes information related to the implementation of communication and customer service, as well as information on the use of services, such as browsing and search data and any profiling and interest information provided by the customer.

6. REGULAR INFORMATION SOURCES

The primary and regular source of information for the register is data collected from customers themselves.

Contract customers' personal data is collected from the customer directly at the time of purchase. In addition, customer data may also be collected from the customer directly by telephone, through a return card, via the internet, by email, or by other similar means.

Information concerning the customer and the vehicle used by the customer may also be retrieved from the vehicle register maintained by Trafi, Posti's address data system, and other similar private and public registers.

Customer data may also be collected through programmatic cookies or technical devices or other similar technologies.

7. REGULAR DISCLOSURES OF DATA

Customer information can be disclosed to the controller's partners if the operation of the service requires it.

Personal data will not be disclosed to third parties for direct marketing purposes or for opinion and market research and other similar surveys without the explicit consent of the data subject.

Information in the register may be disclosed to authorities in accordance with the right granted to authorities by specific legislation.

Personal data will not be disclosed otherwise than for the purpose mentioned above, unless otherwise required by legislation.

Statistical usage data and customer data of the service may be disclosed to third parties in a form from which individual personal data cannot be identified.

8. COOKIES

Cookies are used to improve the customer experience of services and to collect data for analysis and marketing. A cookie is stored on the customer's mobile phone or computer. The service recognises the customer's mobile phone or computer using cookies. Services can be modified to better meet the customer's needs using cookies. The customer can prevent the use of cookies or disable them. Refusing to use cookies may impair the functionality of services, applications, and the website.

9. DATA RETENTION PERIOD

Customer personal data will be retained only for as long as is necessary for the purpose of processing or for as long as the law requires the controller to do so, or until the customer sends a request to the controller to delete their personal data, unless the controller is required to retain the data further or has a legitimate interest in retaining the data further.

10. PRINCIPLES OF REGISTER PROTECTION

Nomado Oy has a security policy in place. The security policy defines the principles for handling data and how data is protected.

The technical customer register is maintained as a technical record by the controller of the register or by a party authorised by them. The information system is protected using appropriate technical safeguards against external data breaches. Only individuals whose job description includes its use access the register. The use of the register is monitored using individual user IDs and passwords.

The data controller's personnel are bound by a duty of confidentiality.

11. RIGHT OF INSPECTION AND RECTIFICATION OF DATA, AND RIGHT OF APPEAL

The customer has the right to access their personal data held in the register free of charge once per year. For more frequent use of the inspection right, the data controller may charge a reasonable fee covering the direct costs incurred. A written and signed inspection request must be submitted to the data controller using the data controller's contact details. Before disclosing the data, the customer's identity shall be verified from a photographic identity document, or other necessary measures shall be taken to ensure that the data is not disclosed to anyone other than the customer themselves.

If the customer becomes aware that personal data held in the register is incorrect or incomplete, or has been processed in violation of the register's purpose or applicable legislation, the customer may, using the controller's contact details, request the controller to correct, block, restrict or delete said personal data. If the processing of personal data is based on the customer's consent, the customer may withdraw their consent at any time by notifying the controller using the controller's contact details. As some services require the processing of the customer's personal data in order to function, the customer accepts that withdrawing consent for the processing of personal data may prevent the customer from using the service.

12. DIRECT MARKETING

With the customer's consent, the controller may send the customer newsletters about other services and products produced by the controller, as well as customer notices regarding the use of the service, and may transfer the customer's details to the controller's partners whose operations are in some way related to the controller's operations or offerings, so that they can send the customer offers related to their own operations. The customer may revoke their consent by notifying the controller using the controller's contact details.

13. CHANGES

The Data Controller reserves the right to correct or amend the privacy policy at any time if changes in applicable data protection and privacy laws necessitate it. The Data Controller recommends that its customers review the privacy policy at regular intervals to ensure they have up-to-date information on how the Data Controller processes customer personal data.