Alinor, Oy Privacy Policy (Last updated January, 2023)
Introduction
This privacy policy (this “Privacy Policy”) describes the collection of personal information by Alinor Oy., a Finnish Company (“Company,” “we,” or “us”) from users of our website at www.alinor.io along with our related websites, networks, applications, and other services provided by us and on which a link to this Privacy Policy is displayed (collectively, our “Service”). This Privacy Policy also describes our use and disclosure of such information. This Privacy Policy is incorporated by reference into the Company Terms of Use (TOU) and subject to the provisions of the Terms of Use. This Privacy Policy also describes your rights as a data subject to inquire about your personal information that we process and describes certain rights that you, as the data subject, have regarding this information. Please read this Privacy Policy carefully to understand our practices regarding your personal information and how we will use it.
Contacting us
If you have any questions or comments about this Privacy Policy, please contact us using the following contact information:
Alinor Oy
Attn: Security Team
Saukonpaadenranta 4 E 120
00180, Helsinki, Finland
[email protected]
What information do we collect?
We use your personal information to carry out the obligations arising from providing and improving the Service. This section describes the types and categories of personal information we may collect, and how we may use that information.
Information you provide us directly
We collect personal information that you provide when you sign up or otherwise use the Service. We use this personal information in a variety of ways, and these include the following:
- Email Newsletters: We may offer email newsletters from time to time on our Service. If you sign up to receive a newsletter from us, we collect your email address and may use that email address to contact you.
- User Accounts and Profiles: Our Service gives you the ability to register for a Company account or to create and update a user profile on the applicable Service. When you sign up for the Service we will collect the personal information that you provide to us in the course of registering for an account or creating or updating a user profile. This information may include name, postal address, telephone number, email address, your professional title, interests you express in different products and services and related demographic information about you. We may indicate that some personal information is required for you to register for the account or to create the profile, while some is optional.
- Interactive Features: Our Service may contain interactive functionality that allows you to engage with other users on the Service, post comments to forums, to upload photographs and other content (the “User Materials”), participate in surveys, and otherwise to interact with the Service and with other users. If you use any interactive functionality on our Service that requests or permits you to provide us with personal information (including, for example, any services that allow you to post User Materials on our Service), we collect the personal information that you provide to us in the course of using these interactive features.
- Correspondence: If you contact us by email, using a contact form on the Service, or by mail, fax, or other means, we collect the personal information contained within and associated with, your correspondence (the “Correspondence”).
- Contests and Sweepstakes: We or our advertisers and other business partners may conduct or sponsor special contests, sweepstakes, and other promotions that users may enter or otherwise participate in on our Service. Certain of these promotions may be co-branded with one of our advertisers or other business partners. In these instances, the collection of your personal information may occur directly by the third-party partner on its website or other online service and may be shared with us. The promotion will state the privacy policy or policies governing the collection of such personal information.
Automatically collected information
When you visit our Service, some information is collected automatically. For example, when you access our Service, we automatically collect your browser’s Internet Protocol (IP) address, your browser type, the nature of the device from which you are visiting the Service (e.g., a personal computer or a mobile device), the identifier for any handheld or mobile device that you may be using, the web site that you visited immediately prior to accessing our Service, the actions you take on our Service, and the content, features, and activities that you access and participate in on our Service. We also may collect information regarding your interaction with email messages, such as whether you opened, clicked on, or forwarded a message.
We may collect this information passively in our server logs. We may also collect information passively using technologies such as cookies and clear GIFs (also known as “Web beacons”) as described in the section “Cookies and Similar Technologies” in this Privacy Policy. We use passively-collected information to administer, operate, and improve our Service and systems, to improve the effectiveness of advertising on our Service, and to provide advertisements and other content that is tailored to you. If we link or associate any information gathered through passive means with personal information, or if applicable laws require us to treat any information gathered through passive means as personal information, we treat the combined information as personal information under this Privacy Policy. Otherwise, we use and disclose information collected by passive means in aggregate form or otherwise in a non-personally identifiable form.
Cookies and Similar Technologies
The Service uses cookies to distinguish you from other users of the Service. This enables us to provide you with the service specifically linked to your user profile and is required for the Service to function. Cookies are small files that allow for personalization of the Service experience by saving your information such as user ID and other preferences.
Information from other sources
We may receive information about you, including personal information, from third parties, and may combine this information with other personal information we maintain about you. If we do so, this Privacy Policy governs any combined information that we maintain in a personally identifiable format.
Collection and processing of sensitive information
The Service does not collect or process ‘sensitive information’, defined as data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person’s sex life or sexual orientation. As such, you should not provide any such information as part of your user profile, as part of any User Generated Materials, as part of any Correspondence, or by any other means with your use of the Service.
How do we use personal information?
We collect personal information when you register for access to the Site as a member, or when you update your account information. We use your personal information for the following purposes:
- We use Personal Information to provide the Service and the information that you request;
- We link this personal data to data about the way you use our Service and the pages you visit to help enhance, improve, operate, and maintain our Service, our programs, services, websites, and other systems;
- to prevent fraudulent use of our Service and other systems;
- to prevent or take action against activities that are, or may be, in violation of our Terms of Use or applicable law;
- to tailor advertisements, content, and other aspects of your experience on and in connection with the Service;
- to maintain a record of our dealings with you; for other administrative purposes; and for any other purposes that we may disclose to you at the point at which we request your personal information, and pursuant to your acceptance of this Privacy Policy.
Legal basis for processing in the EU
If you are resident in the EU, we need to inform you about the legal basis on which we collect and use your personal information. In the EU, the purposes for which we process your personal information are:
- Where we need to perform the contract we are about to enter into or have entered into with you for the Service;
- For the purposes of legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests; and
- Where we need to comply with a legal or regulatory obligation in the EU.
You may be subject to a separate contractual agreement with Us, and if so we use the performance of a contract as the legal basis for processing.
When do we share personal information?
Except as described in this Privacy Policy, we will not disclose your personal information that we collect on the Service to third parties without your consent. We may disclose information to third parties if you consent to us doing so, as well as in the following circumstances:
- Service Providers: We may disclose personal information to third-party service providers (e.g., payment processing and data storage and processing facilities) that assist us in our work. We limit the personal information provided to these service providers to that which is reasonably necessary for them to perform their functions, and we require them to agree to maintain the confidentiality of such personal information;
- Suppliers, Producers, and Distributors: We help customers find suppliers of products and services that meet their needs. An inherent part of that business model is marketing our Service and sharing customer data with our client companies to enable their follow-up sales and marketing activities. These companies may include suppliers of products and services that are listed on our Service, including their distributors and affiliates. These companies may send product samples, documents, or otherwise follow up on products or services the member has expressed an interest in, either implicitly or explicitly.
- Public Areas and Syndicated Services: Some features of our Service may allow you to upload, post, or otherwise transmit User Materials to open areas of the Service, such as content that you post in a public profile on the Service. Alinor is a closed platform, so only companies that have been allowed to the platform have access to this information. Please be aware that any personal information that you include within any User Materials will be made available to other users of the Service who view it. You include Personal Information in User Materials at your sole risk. We may allow you to select privacy options that limit access to some types of personal information in User Materials, but no security measures are impenetrable or perfect. Additionally, even after information posted on the Service is removed, caching and archiving services may have saved that information, and other users or third parties may have copied or stored the information available on the Service. We cannot warrant or guarantee that any personal information that you provide on and in connection with the Service will not be accessed, viewed, or used by unauthorized persons.
- Business Transfers: Information about our users, including personal information, may be disclosed and otherwise transferred to an acquirer, or successor or assignee as part of any merger, acquisition, debt financing, sale of company assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which personal information is transferred to one or more third parties as one of our business assets.
- To Protect our Interests: We also disclose personal information if we believe that doing so is legally required, or is in our interest to protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights or property of others, or otherwise to help protect the safety or security of our Service and other users of the Service.
- To Comply with the Law: We may also disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Communication choices
If you receive commercial email from us, you may unsubscribe at any time by following the instructions contained within the email. You may also opt-out from receiving commercial email from us, and any other promotional communications that we may send to you from time to time (e.g., by postal mail) by sending your request to us by email at [email protected] or by writing to us at the address given in the ‘Contacting us’ section of this policy. Additionally, we allow you to view and modify settings relating to the nature and frequency of promotional communications that you receive from us as part of your user settings.
Please be aware that if you opt-out of receiving commercial email from us, it may take up to ten business days for us to process your opt-out request, and you may receive commercial email from us during that period. Additionally, even after you opt-out from receiving commercial messages from us, you will continue to receive administrative messages from us regarding your use of the Service.
Rights to access
If you have a user account and profile on our Service, you have the ability to access and update many categories of personal information that you provide to us by logging in to your account and accessing your account settings. If you wish to access or amend any other personal information we hold about you, you may contact us at [email protected] If you request that we delete your account with our Service (via a user settings page, by email, or otherwise), we will do so within a reasonable period of time, but we may need to retain some of your personal information in order to satisfy our legal obligations, or where we reasonably believe that we have a legitimate reason to do so. Requests for personal information are processed within 30 days.
Links to external sites
The Service may contain links to other websites, products, or services that we do not own or operate. The Service also may contain links to Third-Party Sites such as social networking services. If you choose to visit or use any Third-Party Sites or products or services available on or through such Third-Party Sites, please be aware that this Policy will not apply to your activities or any information you disclose while using those Third-Party Sites or any products or services available on or through such Third-Party Sites. We are not responsible for the privacy practices of these Third-Party Sites or any products or services on or through them. Additionally, please be aware that the Service may contain links to Web sites and services that we operate but that are governed by different privacy policies. We encourage you to carefully review the privacy policies applicable to any website or service you visit other than the Service before providing any personal information on them.
How long do we keep your personal information for?
Unless otherwise specifically stated elsewhere in this Privacy Policy, we will retain your personal information for the period necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law as in the case of our KYC requirements, which are stored for a period of 10 years. If you request that your general personal information be removed and close your account, your data is removed from our systems no later than 30 days from receiving the request.
Aggregated and anonymized data that no longer identifies the user of the Service is maintained for the purposes necessary to provide the Service.
EU privacy rights
If you are located in the EU, you have the following Data Subject Access Rights with respect to your personal information that we hold:
- Right of access: The right to obtain access to your personal information. Requests for personal information are processed within 30 days.
- Right to rectification: The right to obtain rectification of your personal information without undue delay where that personal information is inaccurate or incomplete.
- Right to erasure: The right to obtain the erasure of your personal information without undue delay in certain circumstances, such as where the personal information is no longer necessary in relation to the purposes for which it was collected or processed.
- Right to restriction: The right to obtain the restriction of the processing undertaken by us on your personal information in certain circumstances, such as where the accuracy of the personal information is contested by you, for a period enabling us to verify the accuracy of that personal information.
- Right to portability: The right to portability allows you to move, copy or transfer personal information easily from one organization to another.
- Right to object: You have a right to object to processing based on legitimate interests and direct marketing.
What is our policy on children?
Children’s safety is important to us, and we encourage parents and guardians to take an active interest in the online activities of their children. Our Services are not directed to children under the age of 18, and we do not knowingly collect personal information from children under the age of 18 without obtaining parental consent. If we learn that we have collected personal information from a child under the age of 18 on our Services, we will delete that information as quickly as possible. If you believe that we may have collected any such personal information on our Services, please notify us at [email protected]
Where do we store and process your personal information?
-
International Transfers: Our servers and data centers are run by Microsoft and are located in the European Union and the United States. If you choose to use the Service from outside of these jurisdictions, then you should know that you are transferring your personal information outside of your region and into the US and EU for storage and processing. By providing your Personal Information to us through your use of the Service, you agree and consent to that transfer, storage, and processing in the US and EU. Also, we may transfer your data from the US and EU to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating the Service. You should know that each region can have its own privacy and data security laws, some of which may be less stringent as compared to those of your own region. Contracts with Producers from whom we may receive EU personal data include model contract clauses approved by the European Commission to ensure the protection of EU personal data. In addition to model contract clauses, Alinor undergoes the following activities to ensure the protection of all personal data, regardless of its source:
- Annual privacy policy and procedures review.
- Consumer data privacy is considered during system updates and implementation of new services.
Jurisdiction and Enforcement
- For European Union residents, you also have the right to lodge a complaint to your local data protection authority. Further information about how to contact your local data protection authority is available at: https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080
- European Union or Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact us at [email protected]
- Under certain conditions specified by the Principles, you may also be able to invoke binding arbitration to resolve your complaint.
How do we secure your personal information?
To help protect your data, we use commercially reasonable steps to protect the data that we collect, including your personal information. The reasonable steps include protecting this data against accidental loss, unauthorized use, and disclosure, and restricting access to personal information by our staff. The Service is hosted by a third-party hosting company that we have determined maintains adequate security controls and utilizes TLS encryption for all internet communication with the Service. We also require all staff that administer and develop the service follow industry-standard controls, including strong passwords, the use of anti-virus and anti-malware software, disk encryption and other best practices.
We use various 3rd party processors to enable us to provide the Service, and as part of our vendor due-diligence, we review the security controls these processors have in place and ensure they meet industry standards appropriate for the type of data we collect.
You should keep in mind, however, that the Service utilizes software, hardware, and networks, which from time to time require maintenance and experience problems beyond our control. Note that no data transmission over the public internet or encryption method can be guaranteed to be 100% secure. Consequently, we cannot ensure or warrant the security of any information that you provide to us. You transmit information to us at your own risk.
Updates to this Policy
We may occasionally update this Policy. When we do, we will also revise the “last updated” date at the beginning of the Policy. Your continued use of our Service after such changes will be subject to the then-current policy. If we change this Policy in a manner that is material, we will use reasonable efforts to notify you via the contact methods you have provided of the change prior to applying the change to any personal information that we collected from you prior to the date the change becomes effective. We encourage you to periodically review this Privacy Policy to stay informed about how we collect, use, and disclose personal information.