Privacy Policy

Last updated: March 2026

Nordic Learning Intelligence Oy

PRIVACY NOTICE FOR CUSTOMER AND MARKETING REGISTERS

In this privacy notice, we explain how we process personal data of our customers and recipients of marketing communications.

1 Data controller

The data controller is Nordic Learning Intelligence Oy (Business ID 3599307-3).

Contact person for register matters:

Niina Sainius

Tel. +358 40 569 3939

Väliniitynkaari 8, 04330 Lahela, Finland

privacy @ gesento.ai

2 Name of the register

The register names are:

a) Nordic Learning Intelligence Oy / Customer Register

b) Nordic Learning Intelligence Oy / Marketing and Communications Register

3 Purpose of processing personal data

Personal data is processed for purposes related to managing, administering, and developing customer relationships, providing and delivering services, developing services, and invoicing. Personal data is also processed for handling potential complaints and other claims.

In addition, personal data is processed for customer communications such as notices and newsletters, and for marketing, including direct marketing and electronic direct marketing, in accordance with applicable legislation. The customer has the right to prohibit direct marketing targeted at them.

The data controller primarily processes personal data itself, but may use service providers and subcontractors acting on behalf of the data controller.

4 Legal bases for processing

The legal bases for processing personal data are the following under the EU General Data Protection Regulation ("GDPR"):

  • the data subject has given consent to the processing of their personal data for one or more specific purposes (GDPR Article 6(1)(a));
  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (GDPR Article 6(1)(b));
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party (GDPR Article 6(1)(f)).

The legitimate interest referred to above is based on a relevant and appropriate relationship between the data subject and the controller arising from the fact that the data subject is a customer of the controller, and where processing is carried out for purposes that the data subject could reasonably expect at the time and in the context of collection of personal data.

5 Data content of the register (categories of personal data processed)

As a rule, the register contains the following personal data of all registered persons:

  • basic personal details and contact information
  • a) Nordic Learning Intelligence Oy / Customer Register: first name, last name, address, phone number, email address
  • b) Nordic Learning Intelligence Oy / Marketing and Communications Register: first name, last name, email address
  • information related to the person's company or other organization and the person's position or title in that company or organization
  • direct marketing permissions and prohibitions

6 Regular data sources

Personal data is collected from the data subject themselves.

Personal data is also collected and updated, within the limits of applicable legislation, from publicly available sources related to implementing the customer relationship between the controller and the data subject, and through which the controller fulfills obligations related to maintaining customer relationships. Data for the marketing and communications register is also collected from external services or applications such as Facebook, Instagram, other social media channels, Mailchimp, Campaign Monitor, possible fairs and events, customer meetings, and partners.

7 Retention period of personal data

Data collected in the register is stored only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal data was collected.

The need to retain personal data is assessed every three years and, in any case, data concerning a registered person is removed from the register ten years after that person's customer relationship with the controller has ended and related obligations and measures have been completed. For example, accounting vouchers are stored for six years after the end of the financial year.

The controller regularly evaluates the necessity of data retention in accordance with its internal policies. In addition, the controller takes all reasonable measures to ensure that inaccurate, erroneous, or outdated personal data is erased or rectified without delay in relation to the purposes of processing.

8 Recipients of personal data (recipient groups) and regular disclosures

Personal data may be processed by service providers acting on behalf of the data controller.

Such service providers may include, for example:

  • IT and system service providers
  • website platform and hosting service providers
  • email and newsletter system providers
  • analytics and marketing service providers
  • other subcontractors necessary for the controller's operations

The controller ensures that data processing agreements required by the EU General Data Protection Regulation (GDPR) have been concluded with personal data processors.

9 Transfer of data outside the EU or EEA

Personal data may also be processed in services located outside the EU or EEA. The controller ensures that transfers are carried out in accordance with the EU Standard Contractual Clauses mechanism or another transfer basis required by data protection legislation.

Data may be transferred in particular to the United States in connection with international service providers used by the controller (e.g., email, marketing, and analytics services).

10 Principles of register protection

Materials containing personal data are stored in locked facilities accessible only to designated persons authorized due to their duties.

Databases containing personal data are located on a server stored in a locked facility accessible only to designated persons authorized due to their duties. The server is protected with an appropriate firewall and technical safeguards.

Access to databases and systems is granted only with personal user IDs and passwords issued separately. The controller has limited access rights and authorizations to information systems and other storage platforms so that data can be viewed and processed only by persons necessary for lawful processing.

In addition, usage events in databases and systems are logged in the controller's IT system logs.

The controller's employees and other persons are committed to confidentiality and to keeping secret the information they receive in connection with personal data processing.

11 Rights of the data subject

The data subject has the following rights under the EU General Data Protection Regulation:

  • the right to obtain confirmation from the controller as to whether personal data concerning them is processed and, where that is the case, access to personal data and the information specified in GDPR Article 15;
  • the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (GDPR Article 7);
  • the right to request rectification of inaccurate or incorrect personal data without undue delay and to have incomplete personal data completed (GDPR Article 16);
  • the right to obtain erasure of personal data concerning them without undue delay in situations defined in GDPR Article 17;
  • the right to restriction of processing in situations defined in GDPR Article 18;
  • the right to receive personal data concerning them in a structured, commonly used, machine-readable format and to transmit those data to another controller in accordance with GDPR Article 20;
  • the right to lodge a complaint with a supervisory authority if the data subject considers that processing of personal data concerning them infringes the GDPR (GDPR Article 77);
  • the right to object to direct marketing and to request restriction of processing or object to processing in accordance with applicable legislation;

Requests concerning the exercise of data subject rights are addressed to the contact person named in section 1.

12 Cookies and analytics

We use cookies on our website to enhance your user experience, remember your settings, and analyze our website traffic.

  • Essential cookies: These are necessary for the basic functions of the site, such as maintaining your language preferences.
  • Analytics cookies: We use Google Analytics to collect information about how the site is used (e.g., most popular pages and session durations). The data collected is statistical and helps us improve our service. This data is anonymized to the extent possible and is not used to identify individual users.

You can choose to accept or decline non-essential cookies via the cookie banner at the bottom of the site. You can also change your settings or withdraw your consent at any time by clearing your browser's cookies.

Published 1 March 2026