Nosto
Legal Center
Privacy
Privacy Notice
Privacy Notice
This Privacy Notice explains how Nosto processes personal data when it acts as a controller, in particular personal data relating to our business contacts and prospects, visitors to nosto.com, and users of the Nosto platform.
Our processing of personal data as a processor on behalf of our customers, when providing our Services, is outside the scope of this Privacy Notice.
1. Controller
Nosto Solutions Oy
Bulevardi 21, 00180 Helsinki
Finland
legal@nosto.com
(hereafter “we” or “Nosto”)
2. Contact for data protection matters
Nosto Solutions Oy
Legal Department
Bulevardi 21, 00180 Helsinki
Finland
legal@nosto.com
3. Legal basis and purpose
We process personal data on one or more of the following legal bases, depending on the situation:
- performance of a contract with you or your employer, or steps taken at your request before entering into one (for example, providing and operating the Nosto platform);
- our legitimate interests in running, promoting and developing our business and maintaining our customer and contact relationships;
- your consent, where we rely on it (for example, certain electronic direct marketing and optional cookies); and
- compliance with our legal obligations.
Where we rely on consent, you can withdraw it at any time.
We process personal data for the following purposes:
- providing and developing our products, Services and website, including offering more relevant content and a better experience;
- fulfilling our contractual obligations and other undertakings;
- managing our customer and contact relationships;
- organising events;
- analysing and improving the use of our website and communications; and
- sending electronic direct marketing where permitted.
We use cookies and similar technologies on our website, including for basic analytics. For more information, please see our Cookie Notice.
4. Personal data we process
We may process the following categories of personal data relating to you:
- identity and contact details, such as name, username, email address, telephone number and postal address;
- business information, such as your employer, business ID, job title or role, and the contact details of company representatives;
- account and login details for the Nosto platform;
- your marketing preferences and any consents you have given;
- event participation details, including any requirements you tell us about (such as dietary requirements);
- information about our relationship with you, such as contracts, orders and other transaction and communication records, together with your location and language; and
- any other information you choose to provide to us.
5. Sources of personal data
We collect most personal data directly from you, for example when you contact us, sign up for our communications, use the Nosto platform, or attend our events. We may also obtain and update data from third parties, such as our partners, contact-information providers and from other similar reliable sources.
6. Personal data we process through the Nosto platform
When users access and use the Nosto platform, we process information they provide to us directly and logs relating to how they use the platform. We use this information to provide, secure, support and improve our products and Services.
When a merchant connects to the Nosto Services through a platform or app, we also receive account and contact information about the merchant and the people who administer or use the Nosto platform on its behalf. We act as a controller for this data and use it to create and administer accounts, authenticate users, and provide, secure and support our products and Services.
To the extent we process personal data as a processor on behalf of our customers, that processing is governed by the Data Processing Addendum (DPA) between Nosto and the relevant customer, who is the controller. If you wish to exercise your data protection rights in relation to that data, please contact the relevant controller in the first instance.
We provide certain services that enable connections with and data ingestion from Social Networks. These Additional Product Terms detail Social Network–related data processing and are incorporated into this Privacy Notice as applicable.
7. Disclosure and international transfers
We do not sell your personal data. We may share it with service providers (processors) that process personal data on our behalf, for example for hosting, IT and marketing operations. They may only process the data on our instructions and under appropriate contractual and security safeguards.
We may also share personal data with our partners, such as resellers, technology and integration partners, and co-marketing partners, where this is necessary for the purposes described in section 3. Where a partner determines how and why the data is processed, it acts as a separate controller and its own privacy notice applies to that processing.
We may transfer personal data outside the EU/EEA. Where we do, we ensure appropriate safeguards are in place. We rely primarily on the European Commission’s Standard Contractual Clauses, together with any additional measures required, and, where applicable, on an adequacy decision or another transfer mechanism approved under applicable law. You can request more information about these safeguards using the contact details in section 2.
8. Security and retention
We use appropriate technical and organisational measures to protect personal data. Access is limited to personnel who need it for their work. Our service providers are likewise required to maintain appropriate security measures.
We store personal data only for as long as is necessary for the purposes described in this notice. The retention period depends on the type of data and the purpose, and we may retain data for longer where necessary to comply with legal obligations (such as accounting requirements) or to establish, exercise or defend legal claims. Marketing contact data is reviewed periodically and deleted when no longer needed.
We regularly assess our retention needs in light of applicable law. We also take reasonable measures to ensure that the personal data we hold is accurate, complete and up to date for the purpose of the processing, and we rectify or delete inaccurate data without delay.
9. Your rights
Subject to the conditions and exceptions set out in applicable data protection law (including the GDPR), you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected and incomplete data completed;
- have your data erased;
- restrict or object to our processing of your data;
- data portability, where the processing is based on your consent or on a contract and is carried out by automated means;
- withdraw your consent at any time, where our processing is based on consent; and
- lodge a complaint with a supervisory authority.
You can object to the processing of your personal data for direct marketing at any time.
To exercise any of these rights, please contact us at legal@nosto.com.
10. US Notice
This US Notice is for individuals residing in certain US states and is designed to help you better understand how we collect, use, and disclose your Personal Data and how to exercise available rights under various applicable privacy laws in the US, such as in California, Colorado, Connecticut, Utah and Virginia.
The categories of Personal Data we collect, our sources, and our purposes are described in sections 4, 5 and 3 of this notice.
You can manage and review how we collect and share your personal data in our Privacy Preference Center.
In several US States, you may have the specific rights to access, correct, delete, and obtain a copy of your Personal Data, to opt out of targeted advertising and certain profiling. To make a request, email legal@nosto.com; we will verify it against the information we hold. Where your state’s law gives you a right to appeal a decision on your request, we will tell you how to do so. You will never be treated differently for exercising these rights.
11. Changes
We may update this Privacy Notice from time to time, for example to reflect changes in our processing or in legal requirements. The current version is always available on our website. If a change is significant, we may also notify you by other appropriate means.