Legal

Privacy policy

How Argnode Oy handles personal data, why we hold it, how long we keep it, and the rights you have under EU data-protection law.

Last updated: 14 August 2026.

This policy explains what personal data Argnode Oy ("Argnode", "we", "us") processes, on what legal basis, who we share it with, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR) and Finnish data-protection law. It describes how things stand on the date above and is updated as our services change.

Who we are (data controller)

Argnode Oy is the data controller for the personal data described in this policy.

We have not appointed a statutory Data Protection Officer, as we are not required to. Data-protection questions go to the address above.

What we collect and why

We keep data collection to a minimum. We only process personal data where we have a lawful basis to do so.

Website visitors

As of the date above, this marketing website carries no analytics, advertising, or profiling technology, and no profile is built from your visit. The site is served from our own servers in the EU and fronted by Cloudflare, our content-delivery network, which processes limited technical data (such as your IP address and browser type) to deliver the site securely and defend against abuse.

We expect this to change. As our own marketing operation grows, we anticipate adding measurement to this site, which may include web analytics, conversion tracking, and advertising tags, including third-party tools such as Google Tag Manager, Google Analytics, and Google Ads. Those tools collect data about visits and can involve transfers outside the EEA. Before any of them goes live, we will update this policy and the cookie policy to describe what is collected and why, and where the law requires consent we will ask for it first.

People who contact us

When you email us or otherwise get in touch, we process the information you choose to share.

As we say on our contact page, incoming messages are pre-processed by an automated system that classifies them and either routes them to the right person or replies directly using AI. The system runs on our own EU-based infrastructure, and it does not make decisions with legal or similarly significant effects about you. Substantive matters are always handled by a human.

Job applicants

If you apply to work with us, we process your application to run the recruitment process.

Clients and prospective clients

When you engage us, or we prepare a proposal for you, we process the data needed to deliver and administer the service.

Data we process on behalf of clients

When we run SEO, advertising, analytics, or automation work, we are given access to systems that may hold personal data belonging to a client and their customers (for example Google Analytics, Search Console, or Google Ads accounts). For that data the client is the controller and Argnode is the processor. We process it only on the client's documented instructions, under a data processing agreement (DPA), with least-privilege, read-only access wherever possible. This policy does not govern how our clients handle their own end-users' data.

AI tools we use

To speed up work that would otherwise be slow or unreliable to do by hand (for example parsing campaign data, tracking configurations, or keyword data), we use third-party AI tools, including Anthropic's Claude. We do not send personal data to these tools. Where information could otherwise identify a person, it is anonymised before it is processed: a name is replaced with a role or a non-identifying label, using a mapping we hold ourselves and the AI provider never has access to. Where personal data does need AI processing, for example classifying incoming email, that runs on hardware we control, not a third-party AI vendor. This applies to our own work and to work we do on behalf of clients.

Cookies

As of the date above, this website sets no cookies of its own, and no consent banner is shown because there is nothing yet to consent to. Our content-delivery network may set strictly necessary security cookies if its protection features are triggered. If we introduce analytics or advertising technology, we will update the cookie policy to list what is set, and where consent is required we will ask for it through a cookie banner before any non-essential cookie is set.

Who we share data with

We do not sell your personal data. We share it only where necessary, with:

We choose EU-based providers wherever we can and prefer to keep data within the European Economic Area (EEA).

International transfers

We aim to keep personal data within the EEA. Where a provider processes data outside the EEA, we rely on an appropriate safeguard under the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses. Cloudflare (US) is covered by the EU-US Data Privacy Framework, and Proton operates from Switzerland, which holds an EU adequacy decision.

How long we keep it

We keep personal data only as long as needed for the purpose it was collected for:

Your rights

Under the GDPR you have the right to:

To exercise any of these, email legal@argnode.com. We will respond within one month.

If you believe we have handled your data unlawfully, you may lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi), or the supervisory authority in your own EU country.

How we protect data

We apply appropriate technical and organisational measures, including least-privilege access, encryption in transit, and access logging. Every member of our team works under their own personal account, scoped to see only what their work requires; nobody holds administrator rights to every system by default, and we never share password logins. We use read-only access to client systems where possible.

Changes to this policy

We may update this policy as our services or the law change. The current version always lives at this address, with the "last updated" date above. Material changes will be highlighted where appropriate.

This document was digitally signed by Niklas Rantanen on 14 August 2026.