---
title: Privacy policy | Argnode
description: How Argnode Oy collects, uses, and protects personal data under the GDPR. What we hold, why, how long, and the rights you have.
nav_title: Privacy
nav_order: 1
---
:::: hero
::: eyebrow
Legal
:::
# Privacy policy
::: lead
How Argnode Oy handles personal data, why we hold it, how long we keep it, and the rights you have under EU data-protection law.
:::
::::

*Last updated: 30 July 2026.*

This policy explains what personal data Argnode Oy ("Argnode", "we", "us") processes, on what legal basis, who we share it with, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR) and Finnish data-protection law. It describes how things stand on the date above and is updated as our services change.

## Who we are (data controller)

Argnode Oy is the data controller for the personal data described in this policy.

- **Company:** Argnode Oy (business ID 2884224-2)
- **Postal address:** Satotie 4 as. 7, 43100 Saarijärvi, Finland
- **Data-protection contact:** [legal@argnode.com](mailto:legal@argnode.com)

We have not appointed a statutory Data Protection Officer, as we are not required to. Data-protection questions go to the address above.

## What we collect and why

We keep data collection to a minimum. We only process personal data where we have a lawful basis to do so.

### Website visitors

As of the date above, this marketing website carries no analytics, advertising, or profiling technology, and no profile is built from your visit. The site is served from our own servers in the EU and fronted by Cloudflare, our content-delivery network, which processes limited technical data (such as your IP address and browser type) to deliver the site securely and defend against abuse.

We expect this to change. As our own marketing operation grows, we anticipate adding measurement to this site, which may include web analytics, conversion tracking, and advertising tags, including third-party tools such as Google Tag Manager, Google Analytics, and Google Ads. Those tools collect data about visits and can involve transfers outside the EEA. Before any of them goes live, we will update this policy and the [cookie policy]({{ROOT}}en/legal/cookie-policy) to describe what is collected and why, and where the law requires consent we will ask for it first.

- **Data:** IP address, browser and device information, pages requested, timestamps.
- **Purpose:** deliver the website, keep it secure, diagnose faults.
- **Legal basis:** our legitimate interest (Art. 6(1)(f) GDPR) in running a secure website.

### People who contact us

When you email us or otherwise get in touch, we process the information you choose to share.

- **Data:** your name, email address, the content of your message, and any details you include.
- **Purpose:** to answer you, and to take steps at your request before entering into a contract.
- **Legal basis:** our legitimate interest (Art. 6(1)(f)) in responding to enquiries, and steps taken prior to a contract at your request (Art. 6(1)(b)).

As we say on our [contact page]({{ROOT}}en/contact), incoming messages are pre-processed by an automated system that classifies them and either routes them to the right person or replies directly using AI. The system runs on our own EU-based infrastructure, and it does not make decisions with legal or similarly significant effects about you. Substantive matters are always handled by a human.

### Job applicants

If you apply to work with us, we process your application to run the recruitment process.

- **Data:** your application, CV, and the information you choose to share, plus our notes and correspondence with you.
- **Purpose:** to assess your application and communicate with you about it.
- **Legal basis:** steps taken prior to a contract at your request (Art. 6(1)(b)) and our legitimate interest (Art. 6(1)(f)) in recruiting.

### Clients and prospective clients

When you engage us, or we prepare a proposal for you, we process the data needed to deliver and administer the service.

- **Data:** contact and company details, billing and payment information, correspondence, contract and project records.
- **Purpose:** to provide our services, manage the relationship, invoice, and meet our legal obligations.
- **Legal basis:** performance of a contract (Art. 6(1)(b)) and compliance with a legal obligation such as accounting law (Art. 6(1)(c)).

### Data we process on behalf of clients

When we run SEO, advertising, analytics, or automation work, we are given access to systems that may hold personal data belonging to a client and their customers (for example Google Analytics, Search Console, or Google Ads accounts). For that data the **client is the controller and Argnode is the processor**. We process it only on the client's documented instructions, under a data processing agreement (DPA), with least-privilege, read-only access wherever possible. This policy does not govern how our clients handle their own end-users' data.

## Cookies

As of the date above, this website sets no cookies of its own, and no consent banner is shown because there is nothing yet to consent to. Our content-delivery network may set strictly necessary security cookies if its protection features are triggered. If we introduce analytics or advertising technology, we will update the [cookie policy]({{ROOT}}en/legal/cookie-policy) to list what is set, and where consent is required we will ask for it through a cookie banner before any non-essential cookie is set.

## Who we share data with

We do not sell your personal data. We share it only where necessary, with:

- **Service providers (processors)** who help us operate. Our main providers are Cloudflare (content delivery and DNS), Proton (Proton AG, Switzerland; end-to-end encrypted email, calendar, and video meetings), and payment processing (for example Stripe for card payments). They act on our instructions under a contract.
- **Our accountant and advisers**, where needed to meet legal and financial obligations.
- **Authorities**, where we are legally required to disclose data.

We choose EU-based providers wherever we can and prefer to keep data within the European Economic Area (EEA).

## International transfers

We aim to keep personal data within the EEA. Where a provider processes data outside the EEA, we rely on an appropriate safeguard under the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses. Cloudflare (US) is covered by the EU-US Data Privacy Framework, and Proton operates from Switzerland, which holds an EU adequacy decision.

## How long we keep it

We keep personal data only as long as needed for the purpose it was collected for:

- **Enquiries** that do not lead to a contract: kept for a reasonable period, then deleted.
- **Job applications:** kept for the duration of the recruitment process and deleted afterwards, unless you agree that we may keep your application for future openings.
- **Client records:** kept for the duration of the relationship and afterwards as required by law. Accounting records are retained for the period required by the Finnish Accounting Act.
- **Access credentials** to client systems: revoked and deleted when an engagement ends.

## Your rights

Under the GDPR you have the right to:

- **access** the personal data we hold about you,
- **rectify** inaccurate or incomplete data,
- **erase** your data ("right to be forgotten"), subject to our legal retention duties,
- **restrict** or **object** to processing based on legitimate interest,
- **data portability** for data you provided, where applicable,
- **withdraw consent** at any time, where processing is based on consent.

To exercise any of these, email [legal@argnode.com](mailto:legal@argnode.com). We will respond within one month.

If you believe we have handled your data unlawfully, you may lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, [tietosuoja.fi](https://tietosuoja.fi)), or the supervisory authority in your own EU country.

## How we protect data

We apply appropriate technical and organisational measures, including least-privilege access, encryption in transit, and access logging. Every member of our team works under their own personal account, scoped to see only what their work requires; nobody holds administrator rights to every system by default, and we never share password logins. We use read-only access to client systems where possible.

## Changes to this policy

We may update this policy as our services or the law change. The current version always lives at this address, with the "last updated" date above. Material changes will be highlighted where appropriate.

::: seealso
See also:
- [Terms of service]({{ROOT}}en/legal/terms-of-service)
- [Cookie policy]({{ROOT}}en/legal/cookie-policy)
:::
