Privacy Policy
Last updated: 10 August 2026
FastHub Oy (business ID 3523272-5) ("Fasthub", "we", "our" or "us") is the controller of the personal data described in this policy. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you visit our website, use our services, or are contacted by us as a business prospect.
Contact: privacy@fasthub.ai · FastHub Oy, Tykistökatu 4, 20520 Turku, Finland
Scope of this policy. This policy describes personal data for which Fasthub acts as controller: visitors to our website, business prospects we contact, and the contact persons of our customers and partners.
It does not cover personal data that our customers transmit through the Fasthub integration platform. For that data the customer is the controller and Fasthub acts as processor on the customer's instructions. That processing — including its location, sub-processors, security measures, retention and deletion — is governed by our Data Processing Addendum, available on request from privacy@fasthub.ai. Where the customer has enabled Fasthub AI features, the Data Processing Addendum also governs how personal data is processed by AI models.
1. Information We Collect
1.1 Information You Provide
We collect information you voluntarily provide when you create an account, contact us for support, subscribe to our newsletter, register for an event, or otherwise communicate with us. This may include:
- Name and email address
- Company name and job title
- Phone number (optional)
- Information about your integration needs and technical environment
1.2 Information Collected Automatically
When you access our website, we may automatically collect: IP address and approximate location, browser type and version, operating system, pages visited and time spent, and referring website addresses.
1.3 Cookies and Similar Technologies
We use cookies and similar technologies in two categories:
- Essential — required for the website to function and to remember your cookie choices. These are always active and cannot be switched off.
- Analytics — help us understand how the website is used. Set only with your consent.
You can give, refuse or change your choices at any time via Cookie settings. Withdrawing consent does not affect processing already carried out.
1.4 Business Contact Information Collected from Other Sources
We market our integration platform to organisations. To do so, we collect and process a limited set of professional contact information about individuals in relevant roles, obtained from sources other than the individual themselves.
Categories of data we process:
- Name, job title and employer
- Business email address and business phone number
- Publicly available professional profile information, such as role history and areas of responsibility
- Publicly available information about the employer organisation, such as industry, size, location and publicly disclosed technology environment
- Records of our communications with you, including messages sent, replies and meetings
Sources of this data:
- Publicly available business sources, including company websites, public trade and business registers, press releases and industry publications
- Professional networking platforms
- Commercial contact-data and business information providers, including the contact-data providers queried through our outreach platform's enrichment service
- Business events, conferences and partner introductions
We do not collect or process special categories of personal data, as defined in Article 9 GDPR, for prospecting purposes, and we do not process personal data of individuals in a private capacity for these purposes.
Legal basis: our legitimate interest in marketing business-to-business services to professionals whose role indicates responsibility for enterprise integration, IT architecture, data or procurement (Article 6(1)(f) GDPR; see Recital 47, which recognises direct marketing as a potential legitimate interest). We have carried out and documented a balancing assessment weighing this interest against your rights and freedoms. A summary of that assessment is available on request from privacy@fasthub.ai.
Where the law requires consent for electronic direct marketing in your jurisdiction, we send marketing messages only where such consent has been obtained, or we restrict contact to channels and addresses permitted under local law.
We provide the information required by Article 14 GDPR at the latest at the time of our first communication with you, including a link to this policy and a clear statement of your right to object.
1.5 Email Communications
Our business emails include a link enabling you to unsubscribe or object to further contact. Where we measure whether an email has been opened or a link clicked, we do so only in accordance with applicable law and, where required, with your consent. You can prevent open tracking by disabling automatic image loading in your email client.
2. How We Use Personal Data
We use personal data to:
- Provide, maintain and improve our services
- Respond to your inquiries and provide customer support
- Contact business prospects about our integration platform and services, and follow up on those contacts
- Send updates about our product, features and events, where you have subscribed or where permitted by law
- Analyse usage patterns to improve user experience
- Comply with legal obligations, including recording and honouring objections to marketing
- Protect against fraud and unauthorised access
3. Legal Bases for Processing
| Purpose | Legal basis |
|---|---|
| Providing our services under a contract | Contract (Art. 6(1)(b)) |
| Business-to-business prospecting and direct marketing | Legitimate interest (Art. 6(1)(f)) |
| Newsletter and marketing subscriptions | Consent (Art. 6(1)(a)) |
| Non-essential cookies and similar technologies | Consent (Art. 6(1)(a)) |
| Analytics, service improvement and security | Legitimate interest (Art. 6(1)(f)) |
| Accounting, tax and other statutory obligations | Legal obligation (Art. 6(1)(c)) |
| Maintaining a suppression list of objections | Legitimate interest (Art. 6(1)(f)) and compliance with Art. 21(3) |
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
4. Data Sharing and Disclosure
We do not sell personal data. We share personal data with:
- Service providers acting as processors on our behalf. The categories of recipient are set out in Section 12.
- Legal requirements: where required by law or to establish, exercise or defend legal claims.
- Business transfers: in connection with a merger, acquisition or sale of assets.
All processors are bound by a written data processing agreement under Article 28 GDPR and may use personal data only on our instructions.
5. Data Retention
| Data | Retention |
|---|---|
| Prospect data where no engagement occurs | 12 months from the last contact attempt |
| Prospect data where a business discussion took place | 24 months from closure of the opportunity |
| Suppression list and minimal record of prior contact | Retained indefinitely (see below) |
| Customer and contract data | Duration of the relationship, then 6 years as required by Finnish accounting law |
| Newsletter subscriber data | Until you unsubscribe; removed after 24 months of no engagement |
| Website analytics data | 14 months |
| Personal data processed on the platform on a customer's behalf | Governed by our Data Processing Addendum, not by this policy |
Suppression list. If you object to marketing or ask us to stop contacting you, we must retain the minimum data necessary — normally your email address or a hashed form of it — in a suppression list. This is the only way we can reliably ensure you are not contacted again, and this limited retention is itself a data protection safeguard. We do not use suppression list data for any other purpose.
Record of prior contact. Where we have contacted you and received no response, we delete your contact data within the period stated above but retain a minimal record — your email address or a hashed form of it, together with the date — for the sole purpose of ensuring we do not repeatedly approach the same person. Retaining this record results in less contact with you, not more.
6. Your Rights
6.1 Right to Object to Direct Marketing
You have the right to object at any time to our processing of your personal data for direct marketing purposes. If you object, we will stop this processing immediately and will not contact you again for marketing purposes. You do not need to give a reason.
To object, use the unsubscribe link in any of our emails, reply to any message from us asking us to stop, or email privacy@fasthub.ai.
6.2 Other Rights
Depending on your location, you may also have the right to:
- Access: request a copy of your personal data, including information about its source
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data
- Restriction: limit how we process your data
- Portability: receive data you provided in a structured, machine-readable format
- Object to processing based on legitimate interests on other grounds
- Withdraw consent at any time
To exercise these rights, contact privacy@fasthub.ai. We respond within one month. You also have the right to lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi).
7. Data Security
We implement appropriate technical and organisational measures, including encryption in transit and at rest, access controls with multi-factor authentication, logging of access to personal data, and data protection training for personnel. The full set of measures applying to platform processing is set out in Annex B of our Data Processing Addendum, available on request. No method of transmission over the internet is entirely secure.
8. International Data Transfers
Fasthub is established in Finland. Where we provide the hosting capacity for the platform, customer data — including personal data — is processed and stored within the European Union by default. Where a customer elects to provide its own capacity, the customer determines the location of processing and is responsible for compliance with any applicable transfer requirements.
Some of the tools we use for sales, marketing and business information may involve processing by providers established outside the European Economic Area, or transfers to such providers. Where this occurs, we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with supplementary measures as appropriate. Section 12 identifies the location and transfer basis for each category of recipient. You may request a copy of the relevant safeguards from privacy@fasthub.ai.
9. Children's Privacy
Our services are directed at organisations and are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for their privacy practices.
11. Changes to This Policy
We may update this Privacy Policy. We will notify you of significant changes by posting the updated policy on this page, updating the "Last updated" date, and — for material changes affecting registered users — by email.
12. Categories of Recipients
| Category of recipient | Role | Location and transfer basis |
|---|---|---|
| Sales engagement and CRM platforms | Processors (Art. 28) | Hosting in the EU; some support and administrative access from the United States under the 2021 Standard Contractual Clauses and the EU–US Data Privacy Framework. |
| Professional networking and business information providers, and the contact-data providers engaged through our outreach platform | Sub-processors of our outreach platform, or independent controllers of their own databases — sources for us rather than processors | Predominantly EEA. One provider's group is established outside the EEA, and one involves transfers to the United States under Standard Contractual Clauses and the EU–US Data Privacy Framework. |
| Business email, calendar and document collaboration | Processor (Art. 28) | EEA contracting entity; transfers to the United States under the 2021 Standard Contractual Clauses and the EU–US Data Privacy Framework. |
| Website analytics | Processor (Art. 28) | Hosting in the EEA; provider established in a country covered by a European Commission adequacy decision. |
| Accounting, payroll, audit and legal advisers | Processors or independent controllers as applicable | Finland. |
| Hosting and infrastructure for the integration platform | Sub-processors under our Data Processing Addendum | European Union. Named in Annex C of the Data Processing Addendum. |
Processors act only on our documented instructions under a written Article 28 agreement. Independent controllers decide for themselves what data to collect and are responsible for informing the individuals concerned; where we obtain data from such a source, we become controller of our own copy and give you the information required by Article 14 at our first contact with you.
Identifying the individual providers. We describe recipients by category rather than by name, as permitted by Articles 13(1)(e) and 14(1)(e) GDPR. If you would like to know the individual providers within any category, including each one's identity, location and transfer mechanism, contact privacy@fasthub.ai and we will tell you. We will also provide this if you make an access request under Article 15.
This section covers processing for which Fasthub is the controller. Where Fasthub acts as processor on a customer's behalf, the sub-processors used for that processing are named in Annex C of our Data Processing Addendum and are notified to customers in advance of any change.