Zure_09_2022-63_sRGB_300dpi_©Sami_Heiskanen

Our Privacy Policy

We care about your privacy

Zure is committed to protecting your privacy and to complying with applicable data protection and privacy laws. Throughout this Privacy Policy the term “personal data” means information relating to an identified or identifiable individual (i.e. a natural person).

1. Introduction and scope

This privacy policy describes how Zure Group Oy and its group companies (“Zure”, “we”) process personal data of customers, potential customers and their contact persons, suppliers, partners and other business stakeholders as well as data of job applicants and people interested in Zure as a workplace, website visitors, newsletter subscribers, event participants, and job applicants.

We process personal data in accordance with the EU General Data Protection Regulation (2016/679, “GDPR”), the Finnish Data Protection Act (1050/2018) and the Finnish Act on Electronic Communications Services (917/2014).

The processing of our own employees’ personal data is described in a separate internal employee privacy notice and is not covered by this policy.

2. Data controller and contact details

Zure Group Oy
Business ID 3152774-5
Kaivokatu 8 B, 00100 Helsinki, Finland
info@zure.com

Zure Group Oy is the data controller for the processing described in this policy. Where a Zure group company carries out its own customer or recruitment activities, that company acts as the controller for those activities. In all privacy matters you can contact us at info@zure.com or through your Zure contact person.

3. What personal data we collect and where it comes from

We collect the following categories of personal data:

  • Basic and contact details: name, email address, phone number, job title and role, employer or company, company address details, preferred language.
  • Customer relationship data: offers, orders, contracts, project and delivery information, correspondence and meeting notes, invoicing and payment information, feedback and satisfaction survey responses.
  • Marketing data: newsletter subscriptions, marketing consents and prohibitions (opt-outs), event registrations and participation, interactions with our emails, website and campaigns.
  • Recruitment data: job application, CV, cover letter, links you provide (e.g. LinkedIn, portfolio), interview notes, assessment results and, with your consent, references.
  • Automatically collected technical data: IP address, browser type and version, device and operating system information, pages visited, time and date of visit, referring site and cookie identifiers.

We collect personal data primarily from you, for example when you contact us, sign a contract, subscribe to a newsletter, register for an event or submit a job application. We also receive personal data from your employer or colleagues (for example when you are named as a contact person for a project), and we may collect business contact details from publicly available sources such as trade registers, company websites and professional networking services.

We do not intentionally process special categories of personal data (such as health data or trade union membership) in the contexts covered by this policy. Please do not include such data in job applications or other communications unless it is essential.

4. Purposes and legal bases of processing 

We process personal data for the following purposes and on the following legal bases:

Purpose

Legal basis

Delivering our services and products; managing offers, orders, contracts and projects

Performance of a contract (6(1)(b)) where you are a party to the contract

Legitimate interest (6(1)(f)) where you act as your employer’s contact person

Customer relationship management, customer communication and satisfaction surveys

Legitimate interest (6(1)(f))

Invoicing, accounting and financial administration

Legal obligation (6(1)(c)): Accounting Act (1336/1997) and tax legislation

Direct marketing, B2B prospecting, newsletters, remarketing, event invitations and event management (see section 5)

Legitimate interest (6(1)(f)) for existing customers, potential customers and B2B contacts

Consent (6(1)(a)) where required by law

Recruitment and processing of job applications

Steps taken prior to entering into a contract (6(1)(b))

Consent (6(1)(a)) for retaining applications for future openings and for certain assessments

Website analytics and development of our website and services

Consent (6(1)(a)) for non-essential cookies

Legitimate interest (6(1)(f)) for aggregated statistics

Information security and prevention and investigation of misuse

Legitimate interest (6(1)(f)); legal obligation (6(1)(c))

Establishment, exercise or defence of legal claims

Legitimate interest (6(1)(f))

Where we rely on legitimate interest, our interests are: providing, developing and marketing our services to businesses; creating, maintaining and developing customer, prospect, and stakeholder relationships; and securing our operations. We have assessed that these interests are not overridden by your interests or fundamental rights, taking into account the professional, business-to-business context of the processing.

You are not under a statutory obligation to provide personal data to us. However, certain data is necessary for us to enter into and perform a contract, respond to your inquiry or process your job application.

5. Direct marketing and customer communication

We may contact representatives of our existing customers, suppliers and partners with communications and marketing concerning our services on the basis of our legitimate interest, without separate consent. GDPR Recital 47 recognises direct marketing as a purpose that may be based on legitimate interest.

Under the Finnish Act on Electronic Communications Services (917/2014), we may send electronic direct marketing (such as email) without prior consent to persons in their professional role, where the marketed services relate to that role, and to existing customers regarding services similar to those they have already purchased from us. Electronic direct marketing to private individuals in other situations requires prior consent.

Our legitimate interest also covers business-to-business prospecting. We may identify potential customer companies based on business characteristics such as industry, size or technology environment, collect the business contact details of relevant persons in those companies from publicly available sources, and approach them about services we reasonably assess to be relevant to their professional role and their company’s business. When we obtain your contact details from a source other than you, we provide the information required by GDPR Article 14 no later than at the time of our first communication with you, or within one month of collecting the data.

Every direct marketing message we send contains an easy way to opt out. You have the right to object to direct marketing at any time and free of charge. After an objection, we retain only the minimum data needed to honour the prohibition (a suppression record).

6. How long we keep personal data

We retain personal data only for as long as it is needed for the purposes described above or as required by law.

When a retention period expires, we delete the personal data or irreversibly anonymise it. Anonymised data may be used for statistical purposes. The same retention periods are applied in the systems we use, including our CRM.

7. Recipients of personal data

We do not sell personal data. We disclose or transfer personal data only as follows:

  • Zure group companies: for internal administrative purposes, such as group-level customer relationship management and reporting.
  • Processors: that process personal data on our behalf and under our instructions, based on data processing agreements under GDPR Article 28. These include our CRM and marketing platform (HubSpot: customer, potential customer and stakeholder data), our recruitment system (Teamtailor: job applicant data), and providers of IT and cloud hosting, email and collaboration tools, website analytics, financial administration and event production.
  • Authorities and other third parties: where we have a legal obligation to disclose data (for example tax authorities or courts), and our auditors, legal counsel and other professional advisers under confidentiality obligations.
  • Parties to corporate transactions: if we are involved in a merger, acquisition or sale of assets, personal data may be disclosed to the parties involved under confidentiality obligations.

8. Transfers outside the EU and EEA

We process personal data primarily within the European Economic Area. Job applicant data in our recruitment system is hosted within the EU.

Where a service provider processes personal data outside the EEA, we ensure an adequate level of protection by relying on a European Commission adequacy decision (GDPR Art. 45), including the EU–U.S. Data Privacy Framework for certified U.S. providers such as HubSpot, or on the European Commission’s Standard Contractual Clauses (GDPR Art. 46(2)(c)) supplemented by additional safeguards where necessary.

9. Cookies and similar technologies

Our website uses cookies and similar technologies. Non-essential cookies (such as analytics and marketing cookies) are used only with your consent, which you can give, refuse and withdraw at any time through the cookie banner on our website. Detailed information about the cookies we use and their lifetimes is provided in our separate Cookie Policy at zure.com.

10. How we protect personal data

We protect personal data with technical and organizational measures appropriate to the risk. These include encryption of data in transit and, where appropriate, at rest; access management based on the need-to-know principle and multi-factor authentication; logging and monitoring; secure software development practices; confidentiality obligations and data protection training for our personnel; and contractual data protection and security obligations imposed on our processors.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and, where the risk is high, also the affected individuals, as required by GDPR Articles 33 and 34.

11. Automated decision-making and profiling

We do not make decisions based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22).

Our marketing may involve light profiling, such as segmenting contacts and scoring leads in our CRM, in order to target relevant content. You may object to this at any time as described in section 12.

12. Your rights

You have the following rights under the GDPR:

  • Access (Art. 15): the right to know whether we process your personal data and to receive a copy of it.
  • Rectification (Art. 16): the right to have inaccurate or incomplete data corrected or completed.
  • Erasure (Art. 17): the right to have your data deleted, for example when it is no longer needed or you withdraw consent, unless we have a legal obligation or another legal ground to retain it.
  • Restriction (Art. 18): the right to have processing restricted in certain situations, for example while the accuracy of the data is being verified.
  • Data portability (Art. 20): the right to receive, in a structured, commonly used and machine-readable format, the data you have provided to us that we process based on consent or a contract, and to have it transmitted to another controller where technically feasible.
  • Objection (Art. 21): the right to object to processing based on legitimate interest on grounds relating to your particular situation. You may object to direct marketing, including related profiling, at any time and without justification, and we will stop that processing without exception.
  • Withdrawal of consent (Art. 7(3)): where processing is based on consent, the right to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise your rights, contact us at info@zure.com or through your Zure contact person. We may need to verify your identity before fulfilling a request. We respond within one month; if the request is complex, we may extend this by up to two further months, in which case we will inform you.

If you consider that our processing of your personal data infringes data protection law, you have the right to lodge a complaint with the supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki (postal address: P.O. Box 800, 00531 Helsinki), www.tietosuoja.fi.

14. Changes to this privacy policy

We may update this privacy policy from time to time, for example due to changes in our services, systems or legislation. The current version, with its last-updated date, is always available at zure.com/privacy-policy. If we make material changes, we will inform you on our website or, where appropriate, by email before the changes take effect.

Contact Us

Your personal data is controlled by Zure Group Oy, Kaivokatu 8B, 00100 Helsinki, Finland, info@zure.com. If you have any questions about this Privacy Policy, please contact us.

Last update 18 September 2026.