PRIVACY POLICY

Last updated: 2 October 2026

1. Data Controller

Materflow Oy
Ilmarisentie 13
15210 Lahti
Finland

Business ID: 2558696-8
Email: info@materflow.com

Materflow Oy (“Materflow”, “we”, “us”) is responsible for the processing of personal data described in this Privacy Policy.

2. What Personal Data We Process

Depending on your relationship with Materflow, we may process the following types of personal data:

  • name and contact details, such as email address, telephone number and postal address;
  • company, organisation, job title and other business contact information;
  • information relating to enquiries, quotations, orders, projects, deliveries and customer relationships;
  • communications between you and Materflow;
  • invoicing, payment and transaction-related information;
  • information contained in customer files, product models, drawings or other materials submitted to us;
  • technical information relating to the use of our website, such as IP address, browser type, device information, log data and cookie identifiers;
  • marketing preferences and consent information;
  • other information that you voluntarily provide to us.

We only process personal data that is relevant for the purposes described in this Privacy Policy.

3. Where We Receive Personal Data

We primarily receive personal data directly from you when you:

  • contact us;
  • request a quotation;
  • place an order;
  • provide files or product information;
  • communicate with us by email, telephone, website forms or other channels;
  • use our website;
  • otherwise interact with Materflow.

We may also receive business contact information from your employer or organisation, public business information, public registers or other legitimate business sources.

Technical information may be collected automatically when you use our website.

4. Why We Process Personal Data

We may process personal data for the following purposes:

  • responding to enquiries and quotation requests;
  • preparing quotations and entering into contracts;
  • manufacturing and delivering products and services;
  • managing customer and supplier relationships;
  • providing customer support;
  • invoicing, accounting and payment administration;
  • maintaining records relating to orders, projects and production;
  • improving our services, internal processes and website;
  • maintaining the security and proper operation of our systems;
  • complying with legal and regulatory obligations;
  • communicating relevant information about our services where permitted by law.

The legal basis for processing depends on the situation and may include:

  • performance of a contract or taking steps at your request before entering into a contract;
  • compliance with a legal obligation;
  • Materflow’s legitimate interests in operating, developing and protecting its business and maintaining customer relationships;
  • your consent, where consent is required.

Where processing is based on legitimate interests, we consider the interests and rights of the individuals concerned before processing the data.

5. Who May Access or Receive Personal Data

Personal data is accessed by Materflow personnel only where necessary for their work.

We may also use external service providers that process personal data on our behalf or provide services necessary for our operations. These may include providers of:

  • website hosting and IT infrastructure;
  • email and communication systems;
  • cloud storage and collaboration tools;
  • customer relationship management systems;
  • accounting and financial administration;
  • production, engineering and business software;
  • cybersecurity, backup and system administration services;
  • analytics and website services;
  • AI-assisted software and services used in business operations.

We do not sell personal data.

Personal data may also be disclosed to authorities or other parties where required by law, legal proceedings or binding official requests.

Where third parties process personal data on our behalf, we require appropriate contractual and security arrangements.

6. International Data Transfers

Some of the service providers used by Materflow may process or store personal data outside Finland, the European Economic Area (EEA), or both.

Where personal data is transferred outside the EEA, we use appropriate safeguards required by applicable data protection legislation. Depending on the destination and service provider, these may include:

  • an adequacy decision by the European Commission;
  • the European Commission’s Standard Contractual Clauses;
  • other legally recognised transfer mechanisms and supplementary safeguards where necessary.

7. Customer Files and Product Models

Customers may provide Materflow with technical files such as 3D models, CAD files, drawings, specifications, photographs and other manufacturing information.

These files are primarily technical production data and do not normally contain personal data. However, where customer files contain personal data, that information may be processed as necessary to provide the requested quotation, manufacturing service, technical evaluation or customer support.

Access to customer files is limited to personnel and service providers who require access for the relevant task.

Customer files and product information are treated as confidential business information in accordance with our applicable contractual and operational practices.

8. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law.

Retention periods depend on the type of information and the nature of the relationship. For example:

  • customer, order and project information may be retained for the duration of the customer relationship and for a reasonable period afterwards;
  • accounting and transaction records are retained for the periods required by applicable accounting and tax legislation;
  • enquiries and communications may be retained where reasonably necessary for customer service, documentation and business continuity;
  • customer production files may be retained where necessary for repeat orders, quality assurance, traceability or customer service;
  • technical logs and website information are retained according to operational, security and analytics requirements;
  • data processed on the basis of consent may be processed until consent is withdrawn, unless another lawful basis applies.

Data that is no longer required is deleted, anonymised or otherwise securely disposed of.

9. Data Security

Materflow uses appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.

These measures may include:

  • access controls and user authentication;
  • restricted access based on work responsibilities;
  • encryption and secure communications where appropriate;
  • backups and system monitoring;
  • security updates and vulnerability management;
  • firewalls and other security systems;
  • contractual confidentiality and data protection obligations for relevant service providers.

No information system can be guaranteed to be completely secure, but we continuously seek to maintain an appropriate level of protection based on the nature of the data and associated risks.

10. Cookies and Consent Management

Our website may use cookies and similar technologies that are necessary for the operation, security and functionality of the website.

We may also use optional cookies or similar technologies for purposes such as analytics or other non-essential functionality.

Where required by law, non-essential cookies are used only after you have provided consent through the website’s consent management system.

You may change or withdraw your cookie consent through the available cookie settings.

Some necessary cookies cannot be disabled because they are required for the website to function correctly.

11. Your Data Protection Rights

Subject to the conditions and limitations provided by applicable data protection legislation, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive personal data you have provided to us in a structured, commonly used and machine-readable format where the right to data portability applies;
  • withdraw consent at any time where processing is based on consent.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise your rights, please contact us at info@materflow.com.

We may need to verify your identity before fulfilling a request.

12. Right to Lodge a Complaint

If you believe that your personal data has been processed in violation of applicable data protection legislation, you have the right to lodge a complaint with a data protection supervisory authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.

You may also contact Materflow directly first so that we can investigate and address the matter.

13. Changes to This Privacy Policy

We may update this Privacy Policy when our services, systems, processing activities or legal requirements change.

The current version of the Privacy Policy will be made available on our website together with the date of the latest update.