Privacy Policy

Renessai Oy (“Renessai”, “we”, “us”) respects your privacy. This policy explains the personal data this website processes, the cookies it uses, and the registers we maintain under the EU General Data Protection Regulation (GDPR).

Last updated: 17 June 2026

Cookies and Analytics

Cookies are small text files that your web browser saves on your device.

This website sets no analytics, advertising, or tracking cookies of any kind, and it does not track individual visitors. Because the site only ever uses cookies that are strictly necessary to deliver a service you have explicitly requested, no cookie consent banner is required under the EU ePrivacy rules, and none is shown.

The complete list of cookies the site can set:

  • Restricted client areas. Parts of the site are private and available by invitation only. When an invited person signs in to such an area, we set one first-party session cookie so their access continues to work during the visit. The cookie is limited to the restricted area it belongs to, cannot be read by scripts, is only sent over a secure connection, and expires automatically after at most 15 days. It exists solely to provide the access the visitor requested and is never used for tracking. As part of operating and securing these areas, sign-ins and access to them are logged. Visitors who never sign in to a restricted area never receive any cookie from us.
  • Contact form bot protection (Cloudflare Turnstile). The form on our contact page is protected by Cloudflare Turnstile, which loads from challenges.cloudflare.com and analyses technical browser signals to tell people from bots. Turnstile does not place tracking cookies and does not follow you across sites; Cloudflare processes this data as described in the Cloudflare Privacy Policy.

Web analytics

We use Cloudflare Web Analytics to understand, in aggregate, how this site is used and how fast it loads. It is a privacy-first measurement tool: it sets no cookies, uses no localStorage or any other client-side storage, and does not fingerprint visitors via IP address, browser characteristics, or any other signal. We only ever see aggregate numbers, such as page views, referrers, countries, and page-load performance, never profiles of individual visitors. The measurement script is served by Cloudflare, which processes this data as described in the Cloudflare Privacy Policy.

Open roles on the careers page

The open positions shown on our careers page are retrieved by our own server from our recruitment system, Gem. Your browser never connects to Gem while you browse our site, and no data about you is sent to Gem by viewing the page. If you choose to view or apply for a role, you move to our job board hosted by Gem at jobs.gem.com, which operates under the Gem Privacy Notice. Applications submitted there are processed as described in the Applicant Register section below.

Applicant Register – Renessai Oy

Controller

Renessai Oy (Business ID: 3442358-9) Bulevardi 6 00120 Helsinki phone +358 10 375 6402

Contact person for register matters

Any questions concerning the register shall be sent to careers@renessai.com.

Name of the register

Applicant register of Renessai Oy and its group companies.

Purpose of use of the register

The register is used for processing and retaining job applications in the recruitment processes of the company and its group companies. We use the recruitment tool Gem to support sourcing, managing candidates, and communicating during the recruitment process. Job applications are submitted through our job board hosted by Gem at jobs.gem.com, which operates under the Gem Privacy Notice; the data submitted there is processed as part of this register.

Retention of personal data

Personal data is retained for two (2) years. The applicant can choose to give consent for retaining the data for longer than two years.

Data to be registered

The following data of the applicants will be processed:

  • applicant’s basic information (name, contact information)
  • further information of the applicant, which is provided voluntarily and in free form (application, CV, etc.)

Regular sources of data

The data recorded to the register is regularly obtained in the following ways:

  • the data is received from the data subject him/herself
  • at job interviews
  • from possible references provided by the applicant
  • from publicly available professional sources (e.g., LinkedIn) when relevant to the recruitment process

Disclosure of the data

The data may be processed within the group companies to the extent required for recruitment. The data will not be disclosed outside of the group companies.

Erasure and adapting of the data

The data may be erased or adapted upon the person’s request. Requests shall be sent to careers@renessai.com.

Transfer of the data outside of the EU or the EEA

Applicant data is processed using the electronic services Trello and Gem. These services may transfer and store personal data in countries outside the EU or the EEA, specifically the United States.

  • Trello is certified under the EU–U.S. Data Privacy Framework.
  • Gem provides GDPR-aligned safeguards for international transfers and may also process data in the United States.

By submitting the application, the applicant consents to the transfer of their personal data outside the EU/EEA, when required for the use of these services. The privacy policies of the services are available here:

Protection of the register

Data in electronic form is retained in databases that are protected by technical and programmatic means ensuring information security. Only specifically authorised persons with defined access rights may access the data.

Customer and marketing register Renessai Oy

Controller

Renessai Oy (Business ID: 3442358-9) Bulevardi 6 00120 Helsinki phone +358 10 375 6402

Contact person for register matters

Any questions concerning the register shall be sent to contact@renessai.com.

Name of the register

Person register for customers and marketing for the Renessai Oy and its group companies.

Purpose of use of the register

Personal data is processed on the basis of the company’s legitimate interests or in the case of persons independently indicating interesting in receiving information, consent given by the data subject. The register is used for processing, retaining and managing customer relationships (including potential customers) and partner relationships of the company and its group companies. The information is also used for marketing purposes, including targeted marketing, direct marketing and segmentation. Information can also be used for business planning and development, market research and measuring amounts of customers.

The company may use subcontractors for offering and delivering its services. In this case personal data can be transferred to subcontractors to the extent needed for service delivery.

The company may use software of an external service provider for customer and marketing communication.

Data to be registered

The following data of the customers will be processed:

  • company data
  • contact information of the customer contact person: name, title, mail address, email, phone
  • customer relationship history
  • data related to customer communication and marketing
  • data related to customer satisfaction surveys
  • other data provided by customers

Regular sources of the data

The data recorded to the person register is regularly obtained in the following ways:

  • the data gathered during all the phases of a customer relationship: marketing, sales, contract signing, customer relationship management.
  • the data to be registered is received from the data subject him/herself, for example by indicating interest by signing up for a newsletter.
  • other sources of data are used in accordance with the law.

Disclosure of the data

The data will not be disclosed to third parties unless required by legislation or regulations by authorities.

Service or software providers of the company may be located or retain data outside of the EU or the EEA. In such cases, the company aims to ensure an adequate level of protection of the information security, as the law requires, by using EU standard clauses concerning the transfer of the data to the third countries.

Protection of the register

Data in the electronic form are retained in databases, which are protected by technical and programmatic means for ensuring information security. Only previously specified persons, who have been given a separately defined license, have the access to the data.

Erasure and adapting of the data

The data may be erased and adapted upon the person’s request. The requests shall be sent to contact@renessai.com.