Database Register
Privacy Notice - GDPR Article 14
Last updated: 26 March 2026
This notice is provided in English. It is governed by Finnish and EU law (the GDPR).
1. Data controller
Axiora Labs Oy (Business ID: 3605198-5)
Helsinki, Finland
Email: [email protected]
2. Data Protection Officer
The Data Protection Officer can be reached at: [email protected]
3. Data subjects
This notice covers individuals whose data is processed in FlowDial's B2B company database. Data subjects include corporate decision makers, responsible persons, board members, CEOs, and other individuals who act in a public role in business.
Data is not collected directly from data subjects but from public sources. For this reason, data subjects are informed about the processing through this notice in accordance with Article 14 of the EU General Data Protection Regulation (GDPR).
4. Categories of personal data
The database contains personal data in the following categories:
- Name - first name and surname
- Job title and role - title and position within the company (e.g. CEO, board member)
- Role and seniority classification - categorisation by decision-making level (e.g. C-level, leadership team, middle management)
- Professional email address - email address associated with the company domain
- Professional phone number - publicly available phone number of the company or the individual
- Company affiliation - company name, business ID, and the individual's role at that company
- Public professional profiles - URLs of publicly accessible professional networking profiles
- Derived data - identification of the company's technology stack from its public website, and signal data related to the company
The data we process is professional contact data. We do not collect or process personal email addresses, home addresses, personal phone numbers, national identification numbers, or special categories of personal data (GDPR Art. 9).
5. Data sources
Personal data is collected from publicly available sources (GDPR Art. 14(2)(f)). Sources include:
- Finnish official company registers - public sources. Trade-register data and related public information (board members, CEOs, signing rights), basic company data, industries, and registration data.
- Finnish public tax records - public source. VAT-registered companies, employer register, prepayment register.
- Companies' own websites - public source. Publicly displayed contact information, contact persons, team data, and press releases.
- Professional networking services - publicly available profiles. Job titles, employment data, and professional skills from public profiles.
- Commercial company-information services - public sources. Company data, financial data, and decision-maker data collected from public sources.
- Finnish official statistics - public source. Industry classifications and regional company statistics.
- Business and financial news - public sources. Executive appointments, organisational changes, and press releases.
All sources are publicly available. We do not obtain personal data from secret or confidential sources.
6. Purposes of processing
Personal data is processed for the following purposes:
- Providing the B2B information service: Making professional contact data of corporate decision makers available through FlowDial for lawful B2B purposes
- Database maintenance and updates: Ensuring data accuracy and timeliness through regular refreshes
- Identification of relevant contacts: Assisting customers in finding the right contacts and companies
- Service improvement: Improving data coverage and quality
7. Legal basis
Processing of personal data is based on the controller's legitimate interest (GDPR Art. 6(1)(f)). The legitimate interest is enabling efficient business-to-business communication by providing accurate information about individuals acting in professional roles.
The legitimate interest has been assessed using the three-part test specified in EDPB Guidelines 1/2024:
7.1 Identification of legitimate interest
The controller's legitimate interest is providing a B2B information service that enables businesses to operate more efficiently. The service helps companies find the right contacts for sales, marketing, recruitment, and investment activity. The Court of Justice of the EU has confirmed (Case C-621/22, KNLTB) that commercial interests can constitute a legitimate interest.
7.2 Necessity of processing
A B2B information service cannot meaningfully operate without the professional contact data of corporate decision makers. We process only data that is necessary for the purpose of the service - professional contact data, not personal data.
7.3 Balancing test
The balance between the legitimate interest and the rights of data subjects has been assessed as follows:
- Nature of the data: The data processed consists of professional contact information related to the individual's role in business - not their private life
- Public availability: All data originates from publicly available sources (official registries, company websites, public business-information services)
- Reasonable expectations: Individuals acting in public business roles can reasonably expect their professional contact information to be available for B2B purposes. Section 4 of the Finnish Data Protection Act supports this assessment.
- Minimal impact on privacy: Processing does not target data within the sphere of private life and does not cause significant harm to data subjects
- Safeguards: Data subjects have the right to object to processing and to request deletion of their data at any time
8. Recipients of data
Personal data may be disclosed to the following categories of recipients:
- FlowDial customers: B2B companies that use the service for lawful business purposes. When customers export data from the service, they act as independent data controllers and are responsible for their own GDPR compliance.
- Technical subprocessors: Service providers related to the platform infrastructure (hosting, database services) that process data on our behalf under a data-processing agreement.
- Authorities: Where required by law.
We do not sell personal data to third parties.
9. International transfers
Data is processed and stored primarily in data centres located in the EU/EEA. If data is transferred outside the EU/EEA (for example via a technical subprocessor), transfers are safeguarded by EU Standard Contractual Clauses (SCC) or other transfer mechanisms under Chapter V of the GDPR. The EU-US Data Privacy Framework (DPF) is accepted for certified US recipients.
10. Retention
Personal data is retained for as long as it remains accurate and necessary for the purposes of processing:
- Professional contact data: Refreshed regularly from original sources. Data is verified against source registries on a routine basis. If the source updates or removes a record, the database is updated correspondingly within a short period.
- Role-related data: Removed when the individual no longer holds the role and the change is reflected in the source.
- Objection requests: When a data subject objects to processing, the data is removed from the database within 30 days and the individual is added to a permanent suppression list to prevent future collection.
11. Rights of data subjects
Right to object (GDPR Art. 21)
You have the right to object at any time to processing of your personal data based on legitimate interest. After your objection we will no longer process your data, unless we have compelling legitimate grounds that override your interests. If your data is used for direct marketing, you have an absolute right to object - processing will stop immediately without a balancing test (GDPR Art. 21(2)).
Send objection notice to: [email protected]. We will process your request within 30 days.
You also have the following rights under the GDPR:
- Right of access (Art. 15): Right to obtain confirmation of whether your data is being processed, a copy of all personal data concerning you, and information about the origin of the data and the sources used.
- Right to rectification (Art. 16): Right to request correction of inaccurate or outdated data.
- Right to erasure (Art. 17): Right to request removal of your data from the database. After deletion, you are added to a suppression list that prevents re-collection.
- Right to restriction (Art. 18): Right to request restriction of processing in certain situations.
- Right to lodge a complaint (Art. 77): Right to file a complaint with a supervisory authority (see section 15).
Note that the right to data portability (Art. 20) does not apply to processing based on legitimate interest.
All requests should be sent to [email protected]. We respond within 30 days. If a request is complex, the response period may be extended by up to two months, in which case we will inform you of the delay and the reasons for it.
12. Profiling and automated decision-making
The FlowDial service allows companies to be filtered and classified by criteria (industry, location, revenue, headcount). This is directed at companies as legal entities, not at natural persons. The service does not make decisions based solely on automated processing within the meaning of GDPR Article 22 that would have legal or similarly significant effects on natural persons. Our customers always make the decisions about whom to contact themselves.
13. Notification to data subjects
This notice is publicly available at flowdial.io/database-register and has been available since 26 March 2026. Data subjects are informed about processing as follows (GDPR Art. 14(3)):
- Data subjects with email addresses: Individuals whose professional email addresses are in our database receive notice of processing within one month of first collection, or at the latest at the time of first contact if the data is used for outreach.
- Data subjects without email addresses: For individuals whose email addresses are not available, we apply the disproportionate-effort exception of GDPR Art. 14(5)(b). In these cases, notification is provided through this publicly available notice. We have implemented appropriate safeguards, including the public availability of this notice and an effective objection mechanism.
14. Information security
We protect personal data with appropriate technical and organisational measures in accordance with GDPR Article 32:
- TLS encryption in transit
- Encryption at rest
- Access control and least-privilege permissions
- Regular security reviews and vulnerability assessments
- Servers located in EU data centres
- Breach detection and notification procedures (GDPR Art. 33-34)
15. Supervisory authority
If you consider that the processing of your personal data does not comply with data-protection law, you have the right to lodge a complaint with a supervisory authority:
Office of the Data Protection Ombudsman
Lintulahdenkuja 4, 00530 Helsinki, Finland
Phone: 029 566 6700
Email: [email protected]
tietosuoja.fi
16. Contact
For questions about this notice or about processing of personal data, please contact:
Axiora Labs Oy
Data Protection Officer
[email protected]
