Privacy Policy for X Firewood Factory Customer Register

This document is the privacy notice required under the EU General Data Protection Regulation (Articles 13 and 14) and the Finnish Data Protection Act (1050/2018).

Prepared on September 11, 2025. Last modified on September 8, 2026.

1 Data Controller

The data controller for the register is:

TP Silva Oy (Business ID: 0550899-7) X Firewood Factory is a brand of TP Silva Oy. Contact person for register matters: Lauri Kälviäinen, Sales Director Address: Technopolis Asemakeskus, Peltokatu 26, 33100 Tampere, Finland Phone: +358 40 834 7776 Email: info@xfirewoodfactory.com

2 Name of the Register

The name of the register is X Firewood Factory Customer Register.

3 Purpose of Processing Personal Data

Personal data is processed for purposes related to managing, administering, and developing customer relationships, providing and delivering services, and developing services and billing. Data is also processed to investigate complaints and other claims.

Additionally, personal data is used for customer communications, including information updates, news, and marketing activities, including direct marketing and electronic direct marketing. Communications may be sent by email, telephone, and WhatsApp, and may include invitations to trade fairs, exhibitions, and other industry events.

Customers and other recipients have the right to prohibit direct marketing targeted at them.

The data controller processes the data itself and uses subcontractors operating on behalf of and for the account of the data controller.

4 Legal Basis for Processing

The legal bases for processing personal data under the GDPR are:

  • The data subject has given consent to the processing for one or more specific purposes (GDPR Article 6(1)(a));
  • Processing is necessary for the performance of a contract to which the data subject is a party or for taking steps prior to entering into a contract at the data subject’s request (GDPR Article 6(1)(b));
  • Processing is necessary for the purposes of the legitimate interests pursued by the data controller or a third party (GDPR Article 6(1)(f)).

The mentioned legitimate interest is based on the relevant and appropriate relationship between the data subject and the controller resulting from the data subject being a customer of the controller and where processing occurs for purposes that the data subject could reasonably expect at the time of data collection and within the context of the relationship.

Legitimate interest is also relied upon for business-to-business direct marketing addressed to representatives of companies and organisations operating in the forestry, firewood production, and wood processing sectors, where the marketing concerns products and events relevant to the recipient’s professional role. The recipient may object to such marketing at any time, and any objection will be given effect without exception.

5 Register Data Content (Categories of Personal Data Processed)

The register may contain the following personal data of each data subject:

  • Basic personal and contact information: first name, last name, address, phone number, email address;
  • Information related to the person’s company or organization and their role or job title in that entity;
  • Direct marketing permissions and prohibitions;
  • Communication history, including messages sent and received by email and WhatsApp;
  • Website addresses, IP addresses, social media profiles, information on ordered services, billing information, and other data related to the customer relationship and services.

6 Regular Sources of Information

Personal data is collected primarily from the data subjects themselves.

The information is obtained directly from customers, for example via online forms, emails, phone calls, WhatsApp messages, social media, customer meetings, or other situations where the customer provides their information.

Personal data is also collected and updated from publicly available sources as permitted by applicable law to fulfill the customer relationship and the controller’s obligations.

Contact details of potential business customers are also collected from publicly available sources, including company websites, publicly available business and trade directories, industry association listings, and trade fair exhibitor and attendee listings. In these cases the categories of data collected are limited to name, job title, employer, business email address, and business telephone number.

7 Retention Period of Personal Data

Personal data is retained only as long and to the extent necessary for the original or compatible purposes for which it was collected.

The necessity of storing data is reviewed every 5 years from the start of the customer relationship; in any case, personal data will be deleted 5 years after the end of the customer relationship, provided all related obligations have been fulfilled. For example, accounting documents are retained for five years after the end of the fiscal year.

Contact details of potential customers who do not enter into a customer relationship are deleted no later than two years after collection, or immediately upon objection to direct marketing.

The controller regularly evaluates the necessity of data retention according to internal practices and ensures that inaccurate, incorrect, or outdated data is deleted or corrected promptly.

8 Recipients and Regular Disclosures of Personal Data

Personal data is not sold or disclosed to third parties for their own independent purposes.

Personal data is processed on the controller’s behalf by the service providers listed in Section 9, under data processing agreements concluded with each of them.

9 Processors and Transfers Outside the EU/EEA

Personal data is processed on behalf of TP Silva Oy by the following service providers:

  • Brevo (Sendinblue SAS) – email marketing
  • Canva Pty Ltd – design and content production
  • Google LLC – Google Analytics, Google Tag Manager, Google Ads
  • HubSpot, Inc. – marketing automation
  • LinkedIn Corporation – advertising
  • Meta Platforms Ireland Limited – Facebook, Instagram, and WhatsApp Business messaging
  • Microsoft Corporation – office and communication software
  • Salesforce, Inc. – customer relationship management
  • The Rocket Science Group LLC d/b/a Mailchimp – email marketing
  • Zoner Oy – website hosting

Some of these service providers are established outside the EU/EEA, mainly in the United States and Australia. Where personal data is transferred outside the EU/EEA, the transfer is based on the EU–US Data Privacy Framework where the recipient organisation is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures.

10 Principles of Register Protection

Materials containing personal data are stored in locked premises accessible only to designated and authorized personnel.

The database containing personal data is located on a server kept in a locked facility with appropriate firewall and technical protection.

Access to databases and systems is restricted to persons with separately granted personal usernames and passwords. Access rights are limited to individuals who need to process the data lawfully. System activities are logged.

Employees and other persons processing personal data are bound by confidentiality obligations.

11 Data Subject Rights

Under the GDPR, data subjects have the following rights:

  • Right to obtain confirmation whether personal data is being processed, and if so, access to the data and information about its processing (GDPR Article 15);
  • Right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal (GDPR Article 7);
  • Right to have inaccurate or incomplete personal data corrected without undue delay (GDPR Article 16);
  • Right to have personal data erased without undue delay under certain conditions (GDPR Article 17);
  • Right to restrict processing under certain conditions (GDPR Article 18);
  • Right to data portability, i.e., to receive personal data provided to the controller and transmit it to another controller (GDPR Article 20);
  • Right to object to processing, including an unconditional right to object to processing for direct marketing purposes (GDPR Article 21);
  • Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects (GDPR Article 22);
  • Right to lodge a complaint with a supervisory authority if the data subject considers that the processing violates the GDPR (GDPR Article 77). In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).

Requests regarding the exercise of data subject rights should be addressed to the contact person mentioned in Section 1.

12 Web Analytics

The following services collect data about visits to the website, including IP address, device and browser information, and cookie identifiers. This data constitutes personal data. It is processed on the basis of consent given via the cookie banner, except where the processing is strictly necessary for the operation of the website.

  • Google Analytics
  • Google Tag Manager
  • Google Ads
  • Mailchimp
  • Meta

13 Targeted Marketing

Based on website visits, and where consent has been given via the cookie banner, we may engage in targeted advertising on the following platforms:

  • Instagram
  • Google
  • Facebook
  • TikTok
  • LinkedIn
X-Firewood factory-logo landscape white