Privacy Policy
Privacy Policy
- Controller
- Martin Nikiforov, trading as Norppa
- Version
- 2.0
- Effective
- 11 August 2026
- Supersedes
- Version 1.0 (25 July 2026)
This notice is issued under Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Finnish Data Protection Act (tietosuojalaki 1050/2018).
1. What this notice covers, and what it does not
This notice explains what we do with personal data when you:
- visit norppa.co or any of its regional versions (
/en-int,/fi-fi,/ro-ro,/ru-ru); - contact us about Norppa IT or Norppa IT;
- subscribe to our email list;
- become a customer and receive invoices from us;
- apply for work with us.
What it does not cover. When we deliver Norppa IT or Norppa IT to a business customer, we handle personal data that belongs to that customer — their employees, their own clients, the visitors to their website. For that data the customer is the controller and we are only a processor. Section 12 explains that relationship, and it is governed by the data processing agreement we sign with each customer, not by this notice. If you are an employee or a client of a Norppa customer and want to know how your data is handled, ask your employer or that company: they decide, we only act on their instructions.
Storage on your own device — the fact that this site sets no cookies, and the handful of values it keeps in your browser — is covered in detail by our separate Cookie Policy, which forms part of this notice.
This notice does not cover media.norppa.co, which is a separate website with its own notice.
2. Who we are, and how to reach us
| Controller | Martin Nikiforov, a private individual trading under the business name "Norppa" |
| Postal address | Leksankuja 3, 01700 Vantaa, Finland |
| Email for all privacy matters | hello@norppa.co |
| General enquiries | sales@norppa.co · Support: support@norppa.co |
Norppa is a business name, not a registered company. It is not entered in the Finnish Trade Register and has no business ID (Y-tunnus). Legally, the controller is the natural person named above, and correspondence about personal data reaches that person directly. Contact details are also published under section 7 of the Finnish Act on the Provision of Information Society Services (458/2002).
Data protection officer. We have not appointed one, and we are not required to: we are not a public authority, we do not monitor people on a large scale, and we do not process special categories of data on a large scale (Art. 37(1) GDPR). Requests are handled by Martin Nikiforov personally at the address above.
3. Our two roles, kept apart
GDPR distinguishes between a controller, who decides why and how personal data is used (Art. 4(7)), and a processor, who only acts on someone else's instructions (Art. 4(8)). We are both, in different situations, and we do not mix the two.
| We act as | When | Governed by |
|---|---|---|
| Controller | Running this website, answering enquiries, sending our newsletter, invoicing, keeping accounts, recruiting | This notice |
| Processor | Operating a customer's website, backups and monitoring (Norppa IT); administering a customer's Microsoft 365, devices and accounts (Norppa IT) | The data processing agreement with that customer (Art. 28(3)) — see section 12 |
4. Whose personal data we process as controller
- Website visitors — anyone who loads a page.
- Enquirers and prospective customers — people who write to us, request a quote, or ask for a free website check.
- Customer contacts — the individuals we deal with at business customers.
- Newsletter subscribers.
- Job applicants — where we publish an opening.
- Our own administrator account — the single account used to manage site content and invoices.
We do not knowingly process personal data about anyone else, we do not buy contact lists, and we do not enrich or combine data from external sources.
5. What we process, why, on what legal basis, and for how long
Each activity below states the information required by Art. 13(1)(c)–(e) and Art. 13(2)(a).
5.1 Delivering the website
- Data: IP address, browser and device type, requested page, referring page, date and time, response status.
- Purpose: to send you the pages you request, keep the site available, and detect abuse such as brute-force or denial-of-service attempts.
- Legal basis: legitimate interests, Art. 6(1)(f) — we cannot operate a website without processing the request that reaches the server. See section 6.
- Retention: server and access logs are kept 3 months, then deleted.
- Recipient: our hosting provider (section 9).
5.2 Remembering your region and language
- Data: the locale you chose, and a flag recording that we already asked you.
- Storage: in your browser's local storage under the keys
norppa.locale,norppa.locale.asked,norppa.cookie.consentandnorppa.festive. Nothing is sent to us and nothing is linked to you. - Purpose: so that you are not redirected away from the version of the site you picked, and not asked the same question twice.
- Legal basis: legitimate interests, Art. 6(1)(f). Under section 205 of the Finnish Act on Electronic Communications Services (917/2014) storage of this kind is exempt from the consent requirement because it is strictly necessary to provide the service you asked for.
- Retention: until you clear your browser storage. We never see these values.
5.3 Detecting which country you are browsing from
- Data: a two-letter country code taken from the request header our content delivery network
adds (
cdn-requestcountrycode, set by Bunny.net). Your IP address passes through the function that reads this header but is never written down, logged or stored by us. - Purpose: to suggest the right regional version of the site, and to restrict the Russian regional version to visitors in Russia.
- Legal basis: legitimate interests, Art. 6(1)(f).
- Retention: none. The country code is used to produce one response and is not stored.
5.4 Answering your enquiry
- Data: your name, email address, company, the content of your message, and anything else you choose to include. For a free website check: the website address you send and your email address.
- Purpose: to answer you, to prepare a quote, and to keep a record of what was agreed during the sales conversation.
- Legal basis: Art. 6(1)(b) where you are asking us to take steps towards a contract; Art. 6(1)(f) for general correspondence and for keeping a short record of enquiries that do not become contracts.
- Retention: if no contract follows, 12 months from our last exchange, then deleted. If a contract follows, the correspondence is kept for the duration of the contract and 24 months after it ends.
- Recipient: our email provider (section 9). Our contact channels are plain email addresses; there is no web form that stores your message in a database.
5.5 Providing the services and supporting customers
- Data: the name, work email, phone number and role of our contact people at the customer; support requests and what we did about them; the technical configuration we manage.
- Purpose: to perform the contract, to provide support within the response times we promise, and to produce the monthly report.
- Legal basis: Art. 6(1)(b) — performance of the contract; Art. 6(1)(f) for keeping a record of incidents and changes so that we can prove what was done and when.
- Retention: for the duration of the contract, and 24 months after a support case is closed. Records that also serve as accounting vouchers follow 5.7.
5.6 Sending our newsletter
- Data: your email address, and the record of your confirmation (date, time and the fact of confirmation).
- Purpose: to send occasional practical notes about websites, security and small business IT.
- Legal basis: your consent, Art. 6(1)(a), read with Art. 7. For subscribers who are natural persons this is also required by section 200 of the Finnish Act on Electronic Communications Services (917/2014).
- How consent works: we use double opt-in. Nothing is sent until you click the confirmation link in the first email. Subscribing is never bundled with anything else, and is never a condition of buying our services.
- Withdrawing consent: click "unsubscribe" in any email, or write to hello@norppa.co. Withdrawal is as easy as giving consent (Art. 7(3)) and takes effect immediately. It does not affect the lawfulness of anything sent before.
- Retention: until you unsubscribe. We then keep the bare record of your consent and its withdrawal for a further 3 years, because Art. 7(1) requires us to be able to demonstrate that consent was validly obtained.
- Recipient: MailerLite (section 9).
5.7 Invoicing, payments and bookkeeping
- Data: customer name, email address, postal address, country, invoice number and line items, amount, VAT rate, currency, due date, payment status and the payment reference returned by our payment provider. We never see or store your card number.
- Purpose: to invoice you, to take payment, and to keep the accounts we are required to keep.
- Legal basis: Art. 6(1)(b) for the invoice itself; Art. 6(1)(c) — legal obligation — for retaining accounting records, under the Finnish Accounting Act (kirjanpitolaki 1336/1997).
- Retention: invoices and accounting vouchers are kept 6 years from the end of the calendar year in which the financial year ended, as chapter 2 section 10 of the Accounting Act requires. We cannot delete these earlier, even on request — see section 10.3.
- Recipients: Stripe for card payments, and our database provider (section 9).
- Invoice links. Each invoice is reachable through a link containing a long random code. Anyone holding that link can see the invoice, so treat it like the invoice itself and do not forward it.
5.8 Recruitment
- Data: whatever you send us — name, contact details, CV, and the content of your application.
- Purpose: to assess your application.
- Legal basis: Art. 6(1)(f), and Art. 6(1)(b) where you are asking us to take steps towards employment.
- Retention: 12 months from the end of the process. We do not keep applications on file beyond that without asking you first.
5.9 Administering the site
- Data: the email address, hashed password, role and session records of our single administrator account.
- Purpose: to let content, cases and invoices be maintained, and to keep unauthorised people out.
- Legal basis: Art. 6(1)(f).
- Retention: for as long as the account exists; session records 3 months.
5.10 Illustrative photographs
Four pages currently load decorative photographs from Unsplash (images.unsplash.com, served
through imgix). Loading them discloses your IP address and browser type to Unsplash Inc. in the
United States. This is the only request the site makes to a party outside our own control, and it
happens only when you scroll to the section containing the photograph. Everything else your browser
loads comes from us or from a processor acting for us — see section 9 and the Cookie Policy.
- Legal basis: legitimate interests, Art. 6(1)(f), limited to the technical data needed to fetch an image.
- Transfer: United States; see section 8.
- Avoiding it: the images are decorative only. Blocking
images.unsplash.comin your browser removes the request without affecting anything you came to the site for.
5.11 What we do not do
To be unambiguous, because it is easier to verify than to promise:
- Cookieless analytics only. Since 15 August 2026 the site counts page views through SiteSights (Germany), which sets no cookie and writes nothing to your device. It receives the page address, the referring page, your screen width and — as with any request over the internet — your IP address. Lawful basis: legitimate interest in knowing whether anyone reads the site, Article 6(1)(f). You may object under Article 21. No Google Analytics, Plausible, Matomo, Hotjar or equivalent, and no profiling. We do not measure visits at all.
- No advertising or tracking pixels. No Meta Pixel, no Google Ads tags, no LinkedIn Insight Tag, no remarketing of any kind.
- No cookies. The site sets no HTTP cookies whatsoever. The four browser-storage keys in 5.2 are the entire extent of client-side storage.
- No third-party fonts. Typefaces are served from our own server, specifically so that no visitor's IP address reaches Google.
- No cookies of any kind, first-party or third-party. What the site does store in your browser is listed key by key in the Cookie Policy.
- No profiling and no automated decision-making within the meaning of Art. 22 — see section 11.
- No sale of personal data, ever, to anyone, for any purpose.
- No AI training. We do not put customer or visitor personal data into AI or machine-learning systems for training purposes.
6. Our legitimate interests, and how we weighed them
Where we rely on Art. 6(1)(f) we are required to balance our interest against your rights and freedoms. The assessments follow EDPB Guidelines 1/2024. In summary:
| Activity | Our interest | Why it is necessary | Why it does not override your rights |
|---|---|---|---|
| Serving pages, logs (5.1) | Operating and defending the site | A server cannot answer a request without processing it | Minimal data, 3-month retention, no linking to a person, no profiling |
| Region and language memory (5.2) | Not sending you to the wrong language | The alternative is asking on every page load | Stored only in your browser, never transmitted to us |
| Country detection (5.3) | Routing you correctly, honouring a regional restriction | Country is the minimum signal that achieves this | Country code only, IP never stored, nothing retained |
| Enquiry records (5.4) | Being able to reconstruct what was discussed and quoted | Sales conversations must be traceable to be honest | Short retention, ordinary business contact data, deletion on request |
| Incident records (5.5) | Proving what we changed on a system and when | Central to a security service; also protects the customer | Concerns work performed, not personal life; access limited to one person |
| Decorative images (5.10) | Presentation of the site | Only the technical data needed to fetch a file | No cookie, no identifier, and trivially blockable |
If you disagree with any of these balances you can object under Art. 21 — see section 10.6. Where you object to processing based on legitimate interests, we stop unless we can demonstrate compelling grounds that override your objection.
7. Consent, and what happens if you decline
We ask for consent in exactly one place: the newsletter. Everything else runs on contract, legal obligation or legitimate interests, so there is nothing else to accept or refuse.
The banner you may see on your first visit records that we told you what the site stores locally. It is a notice, not a gate: whether you accept or decline, the site behaves identically, because nothing it stores requires your consent under section 205 of Act 917/2014. We would rather say this plainly than present a choice that has no effect.
8. Where your data is, and international transfers
Our design principle is that data stays in the European Economic Area. In practice:
| What | Where it is stored |
|---|---|
| Website files and server logs | Frankfurt, Germany — Hetzner Online GmbH |
| Database, edge functions, administrator account | Frankfurt, Germany — Supabase project region eu-central |
| Email (hello@, sales@, support@) | European Union — Zoho EU data region (zoho.eu) |
| Backups of customer websites | Frankfurt, Germany — Hetzner, 30-day rolling retention |
| Newsletter list | European Union — MailerLite EU data centre |
| Our logo, favicon and news images | Bunny.net — edge nodes in Finland, storage in Sweden and Germany |
Three limited transfers outside the EEA remain, and we name them rather than bury them:
- Supabase Inc. (United States) is the provider of our database platform. The data itself is stored in Frankfurt, but Supabase personnel may access it from the United States for support and maintenance. Safeguard: the Supabase data processing addendum incorporating the European Commission's 2021 Standard Contractual Clauses (Art. 46(2)(c)).
- Stripe, Inc. (United States) receives payment data as a sub-processor of Stripe Payments Europe, Limited (Ireland). Safeguard: Standard Contractual Clauses, and Stripe's certification under the EU–US Data Privacy Framework (Art. 45).
- Unsplash Inc. (United States) receives the IP address of visitors who load a page containing a decorative photograph (5.10). Safeguard: Standard Contractual Clauses in Unsplash's terms; the data is limited to the technical detail of an image request.
MailerLite, Inc. (United States) may act as a sub-processor to MailerLite Limited (Ireland) under the EU–US Data Privacy Framework, although subscriber data is stored in the European Union.
We are aware that the adequacy of the EU–US Data Privacy Framework is under challenge before the Court of Justice (Case C-703/25 P) and that oversight arrangements in the United States have been disrupted. For that reason we do not rely on the Framework alone: every US recipient listed above is also covered by Standard Contractual Clauses, which remain effective if the Framework is annulled. You may request a copy of the relevant clauses from hello@norppa.co.
9. Who else handles your data
These are our processors under Art. 28. Each is bound by a written agreement that restricts them to our instructions, obliges them to keep the data confidential and secure, and requires deletion or return at the end of the engagement.
| Processor | Role | Data | Location |
|---|---|---|---|
| Hetzner Online GmbH (Germany) | Web hosting, backup storage | Site files, server logs, backups | Frankfurt, Germany |
| Supabase (Supabase Inc., US; project in EU) | Database, serverless functions, authentication | Site content, invoices, admin account | Frankfurt, Germany (US access — section 8) |
| Zoho (EU data region) | Correspondence you send us | European Union | |
| MailerLite Limited (88 Harcourt Street, Dublin 2, D02 DK18, Ireland) | Newsletter delivery | Subscriber email addresses, consent records | European Union |
| Stripe Payments Europe, Limited (Ireland) | Card payments | Payment and invoice data | Ireland / EEA, with US sub-processing |
| Bunny.net d.o.o. (Slovenia) | Content delivery for cdn1.norppa.co and news images |
IP address and browser type of the request. Request logging is switched off and IP anonymisation is enabled, so no per-visitor log is kept | Edge in Finland; storage in Sweden and Germany |
| Unsplash Inc. (United States) | Decorative images | IP address, browser type | United States |
We use no other processors as controller. We have no subcontractors, no employees and no freelancers with access to personal data: the only person who can reach any of these systems is Martin Nikiforov.
Beyond processors, we may disclose personal data to our accountant and, where we are legally required to, to tax and other authorities, or to a court. We will not hand over data on an informal request; we require a legal basis and we will tell you unless prohibited by law.
10. Your rights
You can exercise any of these free of charge by writing to hello@norppa.co. We will reply within one month, and will tell you if we need to extend that by up to two further months because the request is complex (Art. 12(3)). We may ask you for information to confirm your identity, but only what is genuinely needed (Recital 64) — we will not demand an ID document for a request that arrives from an email address we already hold.
10.1 Access (Art. 15). A copy of your personal data, plus confirmation of the purposes, recipients, retention and origin.
10.2 Rectification (Art. 16). Correction of inaccurate data and completion of incomplete data.
10.3 Erasure (Art. 17). Deletion where we no longer need the data, where you withdraw consent, or where you successfully object. This right has real limits, and we would rather state them than promise more than we can do: we cannot delete invoices and accounting vouchers before the 6-year period in 5.7 expires, because Art. 17(3)(b) preserves processing required by law. We will delete everything else and tell you exactly what we retained and why.
10.4 Restriction (Art. 18). We stop using the data, but keep it, while an accuracy dispute or an objection is resolved.
10.5 Portability (Art. 20). Data you provided to us, in a structured, machine-readable format, where processing is based on consent or contract. In practice this concerns your newsletter subscription and your customer contact details.
10.6 Objection (Art. 21). You can object at any time to anything we do on the basis of legitimate interests (the activities in section 6). We then stop unless we can show compelling grounds that override your objection. Where processing is for direct marketing, the right to object is absolute and we stop immediately, no balancing (Art. 21(3)).
10.7 Withdrawing consent (Art. 7(3)). At any time, for the newsletter, without giving reasons.
10.8 Not being subject to automated decisions (Art. 22). Not applicable — see section 11.
10.9 Backups. When we delete your data, it may persist in a backup for up to 30 days until that backup rotates out. We do not restore deleted data from backup except to recover from a disaster, and if we ever have to, we re-apply outstanding deletions afterwards.
11. No automated decision-making, no profiling
We make no decisions about you by automated means, and we do not profile you (Art. 13(2)(f), Art. 22). Quotes, service decisions and support priorities are all decided by a person. The automated logic on the site is limited to suggesting a language version from a country code, which has no legal or similarly significant effect and which you can override with one click.
12. When we act as processor for a business customer
Under Norppa IT and Norppa IT we handle personal data that belongs to our customer. We are the processor; the customer is the controller. We act only on their documented instructions (Art. 28(3)(a)) and we sign a data processing agreement before any access is granted.
What we can reach under Norppa IT: the customer's website and its database, files uploaded to it, its server, its DNS and email authentication records, and its backups. Any personal data the customer's own website collects — form submissions, accounts, orders — is inside that scope.
What we can reach under Norppa IT depends on the level of access the customer chooses to grant, and the customer decides this, not us:
| Access level the customer grants | What we can reach |
|---|---|
| Limited / delegated administration | Only the specific functions delegated. Correspondingly, only part of what the service can do is available to the customer. |
| Global administrator | The customer's whole Microsoft 365 tenant: user accounts, group memberships, access rights, security policies, devices, and — technically — mailbox and file content, including any personal data about the customer's own employees and clients held there. |
Where the customer grants global administrator rights, that access is broad by nature and may technically extend to special categories of personal data (Art. 9) if the customer keeps such data in their tenant. We therefore commit, in every processing agreement, that:
- we open mailbox or file content only where a specific task requires it — recovering a message, investigating a phishing report, or migrating an account — and not otherwise;
- administrative actions are logged in the customer's own tenant, where the customer can audit them independently of us;
- access is granted to one named person only, with multi-factor authentication;
- we notify the customer without undue delay of any personal data breach affecting their data, so that they can meet their own 72-hour obligation under Art. 33(1);
- we assist the customer with data subject requests, impact assessments and audits (Art. 28(3)(e)–(f));
- we delete or return their data at the end of the engagement (Art. 28(3)(g)).
Sub-processors we use in that role (Art. 28(2)): Hetzner Online GmbH (Germany) for hosting and backup storage; Microsoft Ireland Operations Limited, where the customer's own Microsoft 365 agreement applies; and our own monitoring and protection tooling, which runs on infrastructure we control in Germany. We will inform customers in advance of any intended change to this list and they may object.
If you are an individual whose data we hold in this role, we will forward your request to the controller who is responsible for it and tell you that we have done so; we are not permitted to act on it ourselves.
13. How we protect personal data
Our measures under Art. 32, described honestly rather than aspirationally:
- Encryption in transit — HTTPS with modern TLS across all services; HSTS on our domains.
- Encryption at rest — provided by our hosting and database providers for stored data and backups.
- Access control — one administrator account, protected by multi-factor authentication. There is no shared login and no second person with standing access.
- Least privilege — database row-level security policies restrict what can be read or written; service credentials are held only in server-side environment variables and never shipped to the browser.
- Separation — customer environments are kept separate from each other and from ours.
- Backups and recoverability — daily backups with 30-day retention and a restore test each quarter, because an untested backup is not a backup (Art. 32(1)(c)).
- Availability monitoring — every 5 minutes, around the clock. Note that monitoring runs continuously; support is available on weekdays. These are two different things.
- Patching — components and dependencies are kept current as part of the service.
- Minimisation by design — the site has no cookies, no cross-site tracking, only cookieless visitor counting, and no contact form that writes your message to a database (Art. 25).
No set of measures makes a system impossible to breach, and we do not claim otherwise. We reduce risk, we watch, and we react.
14. Personal data breaches
If a breach occurs that is likely to result in a risk to your rights and freedoms, we notify the Office of the Data Protection Ombudsman within 72 hours of becoming aware of it (Art. 33). If the risk to you is high, we notify you without undue delay, in plain language, telling you what happened, what data was involved, what we are doing, and what you should do (Art. 34). We keep an internal record of every breach, including ones we do not have to report (Art. 33(5)).
15. Where we get data that does not come from you
Almost all of the personal data we hold comes from you directly. The exceptions, disclosed under Art. 14(2)(f):
- From your employer or colleague — if someone at a customer gives us your work contact details as the person we should deal with.
- From your own website's DNS records — publicly available technical records we read when preparing a free website check for the domain you sent us.
- From our payment provider — confirmation that a payment succeeded or failed.
We do not use data brokers, scrapers, or publicly available lists to build a contact database.
16. Children
Our services are sold to businesses and the site is not directed at children. We do not knowingly collect personal data from anyone under 16 (the age set by section 5 of the Finnish Data Protection Act 1050/2018 for information society services). If you believe a child has sent us personal data, write to hello@norppa.co and we will delete it.
17. Complaints
If you think we have handled your personal data unlawfully, please tell us first — we would rather fix it than argue about it. You can also complain directly to the Finnish supervisory authority at any time (Art. 77), and you do not need to contact us first:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) Visiting address: Lintulahdenkuja 4, 00530 Helsinki, Finland Postal address: PL 800, 00531 Helsinki, Finland Telephone: +358 29 566 6700 Email: tietosuoja@om.fi Complaint form: https://tietosuoja.fi/en/notification-data-protection-ombudsman
You also have the right to an effective judicial remedy (Art. 79) and, where you have suffered damage, to compensation (Art. 82).
18. Changes to this notice
We update this notice when what we actually do changes — not to paper over a change after the fact. The version number and effective date are at the top. If a change materially affects your rights, we will say so prominently on the site, and where we hold your email address for a service you use, we will tell you directly before it takes effect.
Version history:
| Version | Date | Change |
|---|---|---|
| 1.0 | 25 July 2026 | First publication (media technology business) |
| 2.0 | 11 August 2026 | Rewritten for the Norppa IT services. Added the controller/processor split, named all processors and their locations, set concrete retention periods, and removed third-party font loading so the site no longer discloses visitor IP addresses to Google. |
Applicable law
This notice is given under, and should be read with:
- Regulation (EU) 2016/679 (GDPR)
- Finnish Data Protection Act — tietosuojalaki (1050/2018)
- Finnish Act on Electronic Communications Services — laki sähköisen viestinnän palveluista (917/2014), in particular section 200 (direct marketing) and section 205 (storage on terminal equipment)
- Finnish Accounting Act — kirjanpitolaki (1336/1997), chapter 2 section 10 (retention of accounting records)
- Finnish Act on the Provision of Information Society Services — laki tietoyhteiskunnan palvelujen tarjoamisesta (458/2002), section 7 (information to be provided)
- Directive 2002/58/EC (ePrivacy), as implemented in Finnish law
Finnish law governs this notice, and Finnish courts have jurisdiction, without prejudice to your right under Art. 77 and Art. 79 GDPR to bring proceedings in the Member State where you live.
This document states how Norppa handles personal data. It is a statement of our own practice, not legal advice to you.