01
Data controllers
Each GreenGridLabs operating entity is an independent data controller within the meaning of Art. 4(7) GDPR for the personal data it collects in its own jurisdiction. For general visits to greengridlabs.com, the controller is the entity of the jurisdiction you contact or contract with. Where no specific entity is involved, GreenGridLabs Finland Oy acts as the primary controller for the shared website.
GreenGridLabs Finland Oy
Helsinki, Finland
GreenGridLabs Sweden AB
Visby, Sweden
GreenGridLabs Germany GmbH
Gera, Germany
For the full registered name, address and register entry of each entity, see the imprint. For privacy enquiries and data subject rights, contact info@greengridlabs.com.
02
Scope of this policy
This privacy policy applies to personal data processed by the GreenGridLabs entities in connection with: (a) visits to greengridlabs.com and its subdomains; (b) inquiries and communications sent through the contact form, email or telephone; (c) commercial relationships with customers, suppliers and partners; and (d) on-site visits to GreenGridLabs facilities.
It does not cover the processing of personal data by other companies in the Riveon Group, which is governed by their own privacy notices, nor processing carried out by customers inside their own tenant environments for which GreenGridLabs acts solely as a colocation host.
03
Categories of personal data
Depending on how you interact with us, we may process:
- Identification & contact data — name, job title, employer, email address, phone number, postal address.
- Communication content — messages, attachments and metadata you send us through the contact form, email or other channels.
- Contract data — information needed to negotiate, perform and invoice colocation and related services, including authorised-personnel lists for site access.
- Access & security data — visitor logs, CCTV recordings and electronic access records for our datacenter facilities, where permitted by local law.
- Technical data — IP address, browser type, device identifiers, access timestamps and log files generated when you visit greengridlabs.com.
We do not knowingly collect special categories of personal data (Art. 9 GDPR) and ask you not to submit such data through our public channels.
04
Purposes & legal bases
We process personal data only on a lawful basis as defined in Art. 6(1) GDPR:
- Responding to inquiries — Art. 6(1)(b) (pre-contractual steps) and Art. 6(1)(f) (legitimate interest in answering questions addressed to us).
- Providing and invoicing services — Art. 6(1)(b) (performance of contract).
- Operating and securing facilities — Art. 6(1)(c) (legal obligations under workplace safety, electricity supply and critical-infrastructure regulations) and Art. 6(1)(f) (legitimate interest in physical security).
- Operating and securing the website — Art. 6(1)(f) (legitimate interest in a functioning, attack-resistant website).
- Compliance with legal obligations — Art. 6(1)(c) (tax, accounting, corporate and regulatory retention requirements under Finnish, Swedish and German law).
05Website enquiry forms
We use the contact details, company information and requirements you submit to respond to your enquiry and discuss the requested service. Please provide only the information needed for this purpose.
When you submit a form, its contents and technical request data are sent to Formspark, operated by Trampoline Software SRL, Belgium, to process your enquiry. This includes your IP address and browser information. Formspark stores data in Ireland and Germany; some subprocessors process data outside the EEA. See its privacy policy, data processing agreement and subprocessor list for details.
We use Cloudflare Turnstile to protect enquiry forms from automated abuse. On pages with a form, Cloudflare receives technical browser and device information, including your IP address, to perform a security check. A verification token is sent with your enquiry to Formspark for server-side validation. Cloudflare, Inc. is based in the United States; processing may occur outside the EEA. This processing serves our legitimate interest in preventing spam and securing communications. See Cloudflare’s privacy policy and data processing information. If the check cannot run, you can contact us by email.
Formspark retains submissions until we delete them; deleted submissions remain recoverable for 30 days. Its published retention period for submitter IP addresses and approximate locations is 12 months. Our retention criteria below apply to our handling of your enquiry.
Form entries are not saved in your browser’s local storage. Submitting an enquiry does not start an AI chat or voice session. You can also contact us directly by email.
06
Recipients & processors
Personal data may be disclosed to: other entities within the Riveon Group on a need-to-know basis; external processors that we engage under data processing agreements (Art. 28 GDPR) for hosting, email, customer relationship management, accounting, security and IT services; professional advisors (auditors, lawyers, tax advisors) bound by confidentiality; and public authorities where we are legally required to disclose.
We do not sell personal data. We do not disclose personal data to third parties for their own marketing purposes.
07
International transfers
Our primary processing takes place within the European Union and the European Economic Area. Where a processor operates outside the EU/EEA, we transfer personal data only on the basis of: (i) an adequacy decision of the European Commission; (ii) the Standard Contractual Clauses adopted by the European Commission under Art. 46(2)(c) GDPR; or (iii) another valid transfer mechanism under Chapter V GDPR. Transfers to Switzerland benefit from the Commission's adequacy decision for Switzerland.
A list of the non-EEA recipients and the applicable safeguards can be requested from info@greengridlabs.com.
08
Retention
We keep personal data only for as long as necessary for the purposes set out above or as required by law. Indicative retention periods:
- Inquiry correspondence — up to 24 months after the last contact, unless a contract results.
- Contract and invoice data — up to 10 years, in line with the statutory retention periods under Finnish, Swedish and German accounting and tax law.
- CCTV and access logs — typically 30 to 90 days, depending on site and local law.
- Website log files — up to 14 days for anti-abuse and troubleshooting, then aggregated or deleted.
09
Security
We maintain appropriate technical and organisational measures (Art. 32 GDPR) to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, aligned with ISO 27001 principles. Measures include access control, encryption in transit, segregation of production data, logging, vendor due diligence and a documented incident response process. In the event of a personal data breach subject to Art. 33 GDPR, we notify the competent supervisory authority and, where required, affected individuals without undue delay.
10
Your rights
Subject to the conditions set out in the GDPR and applicable national law, you have the right to:
- obtain confirmation as to whether we process your personal data and, if so, access to that data (Art. 15);
- request rectification of inaccurate personal data (Art. 16);
- request erasure of your personal data (Art. 17);
- request restriction of processing (Art. 18);
- receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller (Art. 20);
- object to processing carried out on the basis of our legitimate interests (Art. 21); and
- where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing (Art. 7(3)).
To exercise any of these rights, please contact info@greengridlabs.com. We may need to verify your identity before acting on a request.
11
Supervisory authorities
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority — in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR). The authorities with jurisdiction over our operating entities are:
Finland
Tietosuojavaltuutetun toimisto
(Office of the Data Protection Ombudsman)
tietosuoja.fi
Reference: Tietosuojalaki 1050/2018
Sweden
Integritetsskyddsmyndigheten (IMY)
imy.se
Reference: Dataskyddslagen 2018:218
Germany
Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)
tlfdi.de
Reference: BDSG & ThürDSG
12Cookies & tracking
This website’s interface does not use analytics or advertising trackers, set cookies, or save form entries in browser storage. Fonts and visual assets are loaded from the website itself.
Cloudflare Turnstile runs on pages containing enquiry forms to prevent automated abuse. Formspark receives your enquiry when you submit a form, as described under website enquiry forms. If you follow an external link, the destination website’s own privacy and cookie practices apply.
If optional tracking or cookie-based features are introduced, this notice will be updated and consent obtained where required.
13
Changes to this policy
We may update this privacy policy from time to time to reflect changes in our processing activities, in technology or in the applicable law. The most current version is always available at greengridlabs.com/privacy-policy/. Material changes will be communicated in advance through the website or, where appropriate, directly to affected individuals.
This privacy policy is published in English for international readability. In the event of a conflict between the English text and any translation, the English version prevails, without prejudice to mandatory rights under the user's local language as required by applicable law.