Skip to content

Privacy Policy

Anhis Smart Innovations privacy policy — in accordance with the EU General Data Protection Regulation (GDPR)

Privacy Policy

Updated: March 16, 2026

This privacy policy describes how Anhis Smart Innovations collects, processes, and protects personal data in accordance with the EU General Data Protection Regulation (GDPR, 2016/679).


1. Data Controller

Anhis Smart Innovations Tuomas Piirainen (sole proprietorship) Email: tuomas@anhis.fi Phone: +358 40 6698346 Location: Kuopio, Finland

The data controller has not appointed a separate Data Protection Officer (DPO), as the processing activities do not require one under GDPR Article 37. For privacy-related inquiries, contact: tuomas@anhis.fi.


2. Personal Data Collected

2.1 Contact Form

  • Name
  • Email address
  • Company name (optional)
  • Message content
  • IP address (anonymized)
  • Browsing data (page, duration, source)
  • Device and browser technical information
  • Cookie identifiers (Google Analytics)

2.3 AI Chatbot (Aihio AI)

  • Chatbot conversation content
  • Session technical data

2.4 Booking (Cal.com)

  • Name and email address (when making a booking)

PurposeLegal Basis (GDPR Art. 6)Explanation
Responding to contact requestsArt. 6(1)(b) — contractual necessityData is processed at the user’s request to prepare a potential contract
Sending email messagesArt. 6(1)(b) — contractual necessityProcessing contact requests via the Resend service
Website analyticsArt. 6(1)(a) — consentGoogle Analytics is activated only after cookie consent
AI chatbot serviceArt. 6(1)(f) — legitimate interestProviding customer service to website visitors
Appointment bookingArt. 6(1)(b) — contractual necessityArranging consultation meetings
Technical website operationArt. 6(1)(f) — legitimate interestEnsuring website functionality (theme selection, cookie settings)

4. Data Recipients and Processors

Personal data is processed by the following third parties on behalf of the data controller:

Service ProviderPurposeLocationSafeguard
Vercel Inc.Website hosting and server-side operationsUSA/EUEU Standard Contractual Clauses (SCCs), DPA
Resend Inc.Contact form email deliveryUSAEU Standard Contractual Clauses (SCCs), DPA
Google LLCGoogle Analytics 4 (with consent only)USAGoogle Consent Mode v2, EU Standard Contractual Clauses, DPA
Cal.com Inc.Appointment booking systemUSA/EUDPA
Aihio AIAI chatbot serviceEU (Finland)Own service, data stays in the EU

Data is not disclosed to third parties for marketing purposes.


5. Data Transfers Outside the EU/EEA

Some personal data is transferred outside the EU/EEA (to the USA) through the following service providers: Vercel, Resend, Google, and Cal.com.

Transfer safeguards:

  • EU Standard Contractual Clauses (SCCs) — Commission-approved model contract clauses
  • Data Processing Agreement (DPA) — data processing agreement with each service provider
  • Google Consent Mode v2 — analytics data is collected only with user consent

6. Data Retention Periods

Data TypeRetention Period
Contact form messages12 months from last contact
Google Analytics data14 months (Google default setting)
AI chatbot conversationsSession-based — no persistent storage
Booking information12 months from booking date
Cookie settings365 days

Data is deleted after the retention period expires or upon request by the data subject.


7. Rights of the Data Subject

You have the following rights under the GDPR:

  • Right of access (Art. 15) — the right to know what data has been stored about you
  • Right to rectification (Art. 16) — the right to request correction of inaccurate data
  • Right to erasure (Art. 17) — the right to request deletion of your data (“right to be forgotten”)
  • Right to restriction of processing (Art. 18) — the right to restrict the processing of your data
  • Right to data portability (Art. 20) — the right to receive your data in a machine-readable format
  • Right to object (Art. 21) — the right to object to processing based on legitimate interest
  • Right to withdraw consent — you may withdraw your consent at any time (e.g., analytics cookies) without affecting the lawfulness of processing carried out before the withdrawal

Requests regarding your rights: tuomas@anhis.fi. We will respond to requests within 30 days.


8. Right to Lodge a Complaint

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority:

Office of the Data Protection Ombudsman (Finland) Visiting address: Lintulahdenkuja 4, 00530 Helsinki, Finland Postal address: P.O. Box 800, 00531 Helsinki, Finland Email: tietosuoja(at)om.fi Phone: +358 29 566 6700 Website: tietosuoja.fi


9. Automated Decision-Making and Profiling

The AI chatbot (Aihio AI) used on the website answers questions using artificial intelligence, but does not make automated decisions that have legal or similarly significant effects on the data subject (GDPR Art. 22).

The chatbot is a customer service tool that assists in finding information. It does not profile users or make decisions on their behalf.


10. Cookies

The website uses essential and analytics cookies. Analytics cookies are activated only with user consent. A detailed description of cookies can be found in our cookie policy.


11. Changes to This Privacy Policy

We reserve the right to update this privacy policy. Significant changes will be communicated on this page by updating the date. We recommend checking this page regularly.