Privacy Policy
1. Who we are
PS Enterprise Oy (business ID 3395168-9), operating under the brand Gatech (“we”, “us”, “Gatech”), is the data controller for personal data processed in connection with our website gatech.fi, our quotation and sales process, our customer support, and the software services we provide (including EntryNodes Access Management).
2. What personal data we process
We process the categories of personal data listed below only where necessary for the purposes described in Section 3.
- Contact data — name, company, role, email address, phone number, country.
- Project / order data — building type, traffic volume, site location, equipment requested, quotation history, purchase orders, invoices, payment data (last four digits of card only — we do not store full card numbers).
- Technical data — IP address, browser type, device identifiers, log data, cookies, pages visited, time spent on pages.
- Communications data — emails, chat messages, support tickets, call notes.
- Software service data (EntryNodes / AI-CAM / smart lockers) — administrator account data, audit-log events (timestamp, door, credential ID), member-list metadata synced from the customer’s ERP/CRM. We do not receive raw member personal data unless the customer chooses to share it through an integration.
3. Purposes and legal bases
We process personal data on the following GDPR Article 6 legal bases.
- Performance of a contract (Art. 6(1)(b)) — quotation, order fulfilment, delivery, installation, warranty, software service operation, customer support.
- Legitimate interest (Art. 6(1)(f)) — improving the website and our services, fraud and security monitoring, B2B direct marketing to existing business contacts, defending legal claims.
- Legal obligation (Art. 6(1)(c)) — bookkeeping, tax, statutory product-safety records, sanctions screening.
- Consent (Art. 6(1)(a)) — marketing emails to new contacts, non-essential cookies, customer case studies that name your organisation.
4. How we collect data
We collect data directly from you when you request a quote, place an order, contact support, sign up for marketing, or use our software. We also collect technical data automatically through the website. In limited cases we receive data from our authorised resellers, integrators or sub-processors acting on your behalf.
5. Recipients and sub-processors
Personal data is shared with the following categories of recipients, under written data-processing agreements where required by GDPR Article 28.
- Cloud infrastructure providers (EU/EEA hosting for EntryNodes and the website).
- Payment service providers for invoicing and card payments.
- Logistics carriers for delivery (DHL, Schenker and similar).
- Authorised installation partners for on-site commissioning.
- Professional advisers — accountants, auditors, legal counsel.
- Public authorities where required by law (tax, customs, courts).
We do not sell personal data and we do not transfer personal data to third parties for their own marketing.
6. International transfers
Our primary processing is in Finland and the EU/EEA. Where data is processed outside the EEA (for example by certain enterprise email tools), we rely on the European Commission’s adequacy decisions or on Standard Contractual Clauses (SCC) supplemented with technical safeguards. A list of current sub-processors and applicable transfer mechanisms is available on request.
7. Retention
We retain personal data only as long as necessary for the purposes described above.
- Quotation correspondence — up to 24 months after the last contact.
- Order, delivery and warranty data — for the life of the product plus statutory retention (typically 10 years for warranties and accounting records under Finnish law).
- Software audit logs — by default 24 months, configurable per customer contract.
- Website analytics — see the Cookies Policy.
- Marketing data — until consent is withdrawn or the legitimate-interest basis no longer applies.
8. Your rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy,
- request rectification of inaccurate data,
- request erasure where the legal grounds allow,
- restrict or object to processing,
- data portability,
- withdraw consent at any time without effect on prior processing,
- lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) or your local supervisory authority.
To exercise any right, contact myynti@gatech.fi. We respond within 30 days.
9. Security
We apply industry-standard organisational and technical measures, including TLS in transit, encryption at rest for software services, role-based access control, audit logs, regular penetration testing and supplier security review.
10. Children
Our products and services are addressed to businesses and adult professionals. We do not knowingly collect personal data from minors.
11. Changes
We update this Policy when our processing changes. The “Last updated” date at the top of this page reflects the latest version. Material changes are communicated to active customers by email.