YardMate Logo menu
  • Home
  • Members
    • Apply for membership
    • See all members
  • Services
    • Cruise Line Services
    • Human Resources
    • Outfitting
    • Logistics
    • Design
    • Building & Machinery
    • Supportive Operations
    • Accommodation & Transport
    • Customized Solutions
  • Jobs
    • Applying instructions
    • Open jobs
  • Contact
    • Contact Us
    • Press
    • Invoice Info
  • News
  • Login
  • YardMate.fi
  • Home
  • Memberschevron_right
    • Apply for membership
    • See all members
  • Serviceschevron_right
    • Cruise Line Services
    • Human Resources
    • Outfitting
    • Logistics
    • Design
    • Building & Machinery
    • Supportive Operations
    • Accommodation & Transport
    • Customized Solutions
  • Jobschevron_right
    • Applying instructions
    • Open jobs
  • Contactchevron_right
    • Contact Us
    • Press
    • Invoice Info
  • News
  • Login
arrow_back
  1. Home
  2. GDPR Compliance

GDPR compliance

Last updated: 21 September 2026

Implementation in progress. YardMate is actively completing its GDPR compliance programme. This page reports current product controls and planned governance work; it is not a certification or a claim that every organisational measure has already been completed.

Controls already reflected in the platform

  • Role-based access for users, member companies and administrators.
  • Short-lived authentication and workflow cookies with secure-cookie support.
  • Email and authenticator-app multi-factor authentication support.
  • Encrypted private messages and attachments, with authenticated access and malware scanning before delivery.
  • Self-hosted anti-automation challenges, rate limiting and security-event records.
  • Administrative deletion tools and automatic recurring enforcement of the published retention periods for supported record types.
  • Daily compressed database backups to non-public host-mounted storage, with restricted filesystem permissions and automatic 30-day rotation.
  • Core infrastructure hosted in Finland.

Some controls are deployment-dependent and must be enabled and maintained in production. Their presence in the software alone does not replace operational review.

Ongoing compliance programme

  • Complete records of processing activities, lawful-basis review and data-flow mapping.
  • Monitor recurring deletion and periodically verify it against the published production retention schedule.
  • Maintain processor agreements, subprocessor records and transfer assessments.
  • Document data-subject request, incident response and breach-notification procedures.
  • Complete a data protection impact assessment where the final processing scope requires one.
  • Periodically review privacy notices, browser-storage wording and production security settings.

Your rights

Depending on the processing, you may have rights to access, correct, erase, restrict or receive your personal data, to object to processing, and to withdraw consent. You may also complain to the Office of the Data Protection Ombudsman in Finland ↗.

To make a request, use our contact form. We will verify identity before disclosing or changing account information.

Related information

Read the Privacy Notice, Data Processing Addendum, Cookie Information and EU Ownership and Hosting page.

YardMate.fi

The Official Industrial Partner.

  • Built for EU Pay Transparency ↗ (opens in a new tab)
  • 100% EU-owned · Core hosted in Finland
  • GDPR compliance · implementation in progress
Explore
  • Home
  • Marketplace
  • Members
  • News
  • Contact Us
  • Press
  • Invoicing
Legal
  • Terms
  • Privacy
  • Data Processing Addendum
  • Acceptable Use
  • Cookies
© 2026 YardMate Oy. All rights reserved.
Your privacy We use necessary cookies for secure sign-in and forms. We do not use analytics or advertising cookies. Learn more