Privacy Notice
1. Controller
YardMate Oy is the controller for account administration, website contacts, membership operations, security and its own business communications. Business ID: 2826525-4. Registered address: Ahdenkallionkatu 3, 05820 HYVINKÄÄ. Privacy contact: kari.harkonen@yardmate.fi. You can currently reach us through the contact form.
2. Personal data we process
YardMate is a business-to-business service. Account holders are representatives or personnel associated with member companies; YardMate does not offer consumer accounts.
- Identity and business details, such as name, title, organisation, Business ID and VAT information.
- Contact and account details, including email address, phone number, sign-in credentials and verification status.
- Member profiles, RFQs, quotations, documents, private messages and encrypted attachments you choose to provide.
- Contact-form content and follow-up status.
- Prompts, instructions, source material and generated output when you choose to use an AI-assisted feature. You should not submit special-category personal data, confidential personal data or information that is unnecessary for the requested task.
- Technical and security data, such as IP address, browser information, authentication events, anti-abuse signals and cookie choices.
- Service usage and administrative records needed to operate and support the platform.
3. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Create accounts for member-company users, provide membership and operate marketplace features | Performance of the agreement with the member company, steps requested before that agreement, and legitimate interests in administering authorised users |
| Authenticate users, prevent abuse, protect users and keep audit records | Legitimate interests and legal obligations |
| Respond to enquiries and manage business relationships | Contract steps and legitimate interests |
| Provide AI-assisted drafting, analysis, classification or matching features requested by a user | Contract and legitimate interests in providing and improving the requested Service |
| Meet accounting, regulatory and dispute-handling duties | Legal obligations and legitimate interests |
| Send optional marketing communications | Consent or legitimate interests where permitted; you may object at any time |
Our legitimate interests are operating and improving a secure business service, preventing fraud and misuse, supporting users, maintaining business relationships and establishing or defending legal claims. We balance those interests against the rights and reasonable expectations of the people concerned.
Account identity, business contact and authentication information marked as required is necessary to create and administer an account or provide a requested feature. If it is not provided, we may be unable to provide that part of the Service. Profile details, marketing choices and content submitted to optional features are voluntary unless the interface or your organisation's agreement states otherwise.
4. Sources and disclosures
We receive data from you, your organisation, other marketplace participants and public business registers. We may share data with authorised participants you choose to interact with, YardMate personnel who need access, and vetted providers supporting hosting, email, security and business validation. We may also disclose data where legally required or during a corporate transaction subject to appropriate safeguards.
5. International transfers and subprocessors
Core application hosting is in Finland. YardMate uses the following subprocessors to provide the Service:
| Provider | Purpose and data | Primary processing location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting and storage, including account, member, marketplace, message, document and technical data stored in YardMate. | Helsinki, Finland |
| Zoho Corporation B.V. | Transactional and account-related email delivery, including recipient details, message content and authentication or verification messages. | Primarily the European Union |
| Google Gemini AI | AI-assisted features requested by a user. Relevant prompts, instructions, source material and generated output may be sent to the service. | European Union where an EU regional service endpoint is configured; otherwise processing may occur internationally under applicable safeguards |
| Mistral AI | AI-assisted features requested by a user. Relevant prompts, instructions, source material and generated output may be sent to the service. | European Union by default; limited international processing may occur under applicable safeguards |
Mailgun Technologies, Inc. is an additional email subprocessor only where the Mailgun provider is enabled for a deployment. When used, YardMate selects Mailgun's EU processing region for message data.
YardMate limits information sent to an AI provider to what is needed for the selected feature. Users remain responsible for avoiding unnecessary personal data in prompts and source material. YardMate will use enterprise or API terms appropriate for processor use and configure available data controls so that submitted customer content is not used to train general-purpose models, unless a different use is clearly disclosed and has an appropriate legal basis.
Before relying on a non-EEA provider for personal data, YardMate will use an applicable GDPR transfer mechanism and assess supplementary safeguards. YardMate requires subprocessors to provide protections equivalent to those in the YardMate Data Processing Addendum. Customers will receive at least 30 days' advance notice of a material addition or replacement and may raise a reasonable data-protection objection during that period.
You may request information about the applicable transfer safeguard, including a copy where available subject to necessary redactions, by contacting the privacy address in section 1.
6. Retention
We keep personal data only while needed for the relevant service, security, legal or dispute purpose. When a supported record is deleted, it is immediately removed from normal use and its retention period starts. The production maintenance process checks for eligible records when the application starts and every 24 hours thereafter, then permanently removes them in controlled batches.
| Deleted record | Retention period |
|---|---|
| Invitations | 90 days |
| Contact submissions, news, pages, templates, keywords, countries and currencies | 365 days |
| Private messages, user and member records, and member groups | 730 days |
| RFQs, quotations, driving-log records and daily-allowance records | 2,555 days (approximately seven years) |
Deleting an RFQ also removes its related quotations and messages from normal use. Each part is then permanently deleted according to its category above: messages after 730 days, and the RFQ and quotations after 2,555 days. Associated RFQ files are permanently removed with the RFQ.
Data may be retained longer where required by law, needed to establish or defend legal claims, or subject to a preservation obligation. Accounting material is retained for the applicable statutory period. Records not needed for those purposes are not intentionally retained beyond the stated period.
Deleted database data may remain in access-controlled, compressed daily backups for up to 30 days. Production backups are stored outside the public web directory on host-mounted storage with restricted filesystem permissions. Backups are not restored for ordinary access. If a backup is restored for disaster recovery, applicable deletion requests and retention rules are reapplied. Encryption of the underlying backup volume is a production infrastructure control and is verified separately.
7. AI features and automated decisions
AI-assisted features may generate drafts, summaries, classifications or matching suggestions from information a user chooses to submit. Output may be inaccurate and must be reviewed by an authorised user before it is relied on. YardMate does not use these features to make decisions based solely on automated processing that produce legal or similarly significant effects for individuals. If that changes, we will provide the information and safeguards required by applicable law before such processing begins.
8. Security
The platform includes role-based access, multi-factor authentication support, rate limiting, secure-cookie support, encrypted private messages and attachments, malware scanning, and access-controlled downloads. No system is risk-free. We review both software controls and production operations as part of the ongoing GDPR programme.
9. Your rights
Subject to the GDPR's conditions and exceptions, you can request access, correction, erasure, restriction, portability or objection. Where processing is based on consent, you can withdraw it without affecting earlier lawful processing. You may complain to the Office of the Data Protection Ombudsman in Finland .
10. Cookies and updates
See Cookie Information for browser storage details. We may update this notice as the Service, providers or legal requirements change. We will identify the current version and effective date here and give appropriate notice if a change materially affects how we use personal data.