Applies to capfore.com
Last updated: 11 September 2026
Data controller
CapFore Oy
Business ID 3430851-3
Firdonkatu 2, 00520 Helsinki, Finland
Email: gdpr@capfore.com.
1. What this policy covers
This policy describes how CapFore Oy processes personal data in connection with the capfore.com website: data collected when you visit the site, and data you give us when you contact us or request access to further information.
It does not cover the processing of debtor data. If you are a customer with a payment matter, the policy that applies to your data is published on our local sites at capfore.fi and capfore.se.
2. Whose personal data we process
We process personal data relating to visitors to capfore.com, and to representatives of banks, lenders, investors, service providers and other organisations who contact us or with whom we do business.
3. What personal data we process
Contact and enquiry data
Name, company, role, email address, telephone number and the content of your message, together with any information you send us in the course of subsequent correspondence.
Business relationship data
Records of meetings, correspondence and agreements, including information about the organisation you represent and your role in it.
Technical data
IP address, device and browser information, pages visited and similar data collected through cookies and comparable technologies. Our use of cookies is described in our Cookie Policy.
4. Why we process personal data, and on what legal basis
Responding to enquiries
We process contact and enquiry data in order to answer your message and to follow up on it. The legal basis is our legitimate interest in responding to business enquiries addressed to us, and, where relevant, steps taken at your request prior to entering into a contract.
Managing business relationships
We process business relationship data in order to manage and develop our relationships with clients, counterparties and service providers. The legal basis is our legitimate interest in conducting our business.
Operating and improving the website
We process technical data in order to keep the site secure and working, and to understand how it is used. Necessary cookies are used on the basis of our legitimate interest; other cookies are used only with your consent.
Statutory obligations
Where we are required to retain records, for example for accounting purposes, the legal basis is compliance with a legal obligation.
5. Sources of data
We collect personal data directly from you. We may also collect data from public sources such as company registers, your employer's website and professional networking services, where this is relevant to a business relationship.
6. Disclosure of personal data
We disclose personal data to service providers only to the extent necessary for the services they provide to us, including website hosting, email and communication services, customer relationship management and analytics. These providers process the data on our behalf and under our instructions.
We may also disclose data to authorities where there is a legal basis for doing so, and to our advisers where necessary for the establishment, exercise or defence of legal claims.
7. Transfers outside the EEA
We do not routinely transfer personal data outside the European Economic Area (EEA). Where a service provider processes data outside the EEA, we safeguard the transfer using the Standard Contractual Clauses approved by the European Commission.
8. Retention
We retain enquiry data for as long as is necessary to deal with your enquiry and for a reasonable period afterwards, normally no longer than two years from our last contact, unless the enquiry leads to a business relationship. Business relationship data is retained for the duration of the relationship and for the period required by law or by the limitation periods applicable to potential claims. Technical data collected through cookies is retained for the periods set out in our Cookie Policy.
9. Your rights
Under the EU General Data Protection Regulation you have the right:
- to be informed about the processing of your personal data
- to access your data
- to have your data rectified
- to have your data erased
- to restrict processing
- to data portability
- to object to processing carried out on the basis of legitimate interest
- to withdraw consent where processing is based on consent.
Not all rights apply in every situation. Exercising these rights requires verification of your identity.
To exercise your rights, or if you have any question about this policy, contact us at gdpr@capfore.com.
You may also lodge a complaint with the supervisory authority:
Office of the Data Protection Ombudsman
Lintulahdenkuja 4, 00530 Helsinki, Finland
P.O. Box 800, 00531 Helsinki, Finland
tietosuoja(at)om.fi
10. Security
We use technical and organisational security measures, including restriction of access rights, encryption, access monitoring and staff training. Data is held in secured systems with restricted access, and we monitor our service providers' compliance with their data protection obligations through contract management.
11. Changes to this policy
We update this policy whenever our services, our processing of data or the applicable legislation change. The current version is always available on capfore.com.
CapFore Oy · Business ID 3430851-3 · Firdonkatu 2, 00520 Helsinki, Finland