Legal

Privacy Statement

Applies to the nexaflow.fi website and to Google account data connected to the NexaFlow platform · Last updated 20 August 2026

This statement explains how we handle personal data in connection with the nexaflow.fi website. In short: this website uses no cookies, no analytics and no tracking, and we collect no personal data from you unless you choose to contact us.

Scope. Sections 01–04 and 06–12 cover the public website. Section 05 covers the Google account data processed by the NexaFlow platform when a user connects a mailbox to it. All other processing of your firm's and your clients' data within the platform is governed by your service agreement and Data Processing Agreement (DPA).

01 · Who we areData controller

The controller responsible for the personal data described here is an individual operating the NexaFlow service; no company has been incorporated for it yet:

Petteri Tulikoura

Purjeentekijänkuja 7 B 16, 00210 Helsinki, Finland

Privacy contact: petteri@nexaflow.fi

02 · What we collectPersonal data we process

Through this website we process very little personal data:

03 · Why & on what basisPurposes and legal bases

We process the above for the following purposes, under the following legal bases in the EU General Data Protection Regulation (GDPR):

04 · Who we share it withRecipients and processors

We do not sell your personal data. We share it only with service providers who process it on our behalf and under contract:

05 · Google account dataData from a connected Google account

The NexaFlow platform can connect to a user's Google account so that an adviser's own mailbox can inform their work, and so that replies they have approved can be sent from it. This connection is optional and is made only by the account holder, through Google's own consent screen.

What we request, and nothing more

We do not request broader Gmail permissions such as gmail.modify or full-account access. The platform never deletes, alters or labels messages in a connected mailbox.

Nothing is sent without a human decision

The platform may draft a message, but it cannot send one on its own. Every outbound email is proposed to the adviser and is sent only after that person approves it, and an approval applies to that single message.

How this data is handled

Disconnecting and deletion

A connection can be revoked at any time — in the platform's Integrations settings, or from Google's own third-party access page. On disconnection we delete the stored tokens. Message data already stored is deleted in line with the customer's retention settings and their agreement with us, or sooner on request.

Limited Use. NexaFlow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

06 · International transfersData outside the EEA

The website is hosted in the European Union. Some of our providers are established outside the European Economic Area (EEA); where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses.

07 · How long we keep itRetention

Server logs are retained only as long as needed to operate and secure the site, then deleted or anonymised. Correspondence is kept for as long as needed to handle your request and any resulting relationship, after which it is deleted.

08 · Your rightsYour rights under the GDPR

You have the right to request access to your personal data, and its rectification or erasure; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. To exercise any of these, contact us at petteri@nexaflow.fi.

You also have the right to lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi).

09 · SecurityHow we protect your data

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse, including transport encryption (HTTPS) across the site.

10 · ChildrenChildren's data

This website is intended for business audiences and is not directed at children.

11 · ChangesUpdates to this statement

We may update this statement from time to time. The "last updated" date above always shows the current version; material changes will be reflected here.

12 · ContactContact us

For any question about this statement or your personal data, contact petteri@nexaflow.fi.