Privacy Notice
This notice explains how Clarius Oy processes personal data in the Cards and B.Cards service. The notice is part of the service's terms of use.
1. Controller
Clarius Oy, business ID 3260640-2
Soininkuja 7A, 00740 Helsinki, Finland
Email: info@clarius.fi
For the content of the Card, the controller is the Customer. The Customer decides what data they enter on the Card — including the contact person's and employees' data. The Provider acts as processor of that data.
2. Data collected
Account data — name and email address. These are obtained through Google sign-in.
Card content — company name and contact details, contact person's name, job title, telephone number, email address and photograph, and corresponding data from employee slots. These are entered by the Customer.
Enquiries — contacts sent through the Card's enquiry form: name, telephone number and message.
Billing data — data required for invoicing in respect of the paid version.
Technical log data — to ensure the operation and security of the service.
The Service does not collect special categories of personal data or payment card details.
3. Purpose and legal basis of processing
| Purpose | Legal basis |
|---|---|
| Creating and maintaining an account | Performance of a contract |
| Displaying the digital business card | Performance of a contract |
| Passing enquiries to the Customer | Performance of a contract |
| Invoicing and accounting | Legal obligation |
| Technical operation and security of the service | Legitimate interest |
4. Retention period
Account data and Card content are retained for as long as the account is active. After the account is closed, the data is deleted within 30 days.
Enquiries are retained with the Card for as long as the Customer does not delete them and the account is not closed.
Invoicing and accounting records are retained for the period required by the Finnish Accounting Act: source documents for at least six years from the end of the calendar year in which the financial period ended.
5. Recipients of data
The Provider does not sell or disclose personal data for marketing purposes. Data is processed by the following sub-processors:
| Service | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Data storage and running the service | EU — europe-north1 (Finland) |
| Resend | Sending notification emails | United States. Sending may be routed via Ireland, but account data, logs and email metadata are stored in the United States. |
| Anthropic | Machine translation of texts entered on the Card | United States |
To the extent that data is transferred outside the EU, the transfer is based on the standard contractual clauses approved by the European Commission.
6. The Card is public
The Card is public. Data entered on the Card is visible to anyone who knows the Card's address or scans the QR code. The Card is not password-protected. The Customer decides what data they publish.
7. Rights of the data subject
The data subject has the right to:
- access their own data;
- rectify inaccurate data;
- request erasure of data;
- restrict or object to processing;
- data portability.
Requests should be sent by email to info@clarius.fi. We respond within one month.
If the request concerns the content of a Card, it should primarily be addressed to the Customer who owns the Card, who is the controller of that data.
Supervisory authority. The data subject has the right to lodge a complaint with a data protection authority. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi). A data subject may also lodge a complaint with the supervisory authority of their own country of residence.
8. Automated decision-making
The Service does not carry out automated decision-making or profiling that would produce legal effects concerning the data subject.
9. Changes to this notice
This notice may be updated. Customers are notified of material changes by email. Each version has a date, which serves as the version identifier.