Privacy Policy

In this privacy policy, we explain how SM Cybersecurity processes personal data on our website, in connection with inquiries, growth coaching, and recruitment.

Updated August 19, 2026

1. Data controller

SM Cybersecurity Oy
Business ID: 3642909-5
Yo-Kylä 27 A 32, 20540 Turku
Email: miki.khomich@sm-cybersecurity.com
Website: https://sm-cybersecurity.fi/

2. Purpose of the privacy policy

The purpose of this privacy policy is to explain what personal data SM Cybersecurity processes, the purposes for which the data is used, the legal basis for processing, how the data is protected, and what rights the data subject has.

3. What personal data do we process?

We may process, for example, your name, email address, phone number, company name, job title or role, the content of your inquiry or message, and information related to appointment bookings. In the context of recruitment, we may process information provided by the applicant, such as details included in the application, contact information, and data related to work history or skills. We only process data that is necessary for the specific purpose.

4. Purposes and legal bases for processing personal data

Personal data is processed for various purposes depending on how you interact with SM Cybersecurity or which service you use. Personal data may be processed, for example, to handle and respond to inquiries, manage customer and partner relationships, provide services, organize meetings and growth coaching, and for recruitment.

In the context of inquiries and customer or partner relationships, the processing of personal data may be based on legitimate interest or the formation or performance of a contract. When organizing appointments and scheduled meetings, personal data may be processed to carry out contract-related actions or to facilitate communication.

In the context of recruitment, personal data is processed to conduct the recruitment process and evaluate applications. Processing may be based on legitimate interest or another basis permitted by applicable law.

If the processing of personal data is based on consent, consent will be requested separately. Providing consent is voluntary, and it may be withdrawn at any time.

The legal basis for each instance of personal data processing is determined by the purpose of the processing and applicable data protection legislation.

5. Where is personal data obtained from?

As a general rule, personal data is obtained directly from the data subject, for example, via website contact forms, email, appointment bookings, growth coaching, or job applications. We may also receive personal data from company representatives or partners when the processing of such data is related to a customer relationship, collaboration, or the delivery of services.

6. To whom may personal data be disclosed?

Personal data may be processed in systems and services used by SM Cybersecurity, as well as by service providers who process data on behalf of SM Cybersecurity to deliver services. Such services may include, for example, website and hosting services, email and collaboration tools, and appointment and video conferencing platforms. Personal data may be disclosed to authorities when there is a legal obligation or other basis under applicable law to do so.

7. Transfers of personal data outside the EU or EEA

Due to the third-party services we use, personal data may in some situations be processed or transferred outside the EU or EEA. Such situations may arise, for example, in connection with the operation of services used for our website, email, appointment scheduling, or video conferencing.

If personal data is transferred outside the EU or EEA, we ensure that the transfer is carried out in accordance with applicable data protection legislation and that appropriate safeguards are in place.

8. Retention of personal data

Information provided via contact forms is generally retained for as long as required to process the inquiry, manage the associated customer relationship, or perform other justified follow-up actions. Recruitment-related information is retained for the duration of the recruitment process and for as long as necessary for any subsequent processing. Personal data is not retained longer than the purpose of processing or legislation requires.

9. Rights of the data subject

In accordance with applicable legislation, data subjects have the right to be informed about the processing of their personal data and to request access to their own personal data. Data subjects may have the right to request the rectification, erasure, or restriction of processing, as well as the right to object to certain processing and to data portability, provided the legal requirements are met. If the processing of personal data is based on consent, that consent may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal. Data subjects also have the right to lodge a complaint with a data protection authority if they believe their personal data has been processed unlawfully. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.

10. Data security

We protect personal data using appropriate technical and organizational measures. Our goal is to prevent unauthorized access, alteration, disclosure, loss, or destruction of personal data. Access rights are restricted based on roles and necessity, and we utilize the security features provided by our service providers as appropriate.

11. Third-party services

In connection with our website and business operations, we use services such as Webflow for website hosting, Microsoft 365 for email and collaboration, Calendly for appointment scheduling, and Google Meet for video conferencing. The use of these services may involve the processing of personal data, and these service providers process such data in accordance with their own privacy policies and terms of service.

12. Automated decision-making and profiling

In the context of inquiries, appointment bookings, or recruitment processes covered by this privacy policy, SM Cybersecurity does not make decisions based solely on automated processing that would have legal or similarly significant effects on an individual. Furthermore, we do not use personal data for such profiling without an appropriate legal basis and prior notification.

13. Changes to the Privacy Policy

We may update this privacy policy if our operations, the services we use, legislation, or our personal data processing practices change. The updated privacy policy will be published on this page. When an update is made, we will also indicate on the page when the privacy policy was last updated.

14. Contact information

If you have any questions regarding the processing of your personal data, wish to exercise your rights as a data subject, or would like more information about this privacy policy, you can contact us via email:

miki.khomich@sm-cybersecurity.com