Privacy policy
Last updated: 8 August 2026
This privacy policy explains how Grasperk Oy (“we”, “us”) processes personal data when you use the Nolla Maps website and request early access. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (1050/2018).
1. Data controller
The controller of the personal data is:
Grasperk Oy (auxiliary business name: Nolla Maps) Business ID: 3168297-2 Finland Email: hello@nollamaps.com
Nolla Maps is an auxiliary business name of Grasperk Oy. All personal data described here is processed by Grasperk Oy.
2. What data we collect and why
We collect personal data only for specific, limited purposes related to the Nolla Maps service and this website.
- Early access / beta waitlist: work email (required), and optionally your name and company/organisation. Purpose: to receive and manage your request, communicate about the private beta, and invite you when access opens.
- Website technical data: server and security logs that may include IP address, timestamp, and basic request metadata. Purpose: to operate, secure, and troubleshoot the website and the early-access API (including rate limiting abuse).
- We do not use advertising cookies, visitor profiling, or third-party analytics trackers on this marketing site.
3. Legal bases for processing
We process personal data only when a GDPR legal basis applies:
- Article 6(1)(b) GDPR — processing necessary to take steps at your request prior to entering into a contract (handling your early-access request and related beta invitations).
- Article 6(1)(f) GDPR — legitimate interests in keeping the website secure and reliable (technical logs and abuse prevention). Our interests are balanced against your rights; logs are limited and short-lived.
- Article 6(1)(a) GDPR — consent, if we ever ask for optional consent for a purpose that is not covered above. You may withdraw consent at any time without affecting prior lawful processing.
4. Where the data comes from
We receive early-access data directly from you when you submit the form. Technical log data is generated automatically when you use the website or API.
5. Recipients and processors
We use carefully selected service providers that process personal data on our behalf (processors), under contracts that meet Article 28 GDPR requirements:
- Brevo (Sendinblue SAS, France / EEA) — stores early-access contacts and related attributes (such as name, organisation, and locale) so we can manage the waitlist and send beta-related email.
- UpCloud Oy (Finland / EEA) — hosts the website and API in European data centres and may process technical logs necessary to deliver the service.
6. Transfers outside the EEA
We do not transfer personal data outside the European Economic Area (EEA). All processors we use for this website and the early-access waitlist are established in the EEA, and processing is carried out in the EEA.
In particular, waitlist data is processed by Brevo in the EEA, and the website is hosted by UpCloud in the EEA. We do not use vendors outside the EU/EEA for these purposes.
If that ever changed, we would update this policy before any such transfer and apply the safeguards required by Chapter V GDPR.
7. Retention
We keep personal data only as long as needed for the purposes above:
- Early-access contacts: until the private beta programme ends, or you ask us to erase your data, and in any case no longer than 24 months from your last relevant interaction unless a longer period is required to establish, exercise, or defend legal claims.
- Technical security logs: typically for a short period (normally up to 90 days), unless a longer retention is needed to investigate a security incident.
8. Your rights
Under the GDPR and Finnish data protection law, you have the right to:
- access your personal data (Article 15)
- rectify inaccurate data (Article 16)
- erase your data (“right to be forgotten”, Article 17), where applicable
- restrict processing (Article 18)
- data portability (Article 20), where applicable
- object to processing based on legitimate interests (Article 21)
- withdraw consent at any time, where processing is based on consent
- lodge a complaint with a supervisory authority
9. How to exercise your rights
To exercise your rights, or ask questions about this policy, contact us at hello@nollamaps.com. We may need to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu):
Office of the Data Protection Ombudsman Lintulahdenkuja 4, 00530 Helsinki, Finland https://tietosuoja.fi Email: tietosuoja@om.fi
10. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or alteration. Access to waitlist data is limited to people who need it for operating Nolla Maps.
12. Children
Nolla Maps is directed at businesses and professional users. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this privacy policy when our processing or legal requirements change. The “Last updated” date at the top will be revised, and the current version will always be available on this page.