1. Data controller
Nurho (sole-proprietor business based in Helsinki, Finland) is the data controller responsible for the personal data described in this policy. Where Nurho processes personal data on behalf of a client (for example, inside an automation system deployed for them) Nurho acts as a data processor and the client remains the controller; the terms of that processing are governed by the client agreement and a separate Data Processing Agreement (DPA).
For all controller-side processing (the website, cold outreach, contractual relationships with prospects and clients), Nurho can be reached at hello@nurho.net.
2. What personal data we collect
We keep the surface area deliberately small. Depending on how you interact with Nurho, we may process:
From visitors to this site
- Standard server log data (IP address, user-agent, referrer, timestamp) for security and abuse-prevention purposes only.
- No analytics cookies, no tracking pixels, no advertising identifiers (see §11. Cookies).
From people who contact us, book a call, or become clients
- Identity and contact data: name, business email, company name, role.
- Communication data: the content of emails, calls (notes only, calls are not recorded without explicit consent), messages and documents you share.
- Booking data: when you schedule a call via Cal.com, the calendar event details and your declared timezone.
- Commercial data: invoicing details where you become a paying client (legal name, billing address, VAT/EU VAT number if applicable).
From cold outreach prospects
- Publicly available business contact data: name, role, business email, employer, public profile URLs.
- Notes and outreach-history metadata maintained for the purpose of running compliant, non-harassing outreach (see §5. Cold outreach).
3. Why we use it
- To respond to enquiries and run the booked discovery call.
- To deliver contracted services, scope work, build and deploy automation systems, hand them over.
- To invoice clients and meet our statutory record-keeping obligations.
- To run compliant outbound outreach aimed at decision-makers at businesses we believe we can genuinely help.
- To secure the website and infrastructure against abuse.
We do not sell personal data. We do not share it with advertising networks. We do not profile prospects beyond what is necessary to determine whether they are a relevant audience for our work.
4. Legal bases for processing
We rely on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)), for client work and the necessary pre-contract steps that precede it.
- Legitimate interests (Art. 6(1)(f)), for cold business-to-business outreach to clearly identified decision-makers; for website security; for general communications. Where we rely on legitimate interests we have completed a Legitimate Interests Assessment balancing our interests against your rights and freedoms, and you can always object (see §9. Your rights).
- Legal obligation (Art. 6(1)(c)), for tax, accounting and record-keeping obligations imposed by Finnish and EU law.
- Consent (Art. 6(1)(a)), narrowly, where you opt in to specific things such as recording a call or receiving non-essential communications.
5. Cold outreach: how we run it
Nurho performs business-to-business outreach to decision-makers using publicly available contact data. We take this seriously and operate well above the regulatory minimum:
- Only business email addresses of clearly identified individuals at clearly identified businesses are contacted, never generic role inboxes used to bypass consent rules, and never private email addresses.
- Every message identifies Nurho as the sender, the purpose of the message, and a one-click way to opt out of any future contact.
- Opt-outs are honoured immediately, retained as a permanent suppression record, and never re-imported from a fresh data source.
- We maintain a Legitimate Interests Assessment for each campaign and can produce it on request.
- We do not contact prospects in jurisdictions whose anti-spam regime requires prior opt-in consent for B2B email (we maintain a country-level exclusion list).
6. How long we keep data
- Website server logs: up to 30 days, then deleted or aggregated.
- Email and call notes: for the duration of the conversation plus 12 months, unless an active client relationship exists.
- Prospect outreach records: until you opt out or 24 months of inactivity, whichever is first. Opt-out / suppression records are retained indefinitely to honour your request.
- Client engagement records: for the duration of the engagement plus the statutory retention period required by Finnish accounting law (currently 6 years from the end of the financial year).
7. Who we share data with
We keep the list of sub-processors deliberately short, and we use them only for the purposes described below:
- Email provider, to send and receive business email.
- Cal.com, to schedule discovery calls.
- Video-call provider, to host the discovery call itself.
- Hosting provider (EU-resident, currently Hetzner), for website and infrastructure hosting.
- Accounting and invoicing software, to issue invoices and meet our statutory bookkeeping obligations.
An up-to-date list of sub-processors is available on request to hello@nurho.net.
8. International transfers
Our primary infrastructure and hosting is EU-resident. Some sub-processors (notably calendar, email and video-call providers) may transfer data to the United States. Where this is the case, we rely on the EU-U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses with appropriate supplementary measures, as required by GDPR Chapter V. Where a client requires fully EU-only processing for their engagement, we can configure the stack accordingly.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased (the "right to be forgotten"), subject to legal retention obligations.
- Restrict or object to processing, in particular, to object at any time to processing based on our legitimate interests, including any direct marketing.
- Data portability, receive your data in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (
tietosuoja.fi).
To exercise any of these rights, email hello@nurho.net with a description of your request. We aim to respond within 30 days and will tell you if we need longer.
10. Security
We follow a defence-in-depth approach: TLS in transit, encryption at rest where the underlying service supports it, scoped credentials per environment, principle-of-least-privilege access, audit logging of administrative actions, and timely application of security updates. When delivering automation systems to clients we apply the same primitives by default, they are part of the build, not an upsell.
11. Cookies and tracking
This site does not use cookies for advertising or third-party analytics. A single localStorage entry (nurho-theme) may be set in your browser to remember your dark/light preference; you can clear it at any time using your browser settings. Cal.com (used for booking) may set its own cookies on its own domain; refer to cal.com/privacy.
12. Changes to this policy
We update this policy when our practices change. The "Last updated" date at the top of this page always reflects the most recent revision. For material changes, we'll notify existing clients in writing.
13. Contact
Questions, requests, or complaints: hello@nurho.net. We don't currently appoint a Data Protection Officer because the scale of our processing does not require one under Article 37 GDPR, but the email address above is monitored by the founder personally.