Legal

Vendor Privacy Notice

Version
d
Date
10 September 2026
Vendor
ModernPath OyBusiness ID 3567407-2 / VAT FI35674072Kimmeltie 10, 90630 OULU, Finland
Privacy contact
privacy@modernpath.ai
Website
modernpath.ai

This Vendor Privacy Notice applies to personal data Vendor processes in its capacity as an independent controller. Where Vendor processes personal data on behalf of a customer in connection with the Services, the applicable DPA and the customer’s instructions apply instead. For contractual clarity, as between Vendor and a customer under an agreement for the Services, this Notice does not form part of that agreement as a contractual term unless expressly incorporated.

This Vendor Privacy Notice explains how the vendor (also “we”, “us”, or “our”) processes personal data when Vendor acts as an independent controller, including in connection with Vendor’s websites, digital services, sales and marketing, contracting, account administration, billing, support communications, partner management, events, security, and related business operations.

Where Vendor processes personal data on behalf of a customer in connection with the Services, the applicable Data Processing Agreement (“DPA”) and the customer’s instructions apply. This Notice does not govern such processor or sub-processor processing, except to the extent Vendor separately processes related personal data in its own capacity as controller, such as for account administration, billing, legal compliance, fraud prevention, or security.

1.Scope

This Notice applies to personal data Vendor processes as a controller in relation to:

  • —visitors to Vendor websites, portals, and online properties;
  • —individuals representing prospects, customers, resellers, OEMs, suppliers, and other business counterparties;
  • —account administrators, billing contacts, procurement contacts, and other authorized representatives of customers and partners;
  • —individuals who communicate with Vendor through sales, support, partner, legal, finance, or other business channels;
  • —attendees of Vendor meetings, events, webinars, or similar activities; and
  • —other individuals whose personal data Vendor receives in the ordinary course of its business operations.

This Notice does not govern Customer Content or other personal data processed by Vendor on behalf of a customer in connection with the Services, except as stated above.

2.Personal data Vendor may collect

Depending on how you interact with Vendor, Vendor may collect and process the following categories of personal data:

  • —Identity and contact data, such as name, work email address, telephone number, job title, employer, department, and country;
  • —Account and administrative data, such as usernames, business account identifiers, role information, authentication events, and access or administrative logs where applicable;
  • —Communications data, such as emails, meeting invitations, meeting notes, support requests, chat messages, call records, and related correspondence;
  • —Commercial and relationship data, such as records relating to proposals, negotiations, orders, subscriptions, renewals, events, marketing interactions, and relationship-management activities;
  • —Billing and transaction data, such as invoice recipient details, billing address, tax or VAT identifiers, payment status, and related financial-administration data;
  • —Website, device, and usage data, such as IP address, browser type, device information, operating system, referring pages, pages viewed, session data, and cookie or similar technology identifiers;
  • —Security and compliance data, such as logs, alerts, risk indicators, fraud-prevention signals, sanctions or export-screening results where applicable, and records needed to protect Vendor, its systems, customers, and users; and
  • —Preference data, such as communication preferences, consent records, and lawful opt-out records.

Vendor does not seek to collect special categories of personal data through ordinary business interactions unless necessary and lawful.

3.Sources of personal data

Vendor may collect personal data:

  • —directly from you;
  • —from your employer or organization;
  • —from your use of Vendor websites, portals, or communications channels;
  • —from customers, partners, suppliers, or other counterparties with whom Vendor does business;
  • —from service providers acting on Vendor’s behalf;
  • —from publicly available business sources, professional networking platforms, or corporate directories; and
  • —from legal, compliance, fraud-prevention, or security sources where relevant.

4.Purposes of processing

Vendor may process personal data for the following purposes:

  • —to operate, administer, and secure Vendor websites, portals, and business systems;
  • —to create, manage, and administer business accounts, access rights, and related records;
  • —to communicate with prospects, customers, partners, and other business contacts;
  • —to respond to inquiries, requests, support communications, and other correspondence;
  • —to prepare proposals, negotiate contracts, manage orders, deliver business services, and administer commercial relationships;
  • —to manage billing, invoicing, collections, accounting, tax, and financial-administration processes;
  • —to send service notices, legal notices, administrative communications, and other relationship-related communications;
  • —to organize and administer events, webinars, meetings, and related activities;
  • —to improve Vendor’s websites, business operations, reliability, security, and performance;
  • —to detect, investigate, prevent, and respond to fraud, abuse, misuse, security incidents, and unlawful activity;
  • —to comply with legal, regulatory, tax, accounting, audit, reporting, and recordkeeping obligations;
  • —to establish, exercise, and defend legal rights and claims; and
  • —to send business-to-business marketing and promotional communications where lawful, subject to applicable opt-out rights.

5.Legal bases

Where GDPR or similar laws apply, Vendor may rely on one or more of the following legal bases, as applicable:

  • —performance of a contract or steps taken at your request before entering into a contract;
  • —legitimate interests, such as managing business relationships, operating and improving Vendor’s business, securing systems, preventing fraud, administering accounts, and communicating with business contacts;
  • —consent, where required by law, including for certain cookies, analytics, or marketing activities; and
  • —compliance with legal obligations, including accounting, tax, sanctions, regulatory, and recordkeeping requirements.

Where Vendor relies on legitimate interests, Vendor seeks to do so only where those interests are not overridden by applicable rights and interests of the individual.

6.Sharing and disclosures

Vendor may share personal data with:

  • —Vendor affiliates;
  • —service providers and processors acting on Vendor’s behalf, such as providers of hosting, analytics, communications, customer support tooling, CRM, billing, finance, security, or similar services;
  • —professional advisers, including legal, audit, tax, accounting, insurance, and compliance advisers;
  • —payment providers, financial institutions, or collection providers, where relevant;
  • —resellers, distributors, OEMs, implementation partners, or other business counterparties, where relevant to the business relationship and lawful;
  • —governmental, regulatory, judicial, law-enforcement, or supervisory authorities where required or appropriate under applicable law; and
  • —actual or prospective acquirers, investors, lenders, or other business transferees in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections.

Vendor does not disclose personal data to third parties except as described in this Notice, as otherwise permitted by law, or with appropriate notice or consent where required.

7.International transfers

Vendor may process personal data in the country where it was collected and in other countries where Vendor, its affiliates, or its service providers operate.

Where personal data is transferred across borders, Vendor will implement transfer mechanisms and safeguards required under applicable data protection laws, which may include adequacy-based mechanisms, contractual protections such as standard contractual clauses, and supplementary technical or organizational measures where appropriate.

Where Vendor processes personal data on behalf of a customer in connection with the Services, international transfers, region selections, and cloud selections for such processing are governed by the applicable Agreement and DPA, not this Notice.

8.Retention

Vendor retains personal data only for as long as necessary for the purposes described in this Notice, including relationship management, account administration, security, legal compliance, tax and accounting obligations, dispute resolution, and enforcement of rights.

Retention periods may vary depending on the nature of the data, the purpose of processing, the sensitivity of the information, applicable legal requirements, and whether the data is needed for security, fraud-prevention, audit, or evidentiary purposes.

Where Vendor processes personal data on behalf of a customer in connection with the Services, retention and deletion of such data are governed by the DPA, applicable service documentation, and the customer’s instructions, not this Notice.

9.Security

Vendor uses administrative, technical, and organizational measures appropriate to the nature of the data and the risks involved, including measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, and destruction.

No method of transmission, storage, or security control is completely secure, and Vendor cannot guarantee absolute security.

10.Your rights

Where applicable under data protection law, individuals may have rights to:

  • —access their personal data;
  • —request correction of inaccurate or incomplete personal data;
  • —request deletion of personal data;
  • —request restriction of processing;
  • —object to certain processing;
  • —request portability of personal data; and
  • —withdraw consent where processing is based on consent.

Individuals may also have the right to lodge a complaint with a competent supervisory authority.

Privacy requests may be submitted to the privacy email address listed above.

Where Vendor processes personal data as a processor or sub-processor on behalf of a customer in connection with the Services, rights requests relating to that data should generally be directed to the relevant customer, which acts as controller or is responsible to the relevant controller.

11.Marketing choices

Where permitted by law, Vendor may send business-related marketing or promotional communications. Recipients may opt out of such communications at any time using the unsubscribe mechanism provided in the communication or by contacting Vendor using the details above.

Even if you opt out of marketing messages, Vendor may still send service-related, legal, transactional, account, security, or other non-marketing communications where necessary.

12.Cookies and similar technologies

Vendor may use cookies and similar technologies for essential website operation, security, authentication, performance, analytics, preferences, and related business purposes.

Where required by law, Vendor will provide cookie notices, consent mechanisms, or choice controls. Additional details may be provided in a separate cookie notice or cookie settings tool made available through the relevant website or service.

12.1Company identification

We use Leadfeeder (Dealfront), acting on our behalf, to match visitors’ IP addresses against a business database to identify organizations visiting our website and the pages they view. We use this information to understand business interest in our services and support business-to-business sales and marketing. We do not seek to identify individual visitors or link visits to named individuals. IP addresses and related visit data may nevertheless constitute personal data.

We rely on our legitimate interests in understanding and developing business demand for our services (GDPR Article 6(1)(f)). Company identification may operate without cookies and independently of your cookie choices where applicable law permits; where consent is required, we obtain it first. You can object at any time by emailing privacy@modernpath.ai.

13.US state privacy disclosures

Where applicable US state privacy laws apply, Vendor will provide the rights and disclosures required by those laws and will honor verified rights requests subject to applicable exceptions and verification requirements.

Depending on the applicable law and the circumstances, individuals may have rights such as access, correction, deletion, portability, appeal, or the right to opt out of certain targeted advertising, profiling, or other regulated processing activities.

If Vendor engages in activities requiring additional state-specific disclosures, Vendor may provide a supplemental notice.

14.Third-party sites and services

Vendor websites or communications may link to third-party websites, applications, or services. Vendor is not responsible for the privacy practices of third parties, and individuals should review the privacy notices of those third parties separately.

15.Updates to this Notice

Vendor may update this Privacy Notice from time to time. The updated version will become effective when published or otherwise communicated. If required by law, Vendor will provide additional notice of material changes through appropriate channels.

16.Contact details

If you have questions about this Notice or Vendor’s processing of personal data as controller, please use the Vendor and privacy contact details set out in the details block at the beginning of this Notice.