Privacy notice
How The Better One Oy processes personal data on the www.bidi.fi website and in enquiries: what is collected, on what basis it is processed, how long it is kept and what rights you have.
Updated 10 September 2026
The Finnish version prevails in case of any discrepancy between the two language versions.
1. Controller and contact details
The controller of the personal data is The Better One Oy, which is responsible for the processing described in this notice. BIDI is the company's tendering platform for public procurement.
- The Better One Oy, business ID 3597598-3, Finland
- Address: Itätuulenkuja 10 A, LT 1, 02100 Espoo, Finland
- Website: www.bidi.fi
- Enquiries: myynti@bidi.fi
- Privacy matters: tietosuoja@bidi.fi
Iina Kajander is responsible for data protection matters as the company's internal responsible person, tietosuoja@bidi.fi. We have not appointed a data protection officer under Article 37 of the GDPR.
2. What this notice covers
This notice covers personal data we process for our own purposes as a controller: use of the website, enquiries and demo requests, and customer and marketing communication.
3. What personal data we process and where it comes from
Most of the data we process is data you give us yourself.
- What you enter in the contact form: name, email address, organisation, role and the content of your message. The site's language choice is sent with it so that we reply in the right language. Name and email are required; the other fields are optional.
- What you tell us by email, by phone or in meetings, such as contact details and the content of the discussion.
- Technical data generated by use of the site in our service providers' logs: IP address, timestamp, requested address, response code and browser identifiers.
We do not collect special categories of personal data and do not ask for them on the form.
4. Purposes and legal bases for processing
We process personal data only for the following purposes and on the following bases under the EU General Data Protection Regulation (2016/679).
| Purpose | Data | Legal basis |
|---|---|---|
| Replying to enquiries and arranging a demo | Name, email, organisation, role, message content, language choice | Steps prior to entering into a contract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)): replying to an enquiry you initiated |
| Managing the customer relationship and communicating about it | Contact details, organisation, role, contact history | Contract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)) |
| Marketing to organisations | Contact details, organisation, role | Legitimate interest (Art. 6(1)(f)). Electronic direct marketing to organisations is based on section 200 of the Finnish Act on Electronic Communications Services (917/2014) and can be opted out of at any time |
| Running the site, security and abuse prevention | IP address, technical log data | Legitimate interest (Art. 6(1)(f)): keeping the service available and secure |
| Site usage statistics | Address of the page opened, referring site, browser type and country. The data is aggregate and forms no per-visitor identifier | Legitimate interest (Art. 6(1)(f)): establishing which pages are useful to the people reading them |
Where processing rests on legitimate interest, we have assessed that it does not override the interests or rights of the data subject: it is limited to contact details given in a professional capacity and concerns communication the recipient can reasonably expect. You can object to such processing as described in section 12.
5. Cookies and tracking
The site uses one cookie. Your language choice is stored in a cookie named lang so that the site opens in the language you picked. The cookie lasts 12 months, contains no identifiers and is not combined with any other data.
Visitor numbers are measured with Plausible Analytics. It sets no cookies and reads nothing from your device, it gives a visitor no identifier, and it does not recognise the same visitor between visits or between sites. It produces aggregate counts only: how often a page was opened, which site a link was followed from, which browser and which country. Your IP address is not stored, and the data is processed and stored in the EU.
- The site has no advertising tracking and no social media tracking pixels. The measurement is not used for profiling or for targeted marketing.
- The site loads no fonts, scripts or images from third-party servers: the measurement is part of the site's own code. Your browser sends the measurement event to Plausible's API at plausible.io, and no other connection to an outside service is made.
- The LinkedIn link leads to an external site. Once you follow it, LinkedIn's own privacy policy applies.
Because the only cookie in use is strictly necessary for the service to work, and the measurement neither stores anything on your device nor reads anything from it, the site does not ask for cookie consent.
6. What happens to a contact form submission
What you submit is stored in one place: our enquiry list, which we maintain in our own Microsoft 365 environment as a SharePoint list. It holds what you enter on the form — name, email address, organisation, role and message — together with the form's language and the time the enquiry arrived. The contents are not sent by email and are not stored anywhere else.
The people responsible for sales are notified of a new enquiry on an internal Teams channel and by email to the sales address. Each notification carries the arrival time and a link to the list, not the contents of the enquiry.
The contact form is protected against automated spam in three ways: a hidden field only a bot fills in, a check on how long the form took to complete, and a limit on how many submissions come from one address. If a submission trips the first of these we still receive it, marked for checking rather than discarded, so that a mistaken match cannot lose your message.
For that limit the server reads the sender's IP address. The address stays in the server process's memory for at most an hour, is never written to a log, is not stored with the enquiry, and is not disclosed to anyone.
If storing it fails, the error log records the type of the error, never the contents of the form.
We operate no logging service for the handling of the form. Collecting the function's log output would require a separate Application Insights resource, and none is in use; nor is the platform's own log data routed to any log store. The log output is therefore neither collected nor retained by us.
Microsoft retains operational data about the Azure Static Web Apps platform itself, such as service availability, request volumes and platform health, under its own terms. That data does not contain what you enter on the form.
7. Who the data is disclosed to
We do not sell or rent personal data. The only parties processing it on our behalf are the service providers we need to run the site, our email and our customer work. There is a data processing agreement with each of them.
- Microsoft: the technical platform for the website and the contact form (Azure Static Web Apps and Azure Front Door) and the transfer of form data into the list (Azure Logic Apps).
- Microsoft 365: storage of enquiries in a SharePoint list, the notification to a Teams channel, and the email (Exchange Online) we reply from.
- Plausible Insights OÜ: measurement of visitor numbers for the site. The data is processed on a server located in the EU, and nothing by which you could be identified reaches the service.
We may also disclose data to authorities where the law requires it.
8. Where the data sits and transfers outside the EU and EEA
The website and the contact form run on Microsoft Azure, in the West Europe region. Enquiries are stored in a SharePoint list in our own Microsoft 365 environment, and we reply from email in that same environment.
The aggregate data from visitor measurement is processed and stored in the EU.
We do not transfer personal data outside the EU and EEA without a transfer mechanism under Chapter V of the GDPR.
9. Retention periods
We keep personal data only for as long as it is needed for the purpose it was collected for.
| Data | Retention period |
|---|---|
| Enquiries and demo requests in the list, and the email correspondence about them | Until further notice |
| Customer relationship data | Until further notice |
| Marketing opt-outs | Indefinitely, so that the opt-out stays in force |
| Technical log data | The service provider's default period |
Data kept until further notice is deleted once there is no longer a basis for keeping it, or when you ask us to delete it as described in section 12.
10. Security
We protect personal data with technical and organisational measures.
- Traffic to the site and the form submission are encrypted (TLS).
- Access to the data is limited to the roles that need it for their work and is based on personal credentials.
- We collect only what replying to an enquiry requires, and we store enquiries nowhere beyond the list.
- Access to the list is limited to the people responsible for sales and enquiries and is based on our own organisation's user accounts.
In the event of a personal data breach, we notify the Office of the Data Protection Ombudsman within 72 hours, and we notify you if the breach is likely to result in a high risk to your rights.
11. Automated decision-making and profiling
We carry out no automated decision-making and no profiling with the data described in this notice that would have legal or similarly significant effects on you.
Nor does AI make decisions in the BIDI service. It drafts suggestions and the reasoning behind them, and a procurement professional accepts or rejects them.
12. Your rights
You have the rights the GDPR gives you over your own personal data.
- To know whether we process your data and to obtain a copy of it (Article 15).
- To have inaccurate or incomplete data corrected (Article 16).
- To have data erased where there is no longer a basis for processing it (Article 17).
- To ask for processing to be restricted (Article 18).
- To receive the data you have given us in a machine-readable format and transfer it to another controller, where processing is based on consent or a contract (Article 20).
- To object to processing based on legitimate interest (Article 21). You can opt out of direct marketing at any time and do not have to give a reason.
- To withdraw a consent you have given at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
Requests can be made by email to tietosuoja@bidi.fi. We may ask you to clarify the request or verify your identity before we act on it. We reply within one month; if the request is unusually extensive, we may extend that by up to two months and will tell you if we do.
If you consider that we process your data unlawfully, you can lodge a complaint with the Office of the Data Protection Ombudsman: PO Box 800, FI-00531 Helsinki, phone +358 29 566 6700, tietosuoja@om.fi. We would rather you came to us first.
13. Changes to this notice
We update this notice when the service, the processing or the service providers we use change. The current version is always on this page, and the date of the last update appears at the top. We will say so separately if a change is material.