Last updated 24 August 2026
Privacy Policy
How Supernomial Oy, as controller, handles personal data on supernomial.co, in our forms, events and business relations, and what applies when our agents run on your organization's own platform.
We run no cookies and no cross-site tracking on supernomial.co; our host measures visits for us without cookies, reporting only aggregates to us, and we collect what you type into our forms and what arises in ordinary business correspondence. Vercel, Supabase, Resend and Google Workspace run the site and our mail for us, some of it in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses; section 5 says how long we keep data. Our agents and TP Warehouse run on your organization's own platform and cloud and, as delivered, contain no Supernomial endpoint or telemetry; you can ask, correct, delete, object or complain at any time. This summary is for convenience; the numbered sections govern.
1. Who we are and what this policy covers
Supernomial Oy, Business ID 3542056-6, Bulevardi 21, 00180 Helsinki, Finland ("Supernomial", "we") is the controller of the personal data described in this policy. We are not required to appoint a data protection officer; our privacy contact is hello@supernomial.co.
This policy covers supernomial.co and its subdomains (including mail from welcome.supernomial.co and the customer portal once live); contact and demo requests, including the inline forms on our solutions pages; the newsletter; event and Academy sign-ups; business, customer and partner relations, including engagement administration; applications to work with us; our social channels; and, in section 9, users of Supernomial agents on their organization's platform.
It does not cover personal data your organization processes inside its own enterprise AI platform, cloud or TP Warehouse deployment: your organization's own privacy notices govern that data, and where our people access your environment our Data Processing Agreement governs our work (section 9).
2. What we collect, why, and on what legal basis
Most of the personal data we process comes from you; where we received it from someone else, we say so below and tell you at first contact. We do not profile you and make no decisions about you by automated means within the meaning of Article 22 GDPR. The legal bases below refer to Article 6(1) GDPR.
2.1 Visiting the site
Our hosting provider processes your IP address, user agent, the requested path and timestamps to serve pages and protect the site. Our form endpoints also run technical checks against automated submissions and record the timing of your submission. When you use the footer newsletter field, your browser sends the request to our database provider directly, so its servers see your IP address and user agent for that request. Our hosting provider also measures site usage for us through Vercel Web Analytics: page views and paths, referrers, and the visitor’s location at city level, operating system, browser and device class, reported to us only as aggregates. The measurement sets no cookies and stores nothing on your device; visits are counted under an identifier hashed from attributes your browser sends with every request, such as IP address and browser type, not kept in raw form. The hash resets daily, so visits are not followed across days or across sites. Legal basis: legitimate interest in operating, securing and understanding the use of the site (Article 6(1)(f)); the right to object in section 8 applies.
2.2 Contacting us or requesting a demo
The form on /contact/ and the inline forms on our solutions pages collect your first name, last name, business email, job title, country, phone number (optional), your enterprise AI platform, the solution you are interested in, your situation (optional free text) and whether you ticked the newsletter box. With the submission we record the page the form is on and the page you came from, the form variant, the timing of your submission and your browser's user agent, and we add a handling status as we work on it. The fields not marked optional are needed to answer you; without them the form does not send. Purpose: answering your request and pursuing the business relationship you asked about. Legal basis: legitimate interest in answering business inquiries and pursuing sales (Article 6(1)(f)); where you are the contracting party yourself, steps at your request before a contract (Article 6(1)(b)).
Please do not put client-confidential or sensitive personal data in free-text fields.
2.3 Newsletter
If you enter your email in the footer field or tick "Keep me up to date" on a form (the box is unticked by default), we record your email address, the page or form you signed up from and the time, and send you occasional updates from Supernomial. Legal basis: your consent (Article 6(1)(a)), which you can withdraw at any time through the unsubscribe link in every message or by email to hello@supernomial.co; after you unsubscribe we keep a suppression record so that we do not write to you again. Where Finnish law allows, we may also send existing customers information about similar services on the basis of our legitimate interest (Article 6(1)(f)), with an opt-out in every message.
2.4 Events and Academy sign-ups
When you reserve a seat at a workshop, presentation or program, we collect the event, your name, company, work email and message, to run the event and follow up afterwards. Legal basis: where you reserve the seat yourself, steps at your request before and under a contract (Article 6(1)(b)); where your employer registers you, our legitimate interest in running the event; in both cases our legitimate interest in following up (Article 6(1)(f)). Where an event is co-hosted, the co-hosts named on the event page receive the attendee list where the event page says so.
2.5 Business, customer and partner contacts
In ordinary business we process the name, employer, role and contact details of the people we deal with, notes on our conversations and, for customers and partners, the signatures, order, invoicing and engagement-administration data a contract needs. Sources: you, business cards, LinkedIn, introductions, meetings and public sources. Legal basis: legitimate interest in developing and maintaining business relations and in performing our contracts with the organizations you work for (Article 6(1)(f)); where you are the contracting party yourself, the contract (Article 6(1)(b)); for customers and partners, accounting and tax law (Article 6(1)(c)). We may write one-to-one to named people at organizations where what we offer is linked to their role; one email opts you out.
2.6 Portal sign-in
When the customer portal is live and you sign in with Google or Microsoft, we receive your name and email address from the identity provider, and your browser keeps a session marker for that tab (section 6). Legal basis: our legitimate interest in providing the portal to your organization under its contract with us (Article 6(1)(f)); where you are the contracting party yourself, the contract (Article 6(1)(b)).
2.7 Applying to work with us
If you send us an application, we process your CV, letter and our correspondence to assess it. Legal basis: steps at your request before a contract (Article 6(1)(b)) and legitimate interest in recruiting (Article 6(1)(f)). We keep an application for 2 years after the decision, to answer questions about the process and to defend claims; longer only with your consent.
2.8 Social channels
We run pages on LinkedIn, X and YouTube and a Discord community. Each platform is the controller of the data it processes when you interact with us there. We do not bulk-export profile data or messages; where we note a contact's details from LinkedIn for business follow-up, section 2.5 applies.
2.9 Legal obligations and claims
We process personal data where a law requires it (accounting, tax, responses to authorities) and to establish, exercise or defend legal claims (Article 6(1)(c) and (f)).
3. Who receives your data
| Recipient | Purpose | Location | Transfer basis |
|---|---|---|---|
| Vercel Inc. | Hosting, content delivery, the serverless functions behind our forms, hosting logs | United States; worldwide content network; our form functions run in the EU | EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) |
| Supabase Pte. Ltd | The database that stores contact requests and newsletter sign-ups; footer sign-ups reach it directly from your browser | European Union (Ireland) | SCCs |
| Resend (operated by Plus Five Five, Inc.) | Notification emails from welcome.supernomial.co when you send a form or reserve a seat; sending logs kept for 30 days | United States | DPF and SCCs |
| Google Workspace (Google) | Our company email and collaboration suite, where form notifications and correspondence land | Google Cloud EMEA Limited (Ireland); data stored in Google's data centers in the EU and the United States | EU-US Data Privacy Framework (Google LLC is certified) and SCCs in Google's data processing terms |
| GitHub, Inc. | Hosting of our source code, of the plugin repository your organization's platform fetches updates from, and of the public reference files some skills read at runtime; those logs (requesting address, client software, time, requested file, any account it requires) are GitHub's own processing under its privacy statement; no form data | United States | SCCs in GitHub's data protection agreement |
| Google LLC and Microsoft (Microsoft Corporation or Microsoft Ireland Operations Limited, depending on your account) | Identity providers for the customer portal sign-in once it is live; independent controllers for that step | United States (Google LLC, Microsoft Corporation); Ireland (Microsoft Ireland Operations Limited) | Their own notices apply to the sign-in step |
| Event co-hosts | The attendee list of a co-hosted event, where the event page says so | Named on the event page | Not applicable (the co-host is a controller for its own processing) |
| Accountants, lawyers, advisers, banks | Bookkeeping, tax, legal advice and payments | Finland and the EU | Not applicable |
| Authorities and courts | Where the law requires disclosure or a claim is pursued | As required | As required by law |
We do not sell personal data and we use no advertising networks. Internally, your data reaches the founders and the people who reply to you.
4. Where your data is processed and international transfers
The site is served from a worldwide content network, the functions behind our forms run in the EU, and the other locations are in the table in section 3. Transfers outside the EEA rely on the EU-US Data Privacy Framework where the recipient is certified and on the European Commission's Standard Contractual Clauses in all cases, with the UK and Swiss equivalents; we follow the court and regulator decisions on these mechanisms and will switch safeguards if needed. You can ask hello@supernomial.co for a copy of the safeguards that apply to a transfer.
5. How long we keep data
| Data | How long |
|---|---|
| Hosting and security logs | Kept by our hosting provider for a short period; we keep security investigation records for 12 months |
| Contact and demo requests | 24 months after the last substantive contact, then deleted or anonymized; if a request becomes an engagement, the record moves to customer records |
| Newsletter | Until you unsubscribe; then a suppression record |
| Event and Academy registrations | 12 months after the event |
| Business contacts | 24 months after the last meaningful contact |
| Customer, contract and accounting records | The contract term plus the limitation periods for claims; accounting material for the periods the Finnish Accounting Act sets (6 years for vouchers, 10 years for accounting records, counted from the end of the financial year) |
| Applications | 2 years after the decision; longer only with your consent |
| Legal claims and obligations | As long as the claim or obligation requires |
Provider backups cycle on the provider's schedule.
6. Cookies and browser storage
We do not use cookies or any technology that stores or reads information on your device; site usage measurement (section 2) works without either. When you sign in to the customer portal, your browser keeps a session marker for that tab only; it is deleted when the tab closes. The sign-in buttons load code from Google and Microsoft when you click them; their notices apply to that step.
If we ever add storage on your device, this section and the date at the top change first, and we ask for your consent where the law requires it.
7. Security
Access to the data described here is limited to the people who need it. Secret keys for our providers are kept server-side and never in the page; connections to our site are encrypted in transit. Encryption at rest, the transport between providers and the physical security of their systems are our providers' controls, described on their pages. Our controls are designed to meet the standards our clients are certified against: ISO 27001 internationally, SOC 2 in the United States. We have no certification and publish no audit report. For your review we answer your questionnaire, walk your security and data protection teams through each data path, and provide our policies under NDA. More on the Security Notice.
If a personal data breach occurs, we notify the Office of the Data Protection Ombudsman and the people affected where the law requires.
8. Your rights
You have the right to:
- access the personal data we process about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have your data erased where we no longer have a reason to keep it;
- have processing restricted while a question about it is resolved;
- receive the data you gave us in a common machine-readable format, where we process it by consent or contract;
- object to processing based on our legitimate interests, and object to direct marketing at any time; that objection is absolute and we honor it on one click or one email;
- withdraw consent at any time, without affecting the processing that took place before.
To exercise a right, write to hello@supernomial.co. We may ask you to confirm your identity. We answer within one month; for complex requests we may extend by two further months and tell you why.
You can also complain to the Office of the Data Protection Ombudsman, Lintulahdenkuja 4, 00530 Helsinki; P.O. Box 800, 00531 Helsinki, Finland; +358 29 566 6700; tietosuoja@om.fi; tietosuoja.fi, or to the supervisory authority of your own EU or EEA country. If you are in the UK or Switzerland, you have comparable rights under your own law.
9. Our services and your organization's data
Supernomial agents are instruction files (procedures, knowledge, guardrails, playbooks and workflows written as readable text) installed on the enterprise AI platform your organization contracts (Claude Cowork, Copilot Cowork, ChatGPT Work, Vibe Work or your in-house agentic AI) and run under your organization's platform agreement and governance. TP Warehouse runs as a dedicated deployment on a managed database platform and a cloud in your organization's own accounts, in the region it chooses. As delivered, our agents and TP Warehouse contain no Supernomial endpoint, account, API key, license check or telemetry, and no Supernomial sub-processor joins your organization's vendor list in product operation. Where your organization's platform fetches the plugin or its updates from a marketplace or repository we publish, or a skill reads public reference files (country profiles, industry benchmarks) from a repository we publish, the hosting provider logs that fetch or read under its own privacy statement (requesting address, client software, time, requested file and any account it requires); each is one-directional and carries none of your content. Your organization's AI platform vendor and cloud provider process its data under its own agreements with them; their trust centers are linked below.
During an engagement our people work inside your environment with identities you issue, for the time you set, under your terms. We keep no standing access and no credentials, and no copies of your organization's data outside its environment beyond engagement correspondence and the working notes and deliverable drafts an engagement needs, which we delete within 30 days of its end under the Data Processing Agreement. Where our people access your environment or receive personal data during implementation, support, workshops or the AI Deployment Program, we act as your organization's processor under our Data Processing Agreement. Your organization's own privacy notice applies to its users, and we help it answer their questions.
More: Data & Security, the Security Notice, and the platform trust centers of Anthropic, Microsoft, OpenAI and Mistral AI.
10. Children
Our website and services are for professionals and organizations and are not directed at anyone under 18. We do not knowingly collect children's data; if you believe we have, write to hello@supernomial.co and we will delete it.
11. Changes to this policy
This is version 1.0 of this policy. When we change it, we post the new version here with a new date at the top. For material changes we notify subscribers and customers by email where we have an address. Earlier versions are available on request at hello@supernomial.co.
12. Contact
Supernomial Oy, Business ID 3542056-6, Bulevardi 21, 00180 Helsinki, Finland. Privacy and data protection, security reports, general and legal notices: hello@supernomial.co.