Privacy Policy

Last updated: 2026-07-21

  1. Controller

    Nordhash Oy (Business ID: 3535584-8), Finland. Contact: nordhashoy@gmail.com. The Company is the data controller for personal data collected in connection with the Service.

  2. Contact for Data Protection

    Data protection and privacy related questions may be sent to nordhashoy@gmail.com. Customers may also contact the Finnish Data Protection Ombudsman for guidance (tietosuoja@om.fi).

  3. Purpose of Processing

    We process personal data to provide the rental service (including payment, allocation, hosting, monitoring and customer support), to comply with legal obligations (e.g., accounting), and to protect our legitimate business interests (e.g., fraud prevention, service security).

  4. Legal Basis

    Processing is based on contract performance (Art. 6(1)(b) GDPR), legal obligations (Art. 6(1)(c)), legitimate interests (Art. 6(1)(f)) and, where applicable, consent (Art. 6(1)(a)). For marketing or profiling, we rely on explicit consent where required.

  5. Categories of Personal Data

    Categories of data processed include:

    • Identification and contact data: name, email, billing address (if provided)
    • Order and payment data: order identifiers, payment confirmations (provided by payment processors)
    • Configuration data: mining pool, worker name, wallet address (provided by Customer)
    • Technical and operational data: service logs, uptime, IP addresses, device identifiers necessary to provide the Service
    • Support communications and correspondence
  6. Sources of Data

    Data is provided directly by Customers through forms, emails, or via payment processors and support interactions.

  7. Recipients and Data Processors

    We share personal data with third-party processors where necessary to provide the Service. Key processors include:

    • Web3Forms — form submission processing;
    • SumUp (or the configured payment provider) — payment processing;
    • GitHub Pages — hosting the public website (static content).

    We enter into data processing agreements with processors where required by GDPR. Processors act only on our instructions and apply appropriate safeguards.

  8. International Transfers

    Personal data may be transferred to processors or recipients outside the EU/EEA. Where transfers occur, we rely on adequacy decisions, standard contractual clauses, or appropriate safeguards in accordance with applicable law. If you would like further details, contact us at the address above.

  9. Retention Periods

    We retain personal data only as long as necessary to provide the Service, to comply with legal obligations (for example, accounting and tax record retention under Finnish law), to resolve disputes, and to enforce our agreements. Typical retention periods vary by data type; transactional and accounting data may be retained for the statutory period required by law (for example for tax purposes), while support correspondence may be retained for a shorter period.

  10. Security Measures

    We implement technical and organizational measures appropriate to the risk, including access controls, encrypted communications, and restricted access to data. However, no system is completely secure and absolute security cannot be guaranteed.

  11. Data Subject Rights

    Under the GDPR, you have rights including:

    • Access: request a copy of personal data we hold about you;
    • Rectification: request correction of inaccurate or incomplete data;
    • Erasure: request deletion of personal data where lawful (subject to legal retention obligations);
    • Restriction: request restriction of processing in certain circumstances;
    • Objection: object to processing based on legitimate interests or direct marketing;
    • Portability: request data in a commonly used, machine-readable format where processing is based on consent or contract and is carried out by automated means.

    To exercise your rights, contact nordhashoy@gmail.com. You may lodge a complaint with the Finnish Data Protection Ombudsman if you consider your rights under GDPR to be infringed.

  12. Profiling and Automated Decision-Making

    We do not carry out automated decision-making that produces legal effects concerning individuals. Where profiling is used for legitimate purposes (for example security), we will inform you if it significantly affects you and explain applicable rights.

  13. Changes to this Policy

    We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post updates on the website with a revised effective date.

  14. Contact

    Nordhash Oy — Business ID: 3535584-8 — Email: nordhashoy@gmail.com. For data protection queries, you may also contact the Finnish Data Protection Ombudsman.