Fidelix Privacy Notice

Privacy Notice

Updated 8 September 2026

1. Who collects your personal data

The companies belonging to the Assemblin Caverion Group AB group (“Companies” or “we”) are committed to protecting your personal data, and our goal is to make you feel safe when we process your personal data. We protect your privacy in accordance with the EU General Data Protection Regulation and all other applicable laws.

We ask you to read this privacy notice carefully.

This privacy notice applies to the following group companies:

  • Fidelix Oy (Business ID 1770269-0), Myllynkivenkuja 1, 01620 Vantaa, Finland.
  • Fidelix Tech Oy (Business ID 3329591-7), Myllynkivenkuja 1, 01620 Vantaa, Finland.
  • Fidelix Sverige AB (Business ID 556567-5716), Skogsborgsvägen 16, 647 31 Mariefred, Sweden.
  • Fidelix France SAS (Business ID 839 582 335), 69 boulevard Haussmann, 75008 Paris, France.
  • Larmia Control AB (Business ID 556139-3132), Finlandsgatan 38, 164 74 Kista, Sweden.
  • Lansen Systems AB (Business ID 556901-4011), Rörkullsvägen 7, S-30241 Halmstad, Sweden.
  • Säätölaitehuolto Oy (Business ID 2041453-4), Rälssintie 4 A, 00720 Helsinki, Finland.

(hereinafter jointly the “Companies” or “we”)

The Companies process customer and marketing data in a shared customer relationship management system (HubSpot) and, with respect to this processing, act as joint controllers under Article 26 of the General Data Protection Regulation. The Companies have agreed among themselves on the allocation of responsibilities, including how requests concerning data subjects’ rights are responded to. Although the Companies use the same HubSpot system, each Company’s contacts and marketing communications remain under its own control: each Company communicates only with its own customers and contacts. You can exercise the rights described in this notice by contacting the data protection contact person listed below, regardless of which Company you have dealt with.

Data protection contact person

Name: Timo Pellinen

Address: Myllynkivenkuja 1, 01620 Vantaa

Email: privacy@fidelix.com

2. Protecting personal data

We take the protection and security of your personal data seriously. All personal data you provide to the Companies is stored on secure servers, and access to this data is limited to employees and third parties who need it to perform their duties. Persons who have access to personal data must keep such data confidential. The Companies and our service providers take all reasonable measures to ensure that your personal data is protected.

We use appropriate technical, administrative, and organizational security measures to protect personal data against unauthorized access, disclosure, destruction, or other unauthorized processing. The servers are located in the EU or comply with the requirements of the General Data Protection Regulation based on agreements made with the server administrator. Online services are protected by an HTTPS connection that encrypts communications.

3. Data we collect and the purposes of collecting personal data

We only collect personal data that is relevant to the purposes described in this privacy notice. We collect data that (a) you provide to us yourself, but also (b) data collected automatically, or (c) obtained from other external sources. We describe in this notice how we process the personal data of data subjects. Please note that we may combine the data we receive from you, data collected online, data collected offline, and data collected from third-party sources in accordance with applicable laws and regulations on the processing of personal data.

We use your personal data only for the purposes stated in this privacy notice, unless we obtain your consent for other purposes.

3.1 Website users

Our website serves several Companies and is available in several languages. In connection with the contact form or another feature, you will be informed which Company you are dealing with.

When you browse our website, we may collect the following information about you:

  • Demographic data (e.g. country, language)
  • Email tracking (e.g. opened messages, clicks, the date and time of your actions)
  • IP address
  • Website visits (e.g. pages visited, cookies, browser information, the date and time of your visit, user behavior)
  • Additional information you provide when filling in forms (e.g. to download guides) on our website

Purposes and legal bases for data collection:

Some of the processing is necessary for the operation of the website and is based on our legitimate interest in maintaining and optimizing the functionality and user experience of our website.

Processing related to marketing — such as advertising displayed on third-party websites, behavior-based targeting, and marketing cookies used by our partners — is based on the consent you give in the cookie settings. You can manage and withdraw your consent at any time in our cookie notice.

Cookie notice: Cookie notice

The data collected is limited and does not include sensitive personal data.

3.2 Customers

If we have entered into an agreement with you or the company you represent, we typically collect the following information:

  • Basic information such as name, customer number, username, and/or other unique identifier, as well as language of communication
  • Contact information such as email address, phone number, address details
  • Information concerning the company and its contact persons, such as names, titles, and contact details
  • Information related to contracts, assignments, and offers, billing information, and communication-related information
  • Information collected in connection with events and training, such as registration details and special dietary requirements
  • Information related to the technical connection and device, such as IP address, device ID, cookies

Purpose and basis of processing:

Processing is based on the performance of the customer agreement (Article 6(1)(b) of the General Data Protection Regulation): delivering our services, managing and maintaining the customer relationship, and fulfilling our contractual obligations. All of the above data is stored in our shared customer relationship management system (HubSpot).

3.3 Prospective customers and their contact persons

If you are a prospective customer of ours, or represent such a company, we typically collect the following information:

  • Contact information such as name, email address, phone number
  • Information concerning the company, such as company name, titles of contact persons
  • Information provided via the contact form, which is stored in our customer relationship management system (HubSpot)
  • Offers provided and related communications
  • Publicly available social media information
  • Registration information related to events and training, and any special dietary requirements

Purpose and basis of processing:

Processing is based on our legitimate interest (Article 6(1)(f) of the General Data Protection Regulation) in marketing our services and developing our business. We process data to respond to inquiries, provide offers, and develop our business. Most of our contacts are part of a customer or partnership relationship, and we retain data for as long as the relationship is in effect and thereafter for the applicable statutory retention period (e.g. the Accounting Act). We maintain several automated cleanup processes in HubSpot that delete or anonymize data when it is no longer needed. Exception: if you have provided us with a personal email address (e.g. a Gmail, Outlook, or other similar private address), for example by filling in a form on our website, and you are not in a B2B customer relationship with us, we will delete this data no later than one (1) year after the form was submitted. You have the right to object to this processing, see section 5.1.

Some of the processing is based on your consent: this concerns electronic direct marketing, such as newsletters, customer satisfaction surveys, and invitations to events and training. You can withdraw your consent at any time, see section 5.4.

We use Google Ads to target our advertising and measure its effectiveness. For this purpose, we may share a limited amount of information (e.g. a hashed email address) with Google Ads for conversion tracking. This processing is based on the consent you give in the cookie settings. In the advertising of some of our companies, we use the Enhanced Conversions for Leads feature of Google Ads to target our advertising and measure its effectiveness. For this purpose, we send Google your contact information, such as your email address and/or phone number, in hashed form, so that an ad click can be linked to the subsequent progress of the lead in our customer relationship management system. This processing is based on the consent you give in the cookie settings. In this connection, data is transferred to the United States to Google LLC; the transfer is based on Google LLC being certified under the EU-U.S. Data Privacy Framework (DPF). This means that Google complies with EU data protection requirements under the law when transferring data to the United States. In situations where the DPF is not used as the sole basis, Google includes standard contractual clauses (SCCs) in its Customer Data Terms to serve as a legal safeguard. More information on Google’s own data processing.

3.4 Users of the Fidelix cloud service

When you log in to and use our cloud service, we typically collect the following information:

  • Basic information such as name, username and/or other unique identifier, password and language of communication, employer information (if visible in the email address), and information about the housing company or property management company for which the data subject has been registered as a contact person
  • Information related to the technical connection and device, such as IP address, device ID or other identifying information, and cookies
  • User log data in the cloud service, such as login times, actions taken by the user, and acceptance of the terms of use and personal data collection

Purpose and basis of processing:

The delivery, provision, and development of the service, as well as the fulfilment of our contractual obligations, are based on the performance of the contract in the case of the customer, and on legitimate interest in the case of persons bound by the customer’s obligations. Ensuring the continuity of the services and information security is based on our legitimate interest. Electronic direct marketing, such as surveys, is based on separately given consent.

3.5 Persons visiting offices and worksites

The Companies may collect personal data on persons visiting offices or worksites (e.g. access control, visitor lists, video surveillance).

If data is collected, typical categories of data are: visit information (e.g. time of visit, host), contact information, employer information, and access control and video surveillance data. The basis for processing would in this case be legitimate interest: the Companies have an interest in ensuring the safety of their premises and the persons working or visiting there.

3.6 Users of the support request system and installation contact persons

When you contact us regarding a product or application support matter, or when you are designated as a contact person in connection with a product or system we have installed, we typically collect the following information:

  • Company name
  • Job title
  • Phone number
  • Email address
  • Billing address
  • Location information of the installation site

This data is processed in our support request systems (HubSpot, Matrix42) and, with respect to customer and supplier contact information, in our SAP system. Data is stored within the EU.

Purpose and basis of processing:

The purpose of processing is to provide product and application support and maintenance services: receiving, resolving, and tracking support requests, maintaining installed products and systems, and related billing. Processing necessary to fulfil the maintenance or support agreement made with your company (e.g. billing address, information on the installation site, services covered by the agreement) is based on the performance of the contract. The processing of your personal contact information as the contact person for a support request is based on our legitimate interest in ensuring that we can provide your company with the support and maintenance agreed under the contract.

We retain this data for as long as the product or system is installed and covered by support, and thereafter for the retention period required by law (e.g. within product liability and defect liability periods). This corresponds to the actual need for processing, as the service life of installed systems can be long.

4. Disclosure and transfer of personal data

Our Companies transfer personal data only to persons and companies that need it to perform their duties. We ensure that the parties to whom we transfer personal data are properly informed of the purpose of the processing, and we ensure the lawful processing of personal data through contractual arrangements. We also ensure that recipients of personal data commit to complying with restrictions on the use of personal data, including the confidentiality of personal data.

If personal data is transferred outside the EU/EEA, such transfers are either made to a country that the European Commission considers to provide an adequate level of data protection, or the transfers are carried out using appropriate safeguards, such as the European Commission’s standard contractual clauses, and by identifying the need for any additional measures.

4.1 Group companies

Thanks to our shared IT infrastructure and the sharing of information within the group, the Companies may use your personal data for the purposes listed in this privacy notice to the extent that they act as joint controllers (see section 1).

4.2 Suppliers and subcontractors

We use external service providers for certain parts of our business. These include, among others:

  • HubSpot – a customer relationship management (CRM) system used jointly by all Companies for managing customers and leads. Data is located in the EU. HubSpot DPA.
  • Matrix42 (formerly Effecte) – a support request system used to manage product and application support and service requests. Matrix42’s data protection terms.
  • SAP – a system for managing customer and supplier information, including contact persons.
  • Service providers related to the maintenance of IT systems

These service providers act as processors of personal data, and processing agreements in accordance with the General Data Protection Regulation have been concluded with them.

4.3 Third parties

We share data with other partners or stakeholders when this is necessary for our business. We also use cookies and web trackers on our website, and we share data with the third parties that collect it, such as:

  • Google Ads – for advertising conversion tracking and optimization
  • Social media platforms

When third parties are used, we ensure that they comply with our data protection guidelines.

Cookie notice

5. Your rights

As a data subject, you have certain rights relating to your personal data, as described below.

5.1 Right to access, rectify, and object

You may contact us and request that we inform you what personal data we have collected and processed about you and for what purposes it is used. You also have the right to request that we correct inaccurate or incomplete personal data recorded about you.

You also have the right to object to the processing of your personal data when the processing is based on our legitimate interest — this applies in particular to the marketing and business development described in sections 3.1 and 3.3. The right to object does not apply to processing based on the performance of a contract or compliance with a statutory obligation.

5.2 Right to erasure and restriction of processing

You may also request that we delete your personal data from our systems. We will comply with such a request unless we have a lawful reason not to delete the data. After the data has been deleted, we may not be able to immediately remove all remaining copies from our active servers and backup systems. Such copies will be deleted as soon as reasonably possible. Please note that your request to restrict the processing of your personal data may reduce your ability to use our website and other services.

5.3 Right to data portability

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, when the data is processed automatically and the processing is based on your consent, or on the performance of a contract or steps taken prior to entering into a contract.

We will respond to all requests referred to in sections 5.1–5.3 no later than one month after receiving the request.

You may exercise these rights (5.1–5.3) by sending a request by email to privacy@fidelix.com. We may refuse requests that are unreasonably repetitive, excessive, or manifestly unfounded, or where applicable law does not require us to comply with the request.

5.4 Consent

If the personal data you have provided to us is based on your consent, you have the right to withdraw your consent at any time. You can withdraw your consent to digital marketing via the link in the communication you receive, or by email to privacy@fidelix.com.

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. Withdrawal also does not affect processing based on another legal basis, such as contract or legitimate interest — for example, the provision of contract-based services continues as normal even if you withdraw a separate marketing consent.

5.5 Complaints

If you are not satisfied with a Company’s decision or actions, you always have the right to lodge a complaint with your local data protection authority.

6. Cookies

We use cookies on our website. See the cookie notice and your current choices:

Cookie notice: https://www.fidelix.com/cookie-notice/

7. Retention of personal data

We have the right to retain your personal data for as long as necessary for a lawful purpose or as long as required by law. The criteria used to determine the retention period for personal data are the applicable statutory retention period and the lawful purpose of the processing. The data and the length of the retention period vary depending on the data in question and the applicable legislation. We delete and/or anonymize your personal data when it is no longer relevant to the purposes for which we process it. The retention periods by user group are stated below.

  • Data of website users (section 3.1) is retained for the period stated in the cookie notice
  • Customers (3.2): Data is retained for the duration of the customer agreement or right of use, and thereafter for the retention period required by legislation.
  • Prospective customers and their contact persons (3.3): We maintain several automated cleanup processes in HubSpot that delete or anonymize data when it is no longer needed. Exception: if you have provided us with a personal email address (e.g. a Gmail, Outlook, or other similar private address), for example by filling in a form on our website, and you are not in a B2B customer relationship with us, we will delete this data no later than one (1) year after the form was submitted.
  • Data on representatives of sellers of products and services is retained for the duration of the assignment or contractual relationship and thereafter for the retention period required by legislation.
  • Users of the Fidelix cloud service (3.4): data is retained for the duration of the right of use
  • Persons visiting offices and worksites (3.5, where applicable): data is retained for a maximum of 3 years from the visit.
  • Users of the support request system and installation contact persons (3.6): data is retained for as long as the product or system is installed and covered by support, and thereafter for the retention period required by legislation.
  • Recorded material collected via property security systems (e.g. access control, video surveillance) is retained for a separate, significantly shorter retention period than general visitor contact details, typically 30 days.
8. Changes to the privacy notice

We reserve the right to review, modify, and update this privacy notice from time to time. If we make such changes, we will record the change or the date of the change in this privacy notice. Please read this privacy notice regularly, and especially before sending us personal data. We will not notify our users of every update, but if there are significant changes to the privacy notice or the use of your data, we will endeavor to inform you accordingly.