Hapax · Data

How we handle data.

This page covers what the site collects, what happens to an email you send us, and how client material is treated during an engagement. The written policies sit behind this summary and we send them to anyone who asks.

iThis website

The site is static HTML. It sets no cookies and loads no analytics script, no tag manager, no advertising pixel and no embedded third-party widget, so there is no cookie banner, because there is nothing to consent to. There is no account to create and no form to fill in. Email is the only way to reach us.

The pages are served by a commercial hosting provider whose servers keep the ordinary access logs any web server keeps, covering the IP address, the time and the page requested, for security and for running the service. Those logs are held on the provider’s standard rotation and are not used to identify visitors or to build a profile of anyone. Nothing else about your visit is recorded.

iiIf you write to us

Your message arrives in a mailbox on our business Google Workspace account, under that vendor’s data-processing terms, and we use what you send in order to reply. Enquiries are kept for up to twenty-four months, or for as long as a client relationship lasts if one forms, and are then deleted.

You can ask what we hold about you and have it corrected or deleted. Write to enquiries@hapax.fi and we answer within a month. If our answer does not satisfy you, the Finnish Data Protection Ombudsman takes complaints at tietosuoja.fi.

iiiIf we wrote to you first

If you heard from us without contacting us, we hold your name, role, employer and work contact details, together with a note on why the role looked relevant. All of it came from public professional sources such as an employer’s website, press releases, business registries and LinkedIn. We hold no private contact details and we buy no marketing lists. The legal basis is legitimate interest, and the balancing assessment behind it is written down; ask and we will send you a summary.

One reply asking us to stop ends it, permanently and without our asking why. Records with no engagement behind them are deleted at twenty-four months in any case.

ivClient material

Anything a client shares that is not already public is confidential by default, including strategy, financials, internal documents and what gets said in a workshop room. It lives in Hapax’s business accounts rather than on personal accounts or personal devices, and the two founders are the only people who see it, as far as the engagement requires.

We use AI tools in our own work, and our contracts say so. Client personal data goes into such a tool only where there is a signed processing agreement with that vendor covering that use; confidential client information only where the engagement contract permits it. The working default is to anonymise, aggregate, or build a synthetic stand-in and work on that instead.

A client’s name, logo or story appears in anything we publish only with written permission. At the end of an engagement, or whenever you ask, client material is returned or deleted, apart from the invoices and contracts that Finnish bookkeeping law requires us to keep. If material is ever exposed by accident we tell you, and where personal data is involved the Data Protection Ombudsman is notified inside the seventy-two hours the regulation allows.

vThe case studies

The case studies we publish run on data we generate ourselves. Each dataset is engineered so that the right answer is known in advance and held out of the analysis, which is what lets us mark our own results honestly. Where a study uses real documents they come from a public, openly licensed dataset. No client data appears in any of them, and none of them needs a client’s permission to exist.

viThe policies

Behind this page are the documents it summarises: the confidentiality and client-data policy, the AI-use and AI-literacy policy, the retention and data-rights procedure, and the record of processing activities kept under Article 30 of the GDPR. If a procurement or security team wants to read them before an engagement, write to enquiries@hapax.fi and we will send them. Hapax holds no security certifications.

Reviewed · September 2026