Privacy policy.
This statement describes what personal data SunBit Oy collects, for what purposes it is used and what rights the data subject has. The processing of personal data complies with the EU General Data Protection Regulation (GDPR).
Last updated 10 August 2026
1. Data controller
SunBit Oy, Business ID 3357067-5
Sinikalliontie 4, 02630 Espoo, Finland
Contact person: Elmeri Suomi, elmeri.suomi@sunbit.fi, +358 44 329 4406
2. Personal data collected
Enquiries and quote requests. When a data subject submits a quote request or contact form on the website, the following are collected: name, email address, phone number, street address and city, company name where given, and information about the property, namely the current heating type, floor area, annual energy consumption, whether solar panels are installed, and the contents of the free text field. The language used is also recorded, together with information on the page and marketing channel the visitor arrived from where available.
Newsletter. For newsletter subscribers, the email address and the date of subscription are stored.
Booking. When a site assessment is booked, the booking service records the name, email address and the selected time.
Website use. Information on how the website is used is collected: pages visited, device and browser information, approximate location based on the IP address, and advertising and analytics identifiers. This data is collected only to the extent the visitor has given consent in the cookie banner.
Installed systems. Once a system has been installed at a property, it transmits operational data to the controller: energy consumption, temperatures and device status. The system uses SunBit's own network connection and is not connected to the customer's home network. It cannot see other devices at the property or its network traffic. Technical log data is stored for maintenance purposes.
Customer relationship. During the customer relationship, contract, delivery, invoicing and maintenance data is processed, as well as correspondence with the customer.
3. Sources of data
Data is obtained primarily from the data subject: web forms, email, telephone, meetings and contracts. Some data is generated automatically through use of the website or by the installed system.
Where contact details are submitted through a lead form displayed in a Facebook or Instagram advertisement, the data is first collected by Meta and transferred from there to the controller's customer relationship management system. Meta's own privacy policy also applies in such cases.
The contact details of business representatives may be supplemented from public sources, such as company websites or the trade register.
4. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Responding to quote requests and enquiries | Legitimate interest or steps prior to a contract |
| Preparing quotes and sales work | Legitimate interest |
| Fulfilling the contract, delivery, installation and maintenance | Contract |
| Monitoring system operation, detecting faults and calculating yield | Contract |
| Sending the newsletter | Consent |
| Ad targeting and measurement | Consent |
| Analysing and developing use of the website | Consent |
| Accounting and statutory obligations | Legal obligation |
Legitimate interest here means that, following an enquiry, the controller has a justified need to process the data subject's information in order to serve them.
5. Cookies and tracking
Cookies are used on the website. Necessary cookies keep the site functional and do not require consent. Analytics and marketing cookies are activated only once the visitor accepts them in the cookie banner.
The following are in use:
- Google Analytics and Google Tag Manager - measurement of website use
- Google Ads - ad targeting and conversion measurement
- Meta Pixel and Meta Conversions API - ad targeting and measurement.
If cookies are not accepted, the website sends Google an anonymous signal of the visit without cookies or identifiers. The visitor cannot in that case be linked to earlier visits.
Decisions concerning the data subject are not made automatically without human involvement. Advertising is targeted by means of cookies where consent has been given.
The consent selection can be changed at any time via the Cookie settings link in the site footer.
6. Recipients of data
Personal data is not sold. The controller uses trusted service providers who process data on the controller's behalf and in accordance with its instructions:
| Service | Purpose |
|---|---|
| HubSpot | Customer relationship management and newsletter |
| Supabase | Database and server functions |
| Lovable | Website platform and publishing |
| Web3Forms | Storage and delivery of form notifications |
| netFinn | Email service |
| Files, analytics and advertising | |
| Meta Platforms | Advertising and lead forms |
| Calendly | Appointment booking |
Data may also be disclosed to the accountant, auditor or an authority where required by law, and to a partner carrying out installation or maintenance to the extent the work requires.
7. Transfers outside the EU
Some of the services used operate in the United States. Transfers are based either on the EU-US Data Privacy Framework or on standard contractual clauses approved by the European Commission. Data is not transferred to countries lacking an adequate level of protection.
8. Retention periods
Data is retained only for as long as is necessary for the purpose for which it was collected:
- Enquiries and quote requests: for as long as the matter is current and may lead to a customer relationship. Once it is established that an enquiry will not lead to a sale, the data is deleted or anonymised.
- Newsletter: until the subscription is cancelled.
- Customer data: for the duration of the customer relationship and thereafter for as long as contractual, warranty and liability matters require.
- Invoicing and accounting records: for the period required by the Finnish Accounting Act.
- System operating data: for as long as the system is in use. Thereafter the data is deleted or converted into a form in which the data subject cannot be identified.
The data subject may request the deletion of their data at any time, and the data will be deleted unless the law obliges the controller to retain it.
9. Security
Data is protected by passwords and access controls. Only those persons whose duties so require have access to the data.
10. Rights of the data subject
The data subject has the right to:
- be informed of what data concerning them has been stored, and to receive a copy of it
- request the rectification of inaccurate data
- request the erasure of their data
- request the restriction of processing, or object to processing
- receive the data they have provided in a portable format
- withdraw consent at any time, for example by cancelling the newsletter or changing cookie settings
Requests are generally responded to within one month.
The data subject also has the right to lodge a complaint concerning the processing of personal data with the Office of the Data Protection Ombudsman in Finland (tietosuoja.fi).
11. Changes to this policy
This policy is updated when the services or processing practices change. The current version is always available on this page.