Privacy policy
Updated: 1.10.2026
This document is a translation. The binding version of this privacy policy is the Finnish one, published at autobaric.com/tietosuoja. Where the texts differ, the Finnish one applies — not because the translation is careless, but because only one text can be the one that was checked.
This policy covers the autobaric.com site and registration for the Autobaric service. For the data entered into the service the controller is the customer organisation and not Autobaric; that data is covered by the data processing agreement.
What we collect and why
| Data | Why | Basis | For how long |
|---|---|---|---|
| Email address | Confirming registration, and signing in | Preparation and performance of a contract (6(1)(b)) | Life of the account + 24 months |
| Organisation name and jurisdiction | The service produces country-specific records; the jurisdiction decides which forms and retention periods are used | 6(1)(b) | Life of the account + 24 months |
| Estimated number of chambers | Pricing is per chamber | 6(1)(b) | Life of the account |
| Sign-in data | Authentication | 6(1)(b), and for security purposes legitimate interest (6(1)(f)) | Life of the account + 12 months |
The confirmation link is not kept in the clear but as a hash. The link is single-use and it expires.
How retention periods are supervised is of two kinds — and the difference is stated here, because a promise we cannot demonstrate is worse than a limited one we can: the deletion of an abandoned registration (30 days) is supervised by machine — a scheduled job deletes the row. Periods tied to the end of an account are carried out when the account is closed, and they are not yet supervised by machine; until then they are a commitment whose fulfilment is manual work.
What we do not collect
- No tracking. No analytics, no advertising identifiers, no third-party scripts and no external fonts. The site makes no request anywhere else. You can check that in your browser's network tab.
- No cookies on the site. That is why the site does not ask for cookie consent: a consent dialogue for something that does not exist is a bad habit, not good manners. The application has a session cookie, which is necessary for signing in.
- No payment card data. Payment processing is not yet in use; when it is taken into use, card details will go straight to the payment processor.
- No IP addresses kept. The address is used only momentarily for rate limiting, and it is not stored. The web server has no access log.
Where the data is
The server is in Nuremberg, Germany (Hetzner Online GmbH). The data centre, the backups and the audit chain's timestamping service are in the EU, and records do not leave it.
The email delivery servers are in the EU as well. The provider is Migadu-Mail GmbH, a Swiss company whose privacy policy also serves as the data processing agreement. Its data centres are in the EU, in France, not in Switzerland (Migadu's own statement). The company is registered in Switzerland, which has an adequacy decision from the Commission.
Only invitation and confirmation messages go out by email, and they contain a name and an address. Records, regulatory records and compliance reminders are read from the product and do not travel by email at all. The processors and their locations are listed in the record of processing activities.
This section used to say that the email servers' locations had not been confirmed. The point was closed on 1 October 2026. We called it open while it was open: a promise we cannot demonstrate is worse than a limited promise we can.
The name service is with Cloudflare, but traffic does not pass through it: proxying is switched off, and the connection goes straight to the server.
The audit chain's timestamping service receives only a SHA-256 hash. It cannot see the content and cannot infer it.
To whom we disclose
We neither sell nor disclose data for marketing. The subprocessors are the data centre service, backup storage and email delivery; they are listed in the record of processing activities.
Your rights
You have the right to see your data, to have it corrected, to receive it in a machine-readable form, to request erasure, and to restrict or object to processing. We answer within one month.
The right to erasure is not absolute. Records of hyperbaric chamber operations are subject to a national retention obligation (in practice 5 years in Finland, 10 in Germany, 2 in the United Kingdom). While the obligation is in force, an erasure request is answered with a reasoned refusal and the ground is given — and the refusal states the earliest possible date of erasure, because a time-limited obligation is not an absolute prohibition. When the obligation does not prevent it, identifying data is deleted from the live register; event data remains without an identity, because an authority has to be able to see that a run had a named responsible person.
Erasure does not reach a closed record: a signed record contains the crew and the names of the signatories, and it is immutable. The name stays visible in those records for the duration of the retention obligation (GDPR 17(3)(b)); after that the record is deleted in its entirety in accordance with the retention policy.
You can lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).
Contact details
The controller is the operator of the Autobaric service. In data protection matters: admin@autobaric.com
No data protection officer has been designated: the conditions of Article 37 are not met, because the core activity is neither large-scale, regular and systematic monitoring of data subjects nor large-scale processing of special categories of personal data.