Skip to main content
FI EN
Compare loans

Privacy policy

1. Data controller

Qupio Solutions Oy (Business ID 2849637-8)
Vantaa, Finland
Email: hello@qupiosolutions.fi

The data controller is responsible for the processing of personal data on the Lainafy.com website and can be reached in all data protection matters at the email address above.

2. Data protection officer

Under Article 37 of the GDPR, we are not required to appoint a separate data protection officer, as the nature and scale of our activities do not warrant one. All privacy matters are handled by the data controller at hello@qupiosolutions.fi.

3. Categories of personal data processed

3.1 Technical data (always collected)

  • IP address (pseudonymised)
  • Browser type and version
  • Operating system and device type
  • Referring page and search keywords
  • Time spent on site and pages viewed
  • Language and region settings

3.2 Analytics data (with consent only)

  • Anonymous behavioural data (e.g., clicks, scrolling, session duration)
  • Google Analytics cookie data (client ID, session ID)
  • Aggregated statistics for service improvement

3.3 Marketing and affiliate data (with consent only)

  • Affiliate tracking cookies and click identifiers
  • Conversion data from lender partners (anonymous confirmation of loan application)
  • Retargeting cookies (e.g., Meta Pixel, Google Ads)

3.4 Data submitted by users

  • Name, email and message submitted via contact form
  • Name and message submitted via comment form (if enabled)

We do not collect sensitive personal data (such as bank account numbers, national ID numbers or credit information). Any such data is provided directly to the lender through their own forms outside of Lainafy.

4. Legal bases for processing (GDPR Art. 6)

  • Art. 6(1)(a) – Consent: analytics and marketing cookies, retargeting
  • Art. 6(1)(b) – Performance of a contract: responding to contact requests
  • Art. 6(1)(c) – Legal obligation: accounting law retention, authority requests
  • Art. 6(1)(f) – Legitimate interests: essential technical operation, security, abuse prevention

5. Purposes of processing

  1. Providing and developing the loan comparison service
  2. Ensuring site operation and security
  3. Measuring and improving user experience (analytics)
  4. Tracking affiliate commissions and targeted marketing (with consent only)
  5. Responding to contact requests
  6. Fulfilling legal obligations

6. Sources of data

Personal data is primarily collected directly from you when visiting the site (cookies, behavioural data, any forms). Additionally, we may receive anonymous conversion data from our affiliate partners indicating that your click has led to a loan application (we do not receive personal data).

7. Disclosures to third parties

We do not sell or rent personal data to outside parties. However, we may share data with the following:

7.1 Data processors

  • Web hosting provider: technical server maintenance
  • Google LLC / Google Ireland Ltd.: Google Analytics and Google Ads (with consent only)
  • Meta Platforms Ireland Ltd.: Meta Pixel for retargeting (with consent only)
  • Affiliate networks and lender partners: click and conversion tracking (with consent only)

A GDPR Article 28-compliant Data Processing Agreement (DPA) has been signed with all processors.

7.2 Authorities

We disclose data to authorities only when required by law, such as in the case of a suspected crime or on request from the tax authority.

8. Data transfers outside the EU/EEA

Some of the services we use (e.g., Google Analytics, Meta Pixel) may process data in the United States or other countries outside the EU/EEA. Such transfers are based on:

  • The EU–US Data Privacy Framework decision (European Commission, July 2023), which guarantees an adequate level of data protection for data transferred to the United States
  • Standard Contractual Clauses (SCC) of the European Commission, ensuring EU-level data protection in transfers
  • The user’s explicit consent in the case of marketing cookies

9. Data retention periods

Data categoryRetention periodBasis
Server logs (IP, user agent)Up to 90 daysSecurity and abuse prevention
Analytics cookies (Google Analytics)14 monthsGA default setting; user identifiable only in aggregate
Marketing cookies30–365 daysAffiliate network operation
Contact requests2 years after the messageCustomer service and accountability
Accounting data (commission reports)6 years after end of financial yearFinnish Accounting Act (1336/1997)

Data is deleted or anonymised at the end of the retention period.

10. Register protection

Technical safeguards:

  • All site traffic is encrypted via HTTPS/TLS 1.2+
  • Server located in the EU, in the service provider’s secure data centre
  • Servers are protected by firewall and DDoS protection
  • Software updates are installed regularly to patch critical vulnerabilities
  • Backups are encrypted and stored separately from the main server

Organisational safeguards:

  • Access to personal data is limited to representatives of the data controller
  • Access requires a personal user ID and strong password
  • DPAs (GDPR Art. 28) are in place with all processors

11. Automated decision-making and profiling

Lainafy.com does not carry out fully automated decisions with legal effects as defined in GDPR Article 22. Nor do we perform profiling that would significantly affect the rights of the user.

The site may use automated content targeting (e.g., relevant lender recommendations on loan type pages), but this is not GDPR-defined profiling as no decisions are made on behalf of the person.

12. Rights of the data subject

  • Right of access (Art. 15): you can request a copy of the data we process about you
  • Right to rectification (Art. 16): you can request correction of inaccurate data
  • Right to erasure (Art. 17): the ”right to be forgotten” – you can request deletion of your data
  • Right to restriction (Art. 18): you can require suspension of processing in certain situations
  • Right to data portability (Art. 20): you can receive your data in a machine-readable format
  • Right to object (Art. 21): you can object to the use of your personal data e.g. for direct marketing
  • Right to withdraw consent (Art. 7): you can withdraw consent to cookies at any time via the cookie settings in the footer
  • Right to lodge a complaint with the supervisory authority (Art. 77): Office of the Data Protection Ombudsman, tietosuoja.fi

Requests can be made by sending an email to hello@qupiosolutions.fi. We respond to requests within one month at the latest, in accordance with GDPR Art. 12(3). You must prove your identity in the request to prevent wrongful disclosure of data.

13. Cookies

The site uses three types of cookies:

  • Essential: basic site functions such as session management, security and remembering cookie settings. These do not require consent (GDPR Art. 6(1)(f)).
  • Analytics (Google Analytics or similar): only after consent. Helps us understand service usage and develop it.
  • Marketing and affiliate tracking: only after consent. Used to measure conversions and for possible retargeting.

You can change or withdraw your consent at any time via the 🍪 Cookie settings button in the footer or through your browser settings.

14. Affiliate link tracking and marketing partnerships

Lainafy.com is an affiliate comparison service. When you click a lender’s link on the site (”Apply” or similar), you are directed to the lender’s own site, and Lainafy may receive a commission from the possible loan activation. This does not affect the loan interest, terms or fees you receive.

We do not perform credit checks or process loan decisions. All loan terms and data processing in the loan process take place in the lender’s own systems and in accordance with their own privacy policy.

Affiliate tracking is based on the user’s consent (GDPR Art. 6(1)(a)) and is done with anonymous identifiers (click ID, cookie ID). We do not link affiliate tracking to identified user accounts.

15. Privacy of minors

The Lainafy.com service is not directed at persons under the age of 16. We do not knowingly collect the personal data of persons under 16. If a guardian becomes aware that a child has provided us with data, please contact hello@qupiosolutions.fi – we will remove the data without delay.

16. Data breaches

If we detect a personal data breach that is likely to result in a high risk to the rights and freedoms of data subjects, we will notify:

  • The Data Protection Ombudsman within 72 hours of becoming aware of the breach (GDPR Art. 33)
  • The affected data subjects without undue delay (GDPR Art. 34)

17. Changes to the privacy policy

This policy may be updated due to changes in legislation, the introduction of new services or other justified reason. We will notify you of significant changes on our site. The last update date of the policy is shown at the top of the page.

18. Contact details for privacy matters

For all matters relating to the processing of personal data, please contact:

Qupio Solutions Oy
Business ID: 2849637-8
Vantaa, Finland
Email: hello@qupiosolutions.fi

Supervisory authority: Office of the Data Protection Ombudsman
P.O. Box 800, FI-00521 Helsinki
Phone: +358 29 566 6700 (switchboard)
Website: tietosuoja.fi/en