Privacy Policy
How Hyper ICT Oy collects, uses, stores, shares and protects personal data in connection with our IPv4 leasing, network services and website.
Hyper ICT Oy
A Finnish company responsible for determining how and why personal data is processed.
What We Process
Business, technical, network, billing, security, communications and website data.
Why We Process It
Service delivery, billing, network security, abuse prevention, compliance and website analytics.
Your Rights
Access, correction, deletion, restriction, objection, portability and withdrawal of consent where applicable.
Contents
Use the links below to navigate directly to a section of this Privacy Policy.
Introduction
This Privacy Policy explains how Hyper ICT Oy (“Hyper ICT”, “Company”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects personal data in connection with our IPv4 leasing, IP address management, network services, website, and related business activities.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable Finnish and European Union data protection laws.
This Privacy Policy applies to customers, prospective customers, business contacts, website visitors, and other individuals whose personal data may be processed in connection with our services.
Data Controller
The data controller is:
Personal Data We Process
Depending on your relationship with us and the services you use, we may process the following categories of personal data.
3.1 Customer and Business Contact Information
This may include:
- Full name
- Company or organization name
- Business address and billing address
- Email address
- Telephone number
- Billing and administrative contact details
- Other information provided when requesting or using our services
3.2 IPv4 and Network Service Information
When providing IPv4 leasing, IP address management, routing, BGP, RPKI, or related network services, we may process information including:
- Assigned IP addresses and IP ranges
- Autonomous System Numbers (ASN)
- Organization and network identifiers
- Routing information
- BGP configuration and routing information
- RPKI and ROA information
- RIPE Database and other Internet registry information
- Reverse DNS and related technical configuration
- Network and service configuration details
- Technical contacts associated with network resources
Some of this information may be publicly available through Internet registries and routing databases.
3.3 Abuse, Security and Incident Data
To protect our IP resources, networks, customers, and third parties, we may process information related to abuse and security incidents, including:
- IP addresses
- Timestamps
- URLs and domain names
- Network and traffic information
- Technical evidence
- Security alerts
- Abuse complaints
- Blacklist and reputation information
- Information provided by abuse reporters
- Relevant customer or end-user information
- Communications relating to investigation and mitigation
Depending on the nature of an incident, this information may originate from customers, network operators, security organizations, reputation services, rights holders, authorities, or other third parties.
3.4 Billing and Payment Information
We may process information necessary for invoicing, accounting, and payment administration, including:
- Customer and company details
- Billing address
- Invoice information
- Payment status
- Transaction references
- Payment method information
Payments may be made by bank transfer or card.
Where card payments are processed through a third-party payment service provider, payment card information is handled according to the payment provider’s systems and privacy practices. Hyper ICT does not intentionally require customers to provide full payment card credentials through ordinary email or support communications.
3.5 Website and Technical Data
When you visit our website, we may process technical information such as:
- IP address
- Browser and device information
- Pages visited
- Date and time of access
- Referring pages
- Cookie identifiers
- Website usage and analytics information
We use Google Analytics, subject to applicable cookie and consent requirements, to understand how visitors use our website and to improve website performance and content.
Non-essential analytics technologies are used in accordance with the consent choices provided through our cookie consent mechanism.
3.6 Communications
We may retain communications relating to our business relationship, including:
- Emails
- Service requests
- Support communications
- Abuse communications
- Technical requests
- Billing communications
Sources of Personal Data
We may obtain personal data directly from you or your organization.
We may also receive or obtain relevant information from other sources where necessary for providing or protecting our services, including:
- RIPE Database and other Regional Internet Registry (RIR) databases
- Public routing and BGP information
- RPKI and ROA systems
- Internet routing registries
- Upstream providers and network operators
- Abuse reporting organizations
- Security and reputation services
- Blacklist and threat intelligence services
- Customers and business partners
- Publicly available technical sources
- Authorities where applicable
Purposes and Legal Bases for Processing
We process personal data only where we have an appropriate legal basis under applicable data protection law.
5.1 Providing and Managing Services
We process customer, contact, technical, routing, and service information to:
- Provide IPv4 leasing services
- Allocate and manage IP resources
- Configure routing and related network services
- Manage BGP, RPKI, ROA, RIPE Database and related technical operations
- Communicate with customers
- Provide technical support
The legal basis is primarily the performance of a contract or taking steps at the customer’s request before entering into a contract.
5.2 Billing, Accounting and Administration
We process billing, transaction, customer, and company information for:
- Invoicing
- Payment administration
- Accounting
- Financial reporting
- Compliance with statutory record-keeping requirements
The legal basis is performance of a contract and compliance with applicable legal obligations.
5.3 Network Security and Abuse Prevention
We process technical, routing, abuse, security, and reputation information to:
- Detect and prevent abuse
- Investigate security incidents
- Protect IP address reputation
- Prevent fraud, spam, phishing, malware, network attacks, and unauthorized activity
- Protect our network resources and infrastructure
- Respond to abuse reports
- Enforce our Terms and Conditions and acceptable-use requirements
The legal basis is our legitimate interest in protecting our services, IP resources, customers, network infrastructure, and business reputation, as well as compliance with legal obligations where applicable.
5.4 Legal and Regulatory Compliance
We may process and disclose information where necessary to:
- Comply with applicable laws
- Respond to legally valid requests
- Cooperate with competent authorities
- Establish, exercise, or defend legal claims
- Meet regulatory, accounting, or compliance requirements
The legal basis is compliance with legal obligations and, where applicable, our legitimate interests.
5.5 Website Analytics
Where required by applicable law, analytics and other non-essential cookies or similar technologies are used based on your consent.
You may manage or withdraw your consent through the cookie settings available on our website.
RIPE Database and Public Internet Registries
Certain IPv4 and network services may require information to be submitted to or maintained in the RIPE Database or other Internet registry systems.
Depending on the service and technical requirements, such information may include organization details, technical contacts, abuse contacts, network resource information, routing information, or other registry-related information.
Customers should be aware that information published in Internet registries may become publicly accessible and may be processed independently by the relevant registry operator and third parties.
Where possible, we seek to use appropriate organizational or role-based contact information rather than unnecessary personal information.
Sharing of Personal Data
We may share or disclose personal data where reasonably necessary with categories of recipients including:
- Upstream providers
- LIRs and IP resource holders
- Network operators
- Internet registries and RIRs
- Hosting and infrastructure providers
- Payment service providers
- Accounting and administrative service providers
- Security and abuse-handling organizations
- Reputation and blacklist services
- Technical service providers and data processors
- Professional advisers where necessary
- Law enforcement, courts, regulators, or other competent authorities where legally required
We disclose only information that is reasonably necessary for the relevant purpose.
Service Providers and Data Processors
We may use third-party service providers to support our operations, including providers of:
- Cloud and data storage
- Business file storage
- Email and communications
- Website hosting
- Analytics
- Payment processing
- Accounting
- Network infrastructure
- Security and monitoring
Business and operational information may, where appropriate, be stored in Hyper ICT’s company-controlled systems, including Microsoft OneDrive and our accounting and technical systems.
Where a third party processes personal data on our behalf, we take appropriate steps to ensure that the processing is subject to suitable contractual and data protection requirements.
International Data Transfers
Because Internet infrastructure and some of our service providers operate internationally, personal data may in certain circumstances be processed outside Finland or the European Economic Area (EEA).
Where personal data is transferred outside the EEA, we take appropriate measures as required by applicable data protection law.
Depending on the circumstances, these measures may include:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Other safeguards permitted under the GDPR
The technical nature of Internet routing and global network services may also result in technical information being transmitted or made accessible internationally.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected or as required by applicable law.
Retention periods depend on the type of information and the purpose of processing.
In general:
- Customer and service information is retained during the customer relationship and for an appropriate period afterward where necessary for contractual, legal, security, or administrative purposes.
- Accounting, invoice, and financial records are retained for the periods required under applicable Finnish accounting and tax laws.
- Abuse, security, routing, and incident information may be retained for as long as reasonably necessary to investigate incidents, prevent repeated abuse, protect IP resource reputation, establish or defend legal claims, and meet applicable compliance requirements.
- Communications may be retained where necessary for customer service, contractual documentation, dispute resolution, security, or legal purposes.
- Website analytics information is retained according to the applicable analytics configuration and consent settings.
Information may be retained for a longer period where required by law, necessary for legal proceedings, or reasonably required to investigate fraud, abuse, or security incidents.
Data Security
We use appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction.
These measures may include:
- Access controls
- Authentication mechanisms
- Restricted administrative access
- Network and security monitoring
- Secure storage
- Access management
- Backup and recovery measures
- Technical security controls
Access to personal data is limited to persons and service providers who require access for legitimate business purposes.
No electronic system can be guaranteed to be completely secure, and therefore absolute security cannot be guaranteed.
Cookies and Google Analytics
Our website uses cookies and similar technologies for website functionality and, subject to applicable consent requirements, analytics.
We use Google Analytics to help us understand website usage and improve our website and services.
Where consent is legally required, analytics cookies and similar non-essential technologies are not used until the required consent has been obtained.
Visitors can accept, reject, or manage non-essential cookies through the cookie consent mechanism available on our website.
Where available, consent may subsequently be withdrawn or changed through the website’s cookie settings.
Further information about the cookies and technologies used on our website may be provided in a separate Cookie Policy.
Your Rights Under the GDPR
Subject to the conditions and limitations provided by applicable law, you may have the right to:
- Request access to your personal data
- Request correction of inaccurate or incomplete personal data
- Request deletion of your personal data
- Request restriction of processing
- Object to processing based on legitimate interests
- Request data portability where applicable
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with a competent data protection supervisory authority
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
We may need to verify your identity before responding to certain requests.
Right to Lodge a Complaint
If you believe that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority.
Hyper ICT Oy is established in Finland. The relevant supervisory authority in Finland is:
You may also have the right to contact another competent supervisory authority in the European Union depending on your circumstances.
Automated Decision-Making
We may use automated systems to assist with network monitoring, abuse detection, security alerts, blacklist monitoring, routing monitoring, and other operational processes.
These systems may identify activity that requires investigation or protective technical action.
We do not use solely automated decision-making that produces legal effects or similarly significant effects on individuals within the meaning of Article 22 GDPR, unless permitted by applicable law and appropriate safeguards are implemented.
Third-Party Services and External Systems
Our services may interact with third-party systems, including Internet registries, routing systems, payment providers, analytics providers, network operators, security services, and other infrastructure providers.
Where these organizations independently determine how and why they process personal data, their own privacy policies and data protection practices apply.
Hyper ICT is not responsible for independent processing carried out by third parties outside our control.
Children’s Privacy
Our IPv4 leasing and network services are intended for businesses and professional users and are not directed toward children.
We do not knowingly collect personal data from children through our IPv4 leasing services.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, or business practices.
The current version will be published on our website with an updated “Last Updated” date.
Where required by law, we will provide additional notice regarding material changes.
Contact Us
For questions regarding this Privacy Policy, the processing of personal data, or your rights under the GDPR, contact:
Hyper ICT Oy
Business ID: 3394765-5
VAT: FI-33947655
Merituulentie 38 A, Floor 6
02200 Espoo
Finland