Back to Tools
Vainu logo

Vainu

GDPR Compliant

Finnish B2B company database covering Denmark, Finland, Norway and Sweden, with published pricing from 3,500 € a year and the best data-subject documentation in this directory.

🇫🇮Finland🇪🇺EU Hosted🇪🇺 European

Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.

Paidfrom 3,500 €/year
Vainu website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountryFinland
OwnershipEuropean-owned
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
European Union"All the application servers and database servers are protected with encryption, network isolation and firewalls. All services are hosted within the EU area" and "Servers are hosted by the industry-standard providers (AWS and MongoDB Atlas hosted by AWS)" (vainu.com/legal-stuff/security-at-vainu/, read 2026-09-01). The same page states that because all development and data processing is done by Vainu rather than external contractors, "the only parties that have something to do with your data are Vainu and its hosting providers".
EU Servers Available
Data Processing AgreementOffered on request, not published
Sub-processor ListView sub-processors
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified1 September 2026

How we reached this

Finnish legal entity: Vainu.io Software Oy, business ID 2557864-2, FI-00530 Helsinki, named as controller in the privacy policy read 2026-09-01. COMPLIANT, and the reason is the documentation rather than the infrastructure. Vainu publishes four separate legal documents: a privacy policy, a customer register description, a security page, and a database privacy statement. That last one is the Article 14 notice for the people in the database rather than for customers, and it is the strongest example in this directory. It states the legal basis as legitimate interest limited to publicly available personal data relating to a person's role in their company, cites the Article 29 Working Party position that business people and company management can usually be considered to fulfil a role in public life, lists the sources (national patent and registration offices, public officials, company websites, press releases), commits to linking all personal data to the source it was acquired from, limits processing to what data subjects could reasonably expect and to the period the person holds the position, and commits to updating or removing a record when the original source changes. Hosting is EU on the security page's unqualified "All services are hosted within the EU area". Exposure is US_CLOUD_ACT because the named providers are AWS and MongoDB Atlas hosted by AWS, both US companies, so the CLOUD Act reaches the party physically holding the data even though it sits in the EU; same shape as Bouncer and Yespo. Schrems II risk MEDIUM rather than LOW because the privacy statement also states data "may be transferred to, and stored at, a destination outside the European Economic Area" and processed by staff outside the EEA, with data processing agreements or Commission standard contractual clauses as the safeguard, so sccInPlace is true. Vainu holds SOC 2 Type 1, independently audited by Prescient Security, and requires ISO 27001, ISO 27017, ISO 27018 and SOC compliance from hosting partners. dpaEvidence ON_REQUEST: DPAs are referenced as the transfer mechanism but no customer-facing DPA document was located at a public URL. Buyer-side point recorded in the listing: Vainu's legitimate-interest analysis covers Vainu's processing, and the customer becomes controller of the records once they reach their own CRM.

About Vainu

Nordic Company Data, With the Homework Published

Vainu builds and maintains a company database for Denmark, Finland, Norway and Sweden, and sells access to it three ways: through its own prospecting platform, as an enrichment feed into your CRM, or as raw data into a warehouse via API and exports.

What Is In the Data

  • Basic: revenue, employee count, location, official industry, web profile, contact details
  • Vainu Custom Industries, its own classification, which is often more useful than official industry codes for defining a real target market
  • Advanced: advanced financials, group structures, financial PDFs, event data, vehicle data
  • Public documents on request
  • Trigger events and email alerts when something changes at a target account

Published Pricing, Which Is Rare Here

Vainu for Prospecting starts at 3,500 €/year plus a 200 € one-time onboarding fee. Vainu for CRM starts at 4,200 €/year plus 750 € onboarding. There is a pricing calculator on the site and a free trial.

Cost scales with which of the four country databases you turn on and which data tiers you need. Publishing a starting figure and a calculator at all puts Vainu ahead of most of this category, including Clevenio, where everything is quote-only.

The Documentation Is the Best in Its Category

Vainu publishes four separate legal documents, and the split is the right one: a privacy policy, a customer register description, a security page, and, crucially, a database privacy statement.

That last document is the Article 14 notice for the people who are in the database rather than for customers, and it is the strongest example of its kind in this directory. It sets out:

  • The legal basis as legitimate interest, limited to personal data in the public domain relating to a person's role in their company
  • The Article 29 Working Party position that business people, company management and representatives can usually be considered to fulfil a role in public life, cited by name as the reasoning
  • The sources: national patent and registration offices, public officials, company websites, press releases and other material the company itself made public, with all personal data linked to the source it came from
  • A data minimisation commitment: processing is limited so as not to extend beyond what data subjects could reasonably expect, and does not continue beyond the period the person holds the position
  • Automatic correction: if the original source is updated or removed, the record follows it

Most vendors in this category publish nothing like this. Reading it takes ten minutes and it is the document you will want when someone asks how the data was obtained.

Security, and the American Layer

From the security page:

All the application servers and database servers are protected with encryption, network isolation and firewalls. All services are hosted within the EU area.

Since all the software development regarding the applications and data processing is being done by Vainu – not by external contractors – the only parties that have something to do with your data are Vainu and its hosting providers.

That second sentence is effectively a sub-processor list of length two, and it is a strong statement. The hosting providers are named as AWS and MongoDB Atlas (hosted by AWS), both American, which is why this row carries US CLOUD Act exposure despite EU hosting. It is the same trade as Bouncer and Yespo: EU location, US provider.

Vainu holds SOC 2 Type 1, independently audited by Prescient Security, and requires ISO 27001, ISO 27017, ISO 27018 and SOC compliance from its hosting partners. A 99.99% uptime SLA is required of business-critical vendors.

The Company

Vainu.io Software Oy, business ID 2557864-2, FI-00530 Helsinki, Finland. The privacy statement refers to subsidiaries of Vainu Corporation applying the same principles, and notes that data may be processed by staff operating outside the EEA, with transfers covered by data processing agreements or Commission standard contractual clauses.

The Part That Is Still Your Job

As with any prospect database, Vainu's legitimate-interest analysis covers Vainu's processing. Once records reach your CRM you are the controller: your own Article 6 basis, your own Article 14 notice, your own handling of objections. Vainu's documentation makes that work considerably easier than most, because the sources are recorded per record, but it does not do it for you.

Where It Fits

Against Clevenio directly, both Finnish: Vainu is stronger on published documentation and pricing, Clevenio reaches further across Europe and ships MCP. See also Dealfront for DACH, Cognism and Albacross in sales prospecting.

Key Features

Company database for Denmark, Finland, Norway and Sweden
Revenue, employee count, location and official industry on every record
Vainu Custom Industries classification beyond official industry codes
Advanced financials, group structures and financial PDFs
Event, vehicle and public document data
Trigger events with email alerts on target accounts
CRM integrations, CSV and Excel export, and API access
Pricing calculator and free trial

Pros & Cons

Publishes a database privacy statement setting out its legitimate-interest basis, sources and limits, which almost no competitor does
Links every personal data record to the public source it came from
Published starting prices and a pricing calculator, rare in this category
States plainly that only Vainu and its two hosting providers touch your data
SOC 2 Type 1 independently audited, with EU hosting stated without qualification
Hosted on AWS and MongoDB Atlas, so US providers hold the data despite EU hosting
The privacy statement allows transfers and staff access outside the EEA
Database covers only Denmark, Finland, Norway and Sweden
3,500 €/year plus onboarding is out of reach for a solo founder
No customer-facing DPA located at a public URL, only referenced

Vainu GDPR & data protection: common questions

Is Vainu GDPR compliant?

Yes. On the evidence we checked, Vainu meets the requirements European businesses usually need. Vainu is a European company headquartered in Finland, data is hosted within the European Union.

Where does Vainu store data?

Vainu states: ""All the application servers and database servers are protected with encryption, network isolation and firewalls. All services are hosted within the EU area" and "Servers are hosted by the industry-standard providers (AWS and MongoDB Atlas hosted by AWS)" (vainu.com/legal-stuff/security-at-vainu/, read 2026-09-01). The same page states that because all development and data processing is done by Vainu rather than external contractors, "the only parties that have something to do with your data are Vainu and its hosting providers".". Data is hosted within the European Union.

Does Vainu offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Vainu. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover

Is Vainu a European company?

Yes. Vainu is headquartered in Finland and, as far as we can establish, European-owned.

Is Vainu subject to the US CLOUD Act?

Indirectly. Vainu itself is European-owned and headquartered in Finland, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is. Standard Contractual Clauses are in place for transfers, which is the required safeguard but does not override a lawful US order.

Schrems II compliance checklist

Who are Vainu's sub-processors?

Vainu publishes its sub-processor list at https://www.vainu.com/legal-stuff/security-at-vainu/. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Vainu and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.