Bloomsday Oy
Rekisteri- ja tietosuojaseloste · Privacy Policy
Sisältö / Content
- Rekisteri- ja tietosuojaseloste
- Privacy Policy and Register Description
1. Rekisteri- ja tietosuojaseloste
Tämä on Bloomsday Oy:n (y-tunnus: 3106915-8) EU:n yleisen tietosuoja-asetuksen (GDPR) mukainen rekisteri- ja tietosuojaseloste.
Laadittu 24.11.2021. Viimeisin muutos 28.8.2026.
Rekisterinpitäjä
Bloomsday Oy, Kolmas linja 4 LH, 00530 Helsinki
Aputoiminimi: Flux Productions
Rekisteristä vastaava yhteyshenkilö
Jukka Åman, jukka@bloomsday.fi
Rekisterin nimi
Bloomsday Oy:n sidosryhmä-, asiakas- ja markkinointirekisteri
Oikeusperuste ja henkilötietojen käsittelyn tarkoitus
Henkilötietojen käsittelyn tarkoituksena on yhteydenpito asiakkaisiin ja sidosryhmiin, saapuvien yhteydenottojen ja tarjouspyyntöjen käsittely, asiakassuhteen ylläpito ja hoitaminen sekä markkinointi.
Käsittelyn oikeusperusteet ovat:
- Sopimus tai sen valmistelu — asiakassuhteen hoitaminen, tilattujen palvelujen toimittaminen ja laskutus.
- Rekisterinpitäjän oikeutettu etu — yritysten ja organisaatioiden edustajiin kohdistuva yhteydenpito ja B2B-markkinointi, saapuvien yhteydenottojen käsittely ja niihin vastaaminen, sekä tietoturvasta huolehtiminen.
- Lakisääteinen velvoite — kirjanpito- ja verolainsäädännön edellyttämä tositteiden säilyttäminen.
- Työsopimusta edeltävät toimet ja oikeutettu etu — työhakemusten käsittely ja hakijoiden arviointi rekrytoinnissa.
- Suostumus — uutiskirjeen ja muun sähköisen suoramarkkinoinnin lähettäminen silloin, kun vastaanottaja on antanut siihen erikseen suostumuksensa. Suostumus on vapaaehtoinen, ja sen voi peruuttaa milloin tahansa uutiskirjeen lopussa olevasta linkistä tai ilmoittamalla siitä rekisterinpitäjän yhteyshenkilölle. Suostumuksen peruuttaminen ei vaikuta sitä ennen tehdyn käsittelyn lainmukaisuuteen. Suostumus pyydetään erikseen myös tarvittaessa kolmansien osapuolten evästeiden osalta.
Automaattinen ja tekoälyavusteinen käsittely
Verkkosivujemme yhteydenottolomakkeella lähetetyt tiedot käsitellään automaattisessa prosessissa, joka siirtää tiedot asiakkuudenhallintajärjestelmäämme. Osana tätä prosessia lomakkeen sisältöä analysoidaan tekoälypohjaisella kielimallilla. Analyysin tarkoituksena on:
- tunnistaa ja suodattaa roskaviestit ja automaattisesti lähetetyt viestit
- luokitella yhteydenotto aiheen ja kiireellisyyden mukaan sisäistä käsittelyä varten
- muodostaa yhteydenotosta lyhyt tiivistelmä myynnin ja asiakaspalvelun käyttöön
- laatia luonnos vastausviestistä
Käsittely perustuu rekisterinpitäjän oikeutettuun etuun: saapuvat yhteydenotot on käsiteltävä ja niihin vastattava viivytyksettä ja johdonmukaisesti.
Automaattinen käsittely ei johda rekisteröityä koskeviin automaattisiin päätöksiin. Tekoälyn tuottama luokittelu, tiivistelmä ja vastausluonnos ovat aina apuvälineitä, jotka Bloomsday Oy:n henkilöstö tarkastaa. Vastausviestejä ei lähetetä automaattisesti ilman ihmisen hyväksyntää, eikä analyysin tulos yksin ratkaise, otetaanko rekisteröityyn yhteyttä tai millä ehdoilla hänelle tarjotaan palveluja. Kyse ei siten ole tietosuoja-asetuksen 22 artiklassa tarkoitetusta automaattisesta päätöksenteosta.
Rekisteröidyllä on oikeus vastustaa oikeutettuun etuun perustuvaa käsittelyä ja pyytää yhteydenottonsa käsittelyä ilman tekoälyavusteista analyysia. Pyyntö osoitetaan yllä mainitulle yhteyshenkilölle.
Rekisterin tietosisältö
Rekisteriin tallennettavia tietoja ovat: henkilön nimi, asema, yritys/organisaatio, yhteystiedot (puhelinnumero, sähköpostiosoite, osoite), tiedot tilatuista palveluista ja niiden muutoksista, laskutustiedot sekä muut asiakassuhteeseen ja tilattuihin palveluihin liittyvät tiedot.
Lisäksi rekisteriin tallennetaan tieto annetuista markkinointiluvista ja niiden peruuttamisesta sekä uutiskirjeen tilaustiedot.
Yhteydenottolomakkeiden osalta rekisteriin tallennetaan lomakkeella annetut tiedot ja viestin sisältö sekä niistä automaattisesti muodostetut johdetut tiedot: yhteydenoton luokittelu ja aihetunniste, kiireellisyysarvio, sisäinen tiivistelmä sekä vastausviestin luonnos.
Verkkosivuston vierailijoiden IP-osoitteita ja palvelun toiminnoille välttämättömiä evästeitä käsitellään oikeutetun edun perusteella mm. tietoturvasta huolehtimiseksi ja sivuston vierailijoiden tilastotietojen keruuta varten niissä tapauksissa, kun niiden voidaan katsoa olevan henkilötietoja. Kolmansien osapuolten evästeille pyydetään tarvittaessa suostumus erikseen.
Säännönmukaiset tietolähteet
Rekisteriin tallennettavat tiedot saadaan asiakkaalta mm. www-lomakkeilla lähetetyistä viesteistä, sähköpostitse, puhelimitse, sosiaalisen median palvelujen kautta, sopimuksista, asiakastapaamisista ja muista tilanteista, joissa asiakas luovuttaa tietojaan.
Yritysten ja muiden organisaatioiden yhteyshenkilöiden tietoja voidaan kerätä myös julkisista lähteistä kuten verkkosivuilta, hakemistopalveluista ja muilta yrityksiltä.
Osa rekisterin tiedoista muodostuu edellä kuvatun automaattisen käsittelyn tuloksena.
Työnhakijat
Voit lähettää meille työhakemuksen sähköpostitse tai muulla tavalla. Työnhakijoista käsitellään seuraavia tietoja:
- nimi ja yhteystiedot
- työhakemus, ansioluettelo ja muut hakijan itse toimittamat tiedostot
- osaaminen, kokemus ja ammatilliset kiinnostuksen kohteet
- LinkedIn-profiili tai muu hakijan toimittama linkki
- muut hakemuksen käsittelyn kannalta merkitykselliset tiedot, jotka syntyvät haastatteluissa ja hakijan kanssa käydyssä viestinnässä
Tietoja käytetään yksinomaan hakemuksen käsittelyyn ja hakijan kanssa viestimiseen rekrytointiprosessin aikana. Tietoja ei luovuteta ulkopuolisille, ellei laki tai viranomaismääräys sitä edellytä.
Työhakemuksia ei käsitellä edellä kuvatussa tekoälyavusteisessa analyysissä.
Henkilötietojen käsittelijät ja käytetyt palvelut
Bloomsday Oy käyttää henkilötietojen käsittelyssä ulkopuolisia palveluntarjoajia, jotka toimivat henkilötietojen käsittelijöinä rekisterinpitäjän lukuun. Kaikkien kanssa on tehty tietosuoja-asetuksen 28 artiklan mukainen käsittelysopimus. Käytettyjä palvelukategorioita ovat:
- Asiakkuudenhallintajärjestelmä — Visma Severa, palveluntarjoaja Visma Solutions Oy (Suomi). Palvelu toimii Microsoft Azuren North Europe -alueella (Irlanti), ja varmuuskopiot on kahdennettu Azuren Länsi-Euroopan alueelle (Alankomaat); tiedot säilyvät EU-alueella. Tiedot salataan tallennettuna AES-256-salauksella ja siirrossa TLS-salauksella. Varmuuskopiot otetaan päivittäin ja niitä säilytetään 30 päivää. Palvelu noudattaa Visman ISO 27001 -sertifioitua VCDM-tietoturvaviitekehystä. Palveluntarjoajan mukaan kaikki yrityksen ja sen asiakkaiden tiedot hävitetään kuuden kuukauden kuluttua ympäristön käytön lopettamisesta.
- Automaatioalusta — n8n Cloud, palveluntarjoaja n8n GmbH (Saksa). Palvelu toimii Microsoft Azure -pilvi-infrastruktuurissa, ja palveluntarjoajan mukaan laitteisto ja alustalle tallennettu data sijaitsevat Euroopan unionissa. Varmuuskopiot replikoidaan saman maan sisällä toiselle alueelle. Asiakasdata salataan sekä siirrettäessä että tallennettuna (AES256), ja työnkulkujen suoritustiedot poistetaan automaattisesti tilillä määritellyn säilytysajan mukaisesti.
- Tekoälypalvelut (kielimallit) — Anthropic (Claude) ja OpenAI (ChatGPT / OpenAI API). Palveluja käytetään yhteydenottolomakkeiden analysointiin ja vastausluonnosten laatimiseen. Palvelut käsittelevät tietoja osittain Yhdysvalloissa (ks. seuraava luku). Palveluntarjoajien kanssa käytetään yrityskäytön sopimusehtoja, joiden mukaan rajapinnan kautta lähetettyjä tietoja ei käytetä kielimallien kouluttamiseen.
- Sähköposti- ja toimisto-ohjelmistot — Microsoft 365, palveluntarjoaja Microsoft Ireland Operations Limited (Irlanti). Microsoftin EU Data Boundary -järjestelyn piiriin kuuluvien palvelujen tiedot säilytetään EU-alueella.
- Verkkosivujen ylläpito — Digitoimisto Dude Oy (y-tunnus 2548021-5, Kauppakatu 14, 40100 Jyväskylä). Palveluntarjoajan ilmoituksen mukaan sivuston palvelimet sijaitsevat Suomessa, ja asiakastietoihin on pääsy vain yhtiön omistajilla ja työntekijöillä.
- Lomakepalvelu — Gravity Forms (WordPress-lisäosa). Lomakkeiden tiedot tallentuvat sivuston omalle palvelimelle, eikä niitä luovuteta lisäosan toimittajalle.
Tietojen säännönmukaiset luovutukset ja tietojen siirto EU:n tai ETA:n ulkopuolelle
Tietoja ei luovuteta säännönmukaisesti muille tahoille. Tietoja voidaan julkaista siltä osin kuin niin on sovittu asiakkaan tai sidosryhmän kanssa.
Pääosa henkilötiedoista käsitellään EU-/ETA-alueella. Yhteydenottolomakkeiden tekoälyavusteisessa analysoinnissa ja vastausluonnosten laatimisessa käytetään kuitenkin yhdysvaltalaisia palveluntarjoajia (Anthropic ja OpenAI), jolloin lomakkeella annetut tiedot siirtyvät käsiteltäväksi Yhdysvaltoihin.
Siirroissa varmistetaan asianmukainen suojataso käyttämällä Euroopan komission hyväksymiä mallisopimuslausekkeita (SCC) tai muuta tietosuoja-asetuksen V luvun mukaista siirtoperustetta, kuten EU:n ja Yhdysvaltojen välistä tietosuojakehystä (EU–US Data Privacy Framework) silloin, kun palveluntarjoaja on sen piirissä. Lisäksi siirretään vain analyysin kannalta tarpeelliset tiedot.
Henkilötietojen säilytysaika
Henkilötietoja säilytetään niin kauan kuin se on tarpeen käsittelyn tarkoituksen toteuttamiseksi:
- Asiakassuhteeseen liittyvät tiedot: asiakassuhteen ajan ja kolme vuotta viimeisestä yhteydenpidosta.
- Laskutus- ja kirjanpitotiedot: kirjanpitolain edellyttämät kuusi vuotta tilikauden päättymisestä.
- Toteutumattomat yhteydenotot ja tarjouspyynnöt sekä niistä muodostetut analyysitiedot ja vastausluonnokset: 12 kuukautta yhteydenotosta.
- Roskaviesteiksi tunnistetut yhteydenotot: poistetaan viivytyksettä.
- Automaatioalustan työnkulkujen suoritustiedot (execution data), jotka voivat sisältää lomakkeella annettuja tietoja: 14 vuorokautta.
- Työnhakijoiden tiedot: rekrytointiprosessin ajan ja enintään kaksi vuotta rekrytointipäätöksestä. Hakijan suostumuksella hakemus voidaan säilyttää pidempään tulevia tehtäviä varten.
- Markkinointilupaa koskevat tiedot: suostumuksen voimassaolon ajan sekä sen jälkeen niin kauan kuin on tarpeen osoittaa, että suostumus on annettu ja peruutettu asianmukaisesti.
Tarpeettomat tiedot poistetaan tai anonymisoidaan säännöllisesti.
Yritysjärjestelyt
Jos Bloomsday Oy tai sen liiketoiminta siirtyy toiselle yhtiölle esimerkiksi yrityskaupan, sulautumisen tai muun yritysjärjestelyn seurauksena, henkilötiedot voivat siirtyä osana järjestelyä. Tällöin tietojen käsittelyssä noudatetaan edelleen tätä selostetta vastaavia periaatteita, ja olennaisista muutoksista tiedotetaan rekisteröityjä.
Rekisterin suojauksen periaatteet
Rekisterin käsittelyssä noudatetaan huolellisuutta ja tietojärjestelmien avulla käsiteltävät tiedot suojataan asianmukaisesti. Jos rekisteritietoja säilytetään Internet-palvelimilla, niiden laitteiston fyysisestä ja digitaalisesta tietoturvasta huolehditaan asiaankuuluvasti. Rekisterinpitäjä huolehtii siitä, että tallennettuja tietoja sekä palvelimien käyttöoikeuksia ja muita henkilötietojen turvallisuuden kannalta kriittisiä tietoja käsitellään luottamuksellisesti ja vain niiden työntekijöiden toimesta, joiden työnkuvaan se kuuluu.
Automaatioprosessissa käytettävät rajapinta-avaimet ja tunnistetiedot säilytetään salattuina, eikä niitä käsitellä osana varsinaista rekisteriaineistoa.
Tarkastusoikeus ja oikeus vaatia tiedon korjaamista
Jokaisella rekisterissä olevalla henkilöllä on oikeus tarkistaa rekisteriin tallennetut tietonsa ja vaatia mahdollisen virheellisen tiedon korjaamista tai puutteellisen tiedon täydentämistä. Tarkastusoikeus kattaa myös automaattisesti muodostetut johdetut tiedot, kuten yhteydenoton luokittelun ja tiivistelmän.
Mikäli henkilö haluaa tarkistaa hänestä tallennetut tiedot tai vaatia niihin oikaisua, pyyntö tulee lähettää kirjallisesti rekisterinpitäjälle. Rekisterinpitäjä voi pyytää tarvittaessa pyynnön esittäjää todistamaan henkilöllisyytensä. Rekisterinpitäjä vastaa asiakkaalle EU:n tietosuoja-asetuksessa säädetyssä ajassa, pääsääntöisesti kuukauden kuluessa pyynnön vastaanottamisesta. Jos pyyntö on monimutkainen tai pyyntöjä on useita, määräaikaa voidaan jatkaa enintään kahdella kuukaudella. Tällöin jatkamisesta ja sen perusteista ilmoitetaan rekisteröidylle kuukauden kuluessa pyynnöstä.
Muut henkilötietojen käsittelyyn liittyvät oikeudet
Rekisterissä olevalla henkilöllä on oikeus:
- pyytää häntä koskevien henkilötietojen poistamista rekisteristä (”oikeus tulla unohdetuksi”)
- pyytää henkilötietojen käsittelyn rajoittamista tietyissä tilanteissa
- vastustaa oikeutettuun etuun perustuvaa käsittelyä, mukaan lukien suoramarkkinointia ja edellä kuvattua tekoälyavusteista analyysia
- saada tiedot siirrettyä toiselle rekisterinpitäjälle (siirto-oikeus) siltä osin kuin käsittely perustuu suostumukseen tai sopimukseen
- peruuttaa antamansa suostumus milloin tahansa, jos käsittely perustuu suostumukseen
Pyynnöt tulee lähettää kirjallisesti rekisterinpitäjälle. Rekisterinpitäjä voi pyytää tarvittaessa pyynnön esittäjää todistamaan henkilöllisyytensä. Rekisterinpitäjä vastaa asiakkaalle EU:n tietosuoja-asetuksessa säädetyssä ajassa, pääsääntöisesti kuukauden kuluessa pyynnön vastaanottamisesta. Jos pyyntö on monimutkainen tai pyyntöjä on useita, määräaikaa voidaan jatkaa enintään kahdella kuukaudella. Tällöin jatkamisesta ja sen perusteista ilmoitetaan rekisteröidylle kuukauden kuluessa pyynnöstä.
Oikeus tehdä valitus valvontaviranomaiselle
Rekisteröidyllä on oikeus tehdä valitus tietosuojaviranomaiselle, jos hän katsoo, että henkilötietojen käsittelyssä rikotaan tietosuoja-asetusta. Suomessa valvontaviranomainen on tietosuojavaltuutetun toimisto (tietosuoja.fi).
2. Privacy Policy and Register Description
This is the register and data protection statement of Bloomsday Oy (Business ID: 3106915-8) in accordance with the EU General Data Protection Regulation (GDPR).
Prepared on 24 November 2021. Last updated on 28 August 2026.
Controller
Bloomsday Oy
Kolmas linja 4 LH
00530 Helsinki
Finland
Contact Person Responsible for the Register
Jukka Åman, jukka@bloomsday.fi
Name of the Register
Bloomsday Oy Stakeholder, Customer and Marketing Register
Legal Basis and Purpose of Processing Personal Data
Personal data is processed for the purposes of maintaining contact with customers and stakeholders, handling incoming enquiries and requests for proposals, managing customer relationships, and marketing.
The legal bases for processing are:
- Contract or its preparation — managing the customer relationship, delivering ordered services, and invoicing.
- Legitimate interest of the controller — contact with and B2B marketing to representatives of companies and organizations, handling and responding to incoming enquiries, and ensuring information security.
- Legal obligation — retention of records as required by accounting and tax legislation.
- Steps prior to entering an employment contract, and legitimate interest — processing job applications and assessing candidates in recruitment.
- Consent — sending our newsletter and other electronic direct marketing, where the recipient has given separate consent to receive it. Consent is voluntary and may be withdrawn at any time using the link at the end of the newsletter or by notifying the controller’s contact person. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Consent is also requested separately for third-party cookies where required.
Automated and AI-Assisted Processing
Information submitted through the contact forms on our website is processed in an automated workflow that transfers the data to our customer relationship management system. As part of this workflow, the content of the form is analysed using an AI language model. The purpose of the analysis is to:
- identify and filter out spam and automated submissions
- categorise the enquiry by topic and urgency for internal handling
- produce a short internal summary of the enquiry for sales and customer service
- prepare a draft reply message
This processing is based on the controller’s legitimate interest: incoming enquiries must be handled and answered promptly and consistently.
Automated processing does not result in automated decisions concerning the data subject. Any categorisation, summary, or draft reply produced by the AI serves only as an aid and is reviewed by Bloomsday Oy personnel. Reply messages are never sent automatically without human approval, and the result of the analysis alone does not determine whether the data subject is contacted or on what terms services are offered to them. This therefore does not constitute automated decision-making within the meaning of Article 22 of the GDPR.
The data subject has the right to object to processing based on legitimate interest and to request that their enquiry be handled without AI-assisted analysis. Such requests should be addressed to the contact person named above.
Contents of the Register
The register may contain the following information:
- Name of the person
- Position/title
- Company/organization
- Contact details (telephone number, email address, postal address)
- Information about ordered services and changes to them
- Billing information
- Other information related to the customer relationship and ordered services
The register also stores information on marketing consents given and withdrawn, together with newsletter subscription details.
For contact form submissions, the register stores the information provided on the form and the content of the message, together with derived data generated automatically from it: the categorisation and topic tag of the enquiry, an urgency assessment, an internal summary, and a draft reply message.
IP addresses of website visitors and cookies necessary for the functioning of the service are processed on the basis of legitimate interest, for example to ensure information security and to collect statistical data on website visitors, insofar as they are considered personal data. Consent is requested separately where required for third-party cookies.
Regular Sources of Data
The data stored in the register is obtained from customers through, among other things: messages sent via website forms, email, telephone, social media services, agreements, customer meetings, and other situations where the customer provides their information.
Contact details of representatives of companies and other organizations may also be collected from public sources such as websites, directory services, and other companies.
Some data in the register is generated as a result of the automated processing described above.
Job Applicants
You may send us a job application by email or by other means. The following information is processed about job applicants:
- name and contact details
- the application, CV, and any other files provided by the applicant
- skills, experience, and professional interests
- LinkedIn profile or other link provided by the applicant
- other information relevant to processing the application that arises during interviews and communication with the applicant
This information is used solely to process the application and to communicate with the applicant during the recruitment process. It is not disclosed to third parties unless required by law or by an order from a public authority.
Job applications are not subject to the AI-assisted analysis described above.
Processors and Services Used
Bloomsday Oy uses external service providers that process personal data on behalf of the controller. A data processing agreement in accordance with Article 28 of the GDPR has been concluded with each of them. The categories of services used are:
- Customer relationship management system — Visma Severa, provided by Visma Solutions Oy (Finland). The service runs in the Microsoft Azure North Europe region (Ireland), with backups duplicated to the Azure West Europe region (Netherlands); data remains within the EU. Data is encrypted at rest using AES-256 and in transit using TLS. Backups are taken daily and retained for 30 days. The service follows Visma’s ISO 27001-certified VCDM security framework. According to the provider, all company and customer data is destroyed six months after use of the environment ends.
- Automation platform — n8n Cloud, provided by n8n GmbH (Germany). The service runs on Microsoft Azure cloud infrastructure and, according to the provider, the hardware and the data stored on the platform are located within the European Union. Backups are replicated to a separate region within the same country. Customer data is encrypted in transit and at rest (AES256), and workflow execution data is deleted automatically in accordance with the retention period configured on the account.
- AI services (language models) — Anthropic (Claude) and OpenAI (ChatGPT / OpenAI API), used to analyse contact form submissions and prepare draft replies. These services process data in part in the United States (see the following section). Business terms are used under which data submitted via the API is not used to train the language models.
- Email and office software — Microsoft 365, provided by Microsoft Ireland Operations Limited (Ireland). Data for services covered by Microsoft’s EU Data Boundary is stored within the EU.
- Website hosting — Digitoimisto Dude Oy (Business ID 2548021-5, Kauppakatu 14, 40100 Jyväskylä, Finland). According to the provider, the website’s servers are located in Finland and customer data is accessible only to the company’s owners and employees.
- Form service — Gravity Forms (WordPress plugin). Form data is stored on the website’s own server and is not disclosed to the plugin vendor.
Regular Disclosures of Data and Transfers Outside the EU or EEA
Data is not regularly disclosed to other parties. Information may be published to the extent agreed upon with the customer or stakeholder.
Most personal data is processed within the EU/EEA. However, the AI-assisted analysis of contact form submissions and the preparation of draft replies use US-based service providers (Anthropic and OpenAI), which means that information submitted through the form is transferred to the United States for processing.
In such transfers, an adequate level of protection is ensured through the use of Standard Contractual Clauses approved by the European Commission, or another transfer mechanism under Chapter V of the GDPR, such as the EU–US Data Privacy Framework where the service provider participates in it. Only data necessary for the analysis is transferred.
Retention Period
Personal data is retained for as long as necessary for the purpose of processing:
- Data relating to the customer relationship: for the duration of the relationship and three years from the last contact.
- Invoicing and accounting data: six years from the end of the financial year, as required by the Finnish Accounting Act.
- Enquiries and requests for proposals that did not lead to a customer relationship, including the analysis data and draft replies generated from them: 12 months from the date of the enquiry.
- Enquiries identified as spam: deleted without delay.
- Workflow execution data on the automation platform, which may contain information submitted through the form: 14 days.
- Job applicant data: for the duration of the recruitment process and for a maximum of two years from the recruitment decision. With the applicant’s consent, the application may be retained longer for future positions.
- Records of marketing consent: for the duration of the consent and thereafter for as long as necessary to demonstrate that consent was properly given and withdrawn.
Unnecessary data is deleted or anonymised on a regular basis.
Corporate Transactions
If Bloomsday Oy or its business is transferred to another company as a result of an acquisition, merger, or other corporate transaction, personal data may be transferred as part of that transaction. In such a case, the data will continue to be processed in accordance with principles equivalent to those set out in this statement, and data subjects will be informed of any material changes.
Principles of Register Protection
Due care is observed in processing the register, and data processed through information systems is protected appropriately.
If register data is stored on Internet servers, appropriate physical and digital security measures are ensured. The controller ensures that stored data, server access rights, and other information critical to the security of personal data are handled confidentially and only by employees whose duties require such access.
API keys and credentials used in the automated workflow are stored in encrypted form and are not processed as part of the register data itself.
Right of Access and Right to Request Rectification
Every person included in the register has the right to access the data stored about them and to request correction of any inaccurate information or completion of incomplete information. The right of access also covers automatically generated derived data, such as the categorisation and summary of an enquiry.
Requests to access or rectify personal data must be submitted in writing to the controller. The controller may request the person making the request to verify their identity if necessary. The controller will respond within the time frame specified by the GDPR, generally within one month of receiving the request. If the request is complex or if there are several requests, the deadline may be extended by up to two months. In that case, the data subject will be informed of the extension and the reasons for it within one month of the request.
Other Rights Related to the Processing of Personal Data
A person included in the register has the right to:
- request the deletion of personal data concerning them (”right to be forgotten”)
- request the restriction of processing in certain situations
- object to processing based on legitimate interest, including direct marketing and the AI-assisted analysis described above
- receive their data in a portable form (right to data portability), insofar as processing is based on consent or a contract
- withdraw consent at any time, where processing is based on consent
Requests must be submitted in writing to the controller. The controller may request verification of identity if necessary. The controller will respond within the time frame specified by the GDPR, generally within one month of receiving the request. If the request is complex or if there are several requests, the deadline may be extended by up to two months. In that case, the data subject will be informed of the extension and the reasons for it within one month of the request.
Right to Lodge a Complaint with a Supervisory Authority
The data subject has the right to lodge a complaint with a data protection authority if they consider that the processing of their personal data infringes the GDPR. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).