This privacy and data protection policy is compliant with The EU General Data Protection Regulation (Regulation EU 2016/679) (“GDPR”). We do not differentiate between country of access or citizenship when it comes to privacy and provide all our users with the same rights.
Holder of the register
Finnish Education Outreach
Name of the register
This privacy and data protection policy applies to following registers:
- Members register
- Students register
- Collaborators register
- Events register
The purpose of the register
The data saved in the register is used for informing and contacting the persons in the register about activities organised by Finnish Education Outreach.
The data collected and saved at all event registration forms is used solely for coordination purposes of the specific events, according to the EU rules and regulations for projects.
The information saved in the register
- Person’s first name and family name
- Email address
- Possible phone number
Storing of the data
The data will be stored for a maximum of five (5) years after it has been registered. Renewal of the register will be communicated with the person in question in advance.
Passing of the data to third parties
Under no circumstance will Finnish Education Outreach pass on the data to a third party.
First and family names of the event participants may be passed on to the event hotel, conference venue, and the caterers for coordinating purposes of the event. No data will be shared or passed on to other third parties unrelated to the specific event.
The principles of protecting the registers stored
The data collected is stored and managed at the register holder’s data storage. Access to this storage requires login credentials. The data is protected by a firewall. Only the organisation’s DPO’s (delegates for data protection) have access to this data.
Right to inspection, the correction of information and right to prohibit processing
Every registered person has the right to inspect the data concerning them, the right to demand the correction and/or removal of information and the right to prohibit the use of their information for direct marketing or other such purposes, as well as to otherwise refer to their rights as provided for by the Data Protection Act.
For what purposes is personal data collected and used?
We collect, store and process your personal data only for predefined purposes. The main purposes for processing personal data are:
- fulfilling our contractual obligations
- fulfilling legal obligations and responding to legal claims
- customer communications and responding to contact requests
- development of our operations
- targeting our services to you
What data you collect about me and from which sources?
We collect personal data about you mainly from yourself when you contact us or use our services Typically we may get following personal data directly from you:
- email address
What is the basis for processing your personal data?
We make sure that we always have a legal basis to process your personal data. We may process your data on a several different basis. Firstly, we may process your data to fulfill and execute a contract and to meet legal obligations. Secondly, we may process your data also to further our legitimate interests, which are the offering of our services and operating and developing our business. Some personal data we may process based you your consent.
Who processes my personal data and is it transferred to anyone else?
Primarily your personal data is processed by authorized people within our own organization. We may also outsource some parts of the processing to third parties, such as the data systems used to store and process personal data. In these situations, we make sure with contracts and otherwise that the confidentiality of your personal data is secured and data is otherwise processed lawfully.
Is my data transferred outside the EU?
By default, your data is not transferred outside the EU.
How long is my data stored?
We will not store your personal data for longer period than is necessary for its purpose or required by contract or law. The storage times for personal data may vary based on its purpose and the situation. We also intend to keep your data up to date.
How is my data stored and kept secure?
Your data is stored on the servers provided by our service providers, which are secured according to general industry standards and practices. We consider and keep your personal data confidential and do not disclose them to anyone else than those who need it for their work or confidentially to our customers based on contracts we have made with them. Access to your personal data has been protected with user-specific logins, passwords and user rights.
Is it mandatory to provide personal data? What happens if I don’t give it to you?
If you don’t provide us some of your personal data or allow processing of it, it is very likely that we cannot serve you and fulfill the purpose of our business. If you don’t want us to process your data, we ask you to not provide us any personal data.
What rights do I have relating my personal data?
Withdraw your consent
If we process personal data based on your consent, you can at anytime withdraw your consent by notifying us.
Access to data
You have the right to have confirmed if we are processing your personal data and also to know what data we have about you. In addition, you have right to some supplemental information described in the law about the processing activities.
Right to have errors corrected
You have the right to request that we correct any inaccurate or outdated personal data we have about you.
Right to object processing
If we process your personal data based on public interest or our legitimate interest, you have the right to object processing of your data, to the extent that there is no such significant other reason that would override your rights or the processing is not necessary for handling legal claims. Please notice that in this situation we may not be able to serve you anymore.
Right to restrict processing
In certain situations you have the right to require that we restrict processing of your personal data.
Right to data portability
If we process your personal data based on your consent or fulfilling of a contract, you have the right to require transfer of the data you have provided to us to another services provider in a commonly used electronic format.
How can I use my rights?
You can execute and use your rights by contacting us. In such case, we ask you to provide us your name, contact details, phone number as well as a copy of valid personal ID, such as a driver’s license or passport, so we can verify your identity. If you consider that the processing of your personal data is not lawful, you can always also make a notification to a supervisory authority.
Who can I contact in privacy matters?
- Aino Roivainen
- +358 50 548 2465