• fi
  • en
  • RAKLI ry data protection

    Data protection

    1. Data controller

    RAKLI ry (1070296-2), Annankatu 24, Fi-00100 Helsinki

    rakli@rakli.fi

    Contact person: Aija Tasa, Director, aija.tasa@rakli.fi

    2. Whose data do we process?

    We process data pertaining to the following parties:

    3. Information we process

    We only process personal information that is necessary for our operations and information that has been provided to us. A member of the staff of the member you represent may also provide us information. The information we process about the data subject is

    4. The purpose and grounds for processing personal data

    We process data as part of managing and maintaining memberships, communications and information dissemination, sending out invitations to events as well as lobbying and marketing activities.

    Members with contact persons

    The purpose of the processing: Maintaining a membership relationship and enabling the necessary contacts.
    Grounds for processing: 1) Associations Act (Yhdistyslaki 503/1989), 2) the legitimate interest of the controller

    Potential members with contact persons

    The purpose of the processing: Marketing and communications
    Grounds for processing: The legitimate interest of the controller

    Persons associated with stakeholders

    The purpose of the processing: Lobbying and communications, event invitations
    Grounds for processing: The legitimate interest of the controller

    Website users

    The purpose of the processing: Contact requests received via the website. Use of restricted parts of the website.
    Grounds for processing: The legitimate interest of the controller

    5. Data stored in the register

    We only process the kinds of personal data that are necessary for our operations. As a general rule, the data we process has been provided by the data subject themselves. A staff representative of a data subject may also provide us with data.

    We process the following data: name (identifier and contact), postal address (contact), telephone number (contact), email address (contact), employer or company (membership management, targeted marketing), role or title (membership management, marketing targeting), language (membership management), date of birth (identifier), dietary requirements (organisation of events).

    6. The duration of the processing

    As a general rule, personal data is processed for as long as the membership relationship for which we need the data is active or until the member’s contact person is replaced. We record data in the register in the form in which it is obtained from the data subject themselves or from a contact person of a member organisation or from public sources. The data is updated in line with changes the data subject or the contact person of a member organisation informs the controller of or in line with updated data obtained from public sources.

    The personal data of potential members’ contact persons is processed until the contact person is replaced.

    The personal data of stakeholders is processed for as long as the individual operates in a position in which he or she needs to be contacted.

    Subscribers can unsubscribe from our newsletter yourself by clicking the unsubscribe link provided in each newsletter we send out.

    7. Rights of the data subject

    The data subject has the following rights, wherein the requests for their use must be submitted to rakli@rakli.fi

    The right of inspection: Data subjects have the right to verify the personal data we store about them. Data subjects may ask us to correct and/or complete the data we hold about them if they discover errors or omissions in this data.

    Right to object: Data subjects have the right to object to the processing of their personal data at any time if they feel that we have unlawfully processed this data or that we have no right to process certain personal data.

    The prohibition of direct marketing: Data subjects have the right to prohibit us from using their data for direct marketing purposes at any time.

    Removal right: Data subjects have the right to ask us to delete any personal data we hold about them if they feel that the processing of this data is not necessary for the performance of our duties. Upon receipt of such a request, we process the request and then either delete the data in question or inform the data subject of the reason why the data cannot be deleted. Should the data subject disagree with our decision, they have the right to complain to the Data Protection Officer (instructions for filing a complaint). The data subject also has the right to demand that we restrict the processing of the disputed data until such time as the matter can be resolved.

    Right of appeal: Data subjects have the right to complain to the Data Protection Officer if they feel that we are in breach of the applicable data protection legislation when processing their personal data (instructions for filing a complaint).

    8. From what sources do we obtain data?

    Information about members and their contact persons may be obtained from the person in question, a representative of the member or from public sources. Information about stakeholders and their personnel may be obtained from the person in question, a representative of the stakeholder or from public sources.

    9. How do we secure data?

    We respect the data subject’s privacy when processing personal data and processing personal data in a secure manner is important to us. We will properly protect and secure your data. Systems containing personal data are protected by user-specific logins and passwords. Any paper documents are stored in such a way that is inaccessible to third parties.

    Our system is also protected by firewalls and other technical means. The data contained in the register stored in the system is only accessible by the authorised personnel employed by the data controller, wherein the processing of this data is part of their duties. Our registers are located on a virtual server or in a cloud service, in which access to them by unauthorized persons is blocked. The registers are regularly backed up.

    10. Disclosure of information

    Data will not be disclosed for marketing purposes outside of RAKLI ry. The data controller may selectively disclose data to a third party in order to respond to a query or in order to make a report on behalf of the data controller (for example, a reputation survey for RAKLI ry). Ownership of the data is not transferred from the data controller to a third party, nor is the third party entitled to further use of the data. We ensure that all our service providers comply with the data protection laws.

    11. Transfer of data outside of the EU

    We opt to store your data in secure, European-based data centres whenever possible. Some of our service providers may, however, back up data outside the EU/EEA, for example in centres in the US. Data is backed up to keep your data safe when a main server fails.

    12. Cookies

    This website uses cookies. Websites send a cookie to web browsers. This is a small text file that is stored on your computer’s hard drive. There are temporary session ID cookies that are removed when you exit your web browser and persistent cookies that are stored on your computer’s hard drive. Cookies allow us to identify the browser and use the information we receive to calculate the number of browsers that visit our site and to analyse the use of our site through means such as statistical tracking. They also allow us to view and track the interests of our users, thus improving our website. All information collected is anonymous and cannot be used to associate persons with online activities.

    Most web browsers automatically accept cookies, but users can change their browser settings and opt out of cookies at any time. The use of cookies can be prevented by modifying your browser settings and disabling their use.