Privacy Policy

1 Introduction

This privacy policy describes how Viittoen Oy ("Viittoen") collects and processes the personal data of its customers, users of the EGALA service, and visitors to the https://egala.fi/ website. In this policy, the term "Service" refers to the website and the EGALA services collectively.

2 Responsible Controller and Data Processors

The Controller for the personal data mentioned in this policy is Viittoen Oy. For questions regarding personal data, please contact:
Piia Nuolioja
044 368 8868
piia.nuolioja@viittoen.fi

Viittoen utilizes the following external Data Processors for processing data described in this policy:

3 Personal Data Categories, Purposes of Processing, Data Sources, and Legal Grounds for Processing

Personal Data Category Purpose of Processing Data Sources Legal Basis for Processing Retention Period and Deletion
Customer Contact Information (name, email, phone, organization), phone number, organization and position, and organization's address details Managing the customer relationship; informing about key matters related to the customer relationship; fulfilling assignments and agreements; acquiring new assignments; and developing business operations The data subject themselves or the organization they represent Legitimate interest and performance of a contract For the duration of the customer relationship and for a maximum of 24 months after the end of the customer relationship, after which the data is deleted
Contact Information of Customer Organizations' Employees, such as name, email address, phone number, organization and position, and organization's address details Managing the customer relationship; informing about key matters related to the customer relationship; fulfilling assignments and agreements; acquiring new assignments; and developing business operations The data subject themselves or the organization they represent Legitimate interest and performance of a contract For the duration of the customer relationship and for a maximum of 24 months after the end of the customer relationship, after which the data is deleted
Interpretation Event Content (speech, text, possible video) Provision of the service (interpretation, subtitling). The data subject themselves and parties to the service situation. Legitimate interest and performance of a contract. 30 days if the Customer saves the content, then deleted. Otherwise, data is removed immediately.
Contact Info for Potential Customers (name, email, phone) who used the "Contact Us" form. Acquiring new customers; contacting; responding to contact requests. The data subject themselves. Legitimate interest and performance of a contract. Stored for a maximum of 24 months, then deleted.
Technical Website Usage and Analytics (time spent, organization, IP address, pages browsed, referral/exit pages) Development of websites and services; ensuring technical operation and maintenance; business development. Google Analytics. Consent given for the use of cookies. 12 months.

4 Personal Data Transfers

The Microsoft Azure cloud platform is utilized in the production of the Service. The service provider is Microsoft Ireland Operations Limited, acting as a data processor on behalf of Viittoen Oy. Personal data stored for the service is kept primarily in Microsoft Azure data centers located within the EU/EEA area. Microsoft does not use the data for its own purposes, but only to enable the technical delivery of the service.

5 Transfer of Personal Data Outside the EU/EEA

Personal data may be transferred outside the EU/EEA in situations permitted by data protection legislation, where the transfer does not require separate permission—i.e., there is either an adequacy decision regarding the level of data protection for the country in question, or standard contractual clauses (SCCs) can be used. In such cases, a contract concerning the receipt of personal data is always in place, as required by data protection legislation.

6 How do we protect personal data?

We maintain a level of data security that is up-to-date in terms of the nature and processing of personal data. Only those of our employees who, by virtue of their work, have the right to process customer data are authorized to use the Service containing personal data. Each user has their own username and password for the Service. Log data is collected in the system regarding the processing of personal data, such as their creation, modification, and deletion.

The log data identifies the person who made the change (email address) and includes the date and timestamp. This data is kept for two (2) years from its creation. Data is collected in databases that are protected by firewalls, passwords, and other technical means. The databases and their backups are located in locked premises, and the data can only be accessed by certain pre-designated individuals.

7 What are your rights as a data subject?

Under the GDPR, a data subject has the following rights related to personal data, as further described in GDPR articles 15-21:
a) Right of access to data: The data subject has the right to request confirmation as to whether their personal data is being processed in connection with the websites or the Service, and to gain access to their data.
b) Right to rectify data: The data subject has the right to request the controller to correct erroneous or incomplete personal data processed in connection with the websites or the Service.
c) Right to erase data: The data subject has the right to request that personal data concerning them be deleted if it is no longer needed for the purpose for which it was collected or processed, if the data subject objects to the processing and there are no overriding legitimate grounds for processing, if personal data is processed unlawfully, or if personal data must be erased to comply with a legal obligation.
d) Right to restrict processing: The data subject has the right to request restriction of the processing of personal data concerning them if the accuracy of the personal data is contested, if the processing is unlawful, or if the controller no longer needs the personal data in question but the data subject reasonably opposes the erasure of the personal data, or if the data subject objects to the processing and it has not yet been verified whether there are legal grounds for processing.
e) Right to object: The data subject has the right to object to the processing of their personal data insofar as the data is processed in connection with the Company's websites or services based on GDPR Article 6(1)(f), in which case the controller must prove that there is a compelling legal basis for processing to continue processing such personal data.

The data subject always has the right to lodge a complaint about the processing of personal data with the data protection authority if the data subject considers the processing to be unlawful. More information is available at www.tietosuoja.fi. The data subject should be prepared to prove their identity when exercising their rights.

8 Who can you contact?

All contacts and requests concerning this statement must be submitted in writing or in person to the contact person named in section two (2).

9 Changes to the privacy policy

Viitto reserves the right to change the privacy policy if necessary. If we change this statement, we will post the changes in the statement with a date. If the changes are significant, we may also inform you about them in other ways, such as by email or by placing a notice on our website. We recommend that you visit our pages regularly and take note of any changes we make to the statement.