Legal
Privacy Policy
How we collect, use, store and protect personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.
Last updated: This policy applies to the current version of this website and to all personal data processing carried out by the association.
1. Data controller
Suomi-Venäjä-Seuran - Samfundet Finland-Ryssland Kiteen osasto ry
Hämeenkatu 20, 33200 Tampere, Finland
Registration ID: PRO: 30664502
Phone: +358 50 466 3923
Email: info@kiteefriendship.store
All privacy enquiries, access requests and complaints should be sent to info@kiteefriendship.store. The association is a voluntary, non-profit body and does not sell personal data under any circumstances.
2. Personal data we collect
- Contact form data: name, email address, subject and message content that you voluntarily submit.
- Correspondence: emails, letters and phone notes relating to your enquiry, volunteering interest, membership or donation.
- Event participation: where registration is required, the name and contact details needed to organise the activity and, where relevant, accessibility or dietary requirements you choose to share.
- Technical data: limited server log information such as IP address, browser type, requested pages and timestamps, generated automatically when the site is accessed.
We do not knowingly collect special-category data, and we do not request personal data from children without the consent of a parent or guardian.
3. Purposes and legal bases
- Consent (Art. 6(1)(a)): answering enquiries you submit voluntarily and sending information you have asked to receive.
- Contract or pre-contractual steps (Art. 6(1)(b)): administering membership, volunteering arrangements and event participation.
- Legal obligation (Art. 6(1)(c)): maintaining accounting records and a member register as required by Finnish association and accounting law.
- Legitimate interests (Art. 6(1)(f)): maintaining the security and integrity of this website and our communications.
4. Cookies and analytics
This website is designed to function without advertising or profiling cookies. Any cookies used are strictly necessary for the site to operate (for example, preserving security state or basic session behaviour). Strictly necessary cookies do not require consent under EU rules. If we later introduce optional analytics or embedded third-party content, a consent banner will be presented and no optional cookies will be set before you agree.
You can block or delete cookies at any time through your browser settings; core pages of this website will continue to work.
5. Sharing and transfers
Personal data is accessible only to the board members and volunteers who need it for the purpose described above. We may use service providers for email and website hosting, who act as processors under written agreements. We do not transfer personal data outside the European Economic Area unless an appropriate safeguard under Chapter V GDPR applies, such as an adequacy decision or standard contractual clauses.
6. Retention
- Enquiry correspondence: retained no longer than 24 months after the matter is closed.
- Membership and volunteering records: retained for the duration of the relationship and as required by law.
- Accounting records including donation records: retained for the statutory retention period under Finnish accounting law.
- Server logs: retained for a short technical period and then deleted or anonymised.
7. Your rights under EU law
- Right of access to your personal data and to receive a copy.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure where the legal conditions are met.
- Right to restriction of processing and right to object.
- Right to data portability for data processed by consent or contract.
- Right to withdraw consent at any time, without affecting prior lawful processing.
- Right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).
To exercise any right, email info@kiteefriendship.store. We respond within one month, as required by GDPR, and may ask for information needed to verify your identity.
8. Security
We apply appropriate organisational and technical measures, including access limitation, encrypted transport (HTTPS), password protection of accounts, and a policy of collecting the minimum data necessary. Volunteers with data access are instructed on confidentiality.
9. Changes to this policy
We may update this policy to reflect changes in our activities or in applicable law. The current version is always published on this page.