Hilla receives, collects and processes personal data of users of the Services (later collectively “Data Subjects”). Hilla’s Services are not intended for Data Subjects who have not reached the age of majority in their country of residence. We do not knowingly collect Personal Data from anyone under the age of majority without such consent. If You believe that we might have any information from or about a child under the age of majority, please contact us at firstname.lastname@example.org
“Personal Data” refers to data which allows the identification of an individual person (as defined and in compliance with the European Union’s General Data Protection Regulation 2016/679 (“GDPR”)). This is opposite to “non-personal data” meaning data that cannot be used to specifically identify any person.
We commit to adhere to the provisions of the aforementioned legislation and other such applicable laws and regulations pertaining to processing of Personal Data, as well as to process Personal Data in compliance with good data processing practice. All personnel processing Personal Data are obliged to keep such data strictly confidential.
WHAT IS THE BASIS FOR PROCESSING?
The legal basis for the processing of your Personal Data is, where not stated otherwise or another legal basis is otherwise applicable, the performance of the contract for providing the Services to you, as permitted by GDPR article 6(1)(b).
Hilla can also process your Personal Data where we have a legitimate interest to do so, as permitted by GDPR article 6(1)(f), such as for marketing purposes. Where we rely on legitimate interests as a reason and legal basis for processing personal data, we have considered whether or not those interests are overridden by the rights and freedoms of the Data Subjects and have concluded that they are not.
Where the processing is such that your consent is required by the applicable legislation, we will state so and obtain your consent, and this will be the legal basis for the processing of your Personal Data, as permitted by GDPR article 6(1)(a). However, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. If such withdrawal means that we are no longer able to provide the Services to you, we may cease providing the Services.
We do not collect or process sensitive personal data (Personal Data of special categories).
WHY AND HOW DOES HILLA PROCESS PERSONAL DATA?
Personal and non-personal data is collected directly from the Data Subjects, such as through registration to the events organized by Hilla.
While the provisioning of certain Personal Data is necessary for the use of the Services including participating in the events, certain Personal Data is provided voluntarily. Personal Data may be updated and supplemented by collecting data from private and public sources, such as commercially available directories and websites.
We process Personal Data of Data Subjects to offer the Services and to maintain our relationship with you. In this context, Personal Data may be processed for the following purposes:
• Provide Data Subjects with the Services as requested by the Data Subjects for example via registration to the events
• invoicing (including debt collection), customer service, feedback and related communications
• provision of information and materials related to our Services, for example by newsletters and direct marketing
• Improve and personalize the Services, as well as to develop new Services;
• market and customer analysis and surveys
• Correspond with Data Subjects regarding customer service issues;
• To enforce the terms of our Services;
• ensuring security of our Services and preventing abuses
• ensuring security of our IT environments and protection of data
• complying and fulfilling our legal duties and obligations
Hilla will use your Personal Data for marketing and other similar purposes, and upon your consent, to email marketing by Hilla. You can opt-out of receiving promotional emails by following the instructions in those emails. If you opt-out, Hilla can still send you non-promotional customer information, such as emails about providing the Services or our ongoing business relations with you. Please note that if you do not provide Hilla the required information, this may mean that we are not able to provide the Services to you, perform the contract necessary for the provisioning of the Services or to comply with Hilla’s legal obligations.
In addition to Personal Data, we will collect non-personal data relating to the Data Subjects. This information includes either anonymous or anonymized data or data linked to Personal data that is generated during the use of our website.
You understand that some of the Services, mainly the organization of the events, may require you to permit Hilla to make certain information available to other Data Subjects (as specified in more detail in the Services).
Information you give to us (for example through event registration)
As long as our services are provided to you.
Technically gathered data (for example through our website)
As long as our services are provided to you.
WHO HAS ACCESS TO THE DATA?
Transfer outside EU/EEA:
Personal Data may also be transferred outside the European Union and the European Economic Area (“EU/EEA”) within the company and also to our service providers. In case Personal Data is transferred outside EU/EEA, such transfers are either made to a country that is deemed to provide a sufficient level of privacy protection by the European Commission or transfers are carried out by using appropriate safeguards such as standard data protection clauses adopted or otherwise approved by the EU Commission or competent data protection authority in accordance with the GDPR.
In addition, we may share the Personal Data in connection with any merger, sale of our assets, or a financing or acquisition of all or a portion of our business and in connection with other similar arrangements.
Personal Data are also disclosed to third parties if required under any applicable law or regulation or order by competent authorities, and to investigate possible infringing use of the products and services as well as to guarantee the safety of the products and services.
HOW DOES HILLA PROTECT DATA?
Securing the integrity and confidentiality of Personal Data is important to Hilla. We have taken adequate technical and organizational measures in order to keep Personal Data safe and to secure it against unauthorized access, loss, misuse or alteration by third parties, such as by encryption, access controls and firewalls. Nevertheless, considering the cyber threats in modern day online environment, we cannot give full guarantee that our security measures will prevent illegally and maliciously operating third parties from obtaining access to Personal Data or absolute security of the Personal Data during its transmission or storage on our systems. For the avoidance of doubt, the safeguarding of all account registration information and credentials are the responsibility of the Data Subjects.
The register will be maintained on external service providers’ servers with appropriate safeguards. The register is protected by appropriate industry standard, technical and organizational safety measures. Although Hilla makes good faith efforts to store the data collected in a secure operating environment that is not available to the public, Hilla cannot guarantee the absolute security of that information during its transmission or its storage on the systems. Hilla will post a notice in the Services in case material security breach that endangers your privacy or Personal Data, and if necessary, will contact affected Data Subjects directly. Hilla may also temporarily shut down the Services to protect the Personal Data.
COOKIES AND OTHER TRACKING TECHNOLOGIES
If Hilla will use other tracking technologies in addition to cookies, Hilla shall notify Data Subjects of use of such tracking technologies.
Hilla may use third-party data analytics and/or utility platforms. A list of the third-party data analytics and/or utility platforms can be provided upon request.
You may decline the collection and storage of your data in the future and opt out by following the instructions on those third-party data analytics platforms’ websites. To opt out of internet-based behavioural advertising, you may opt-out by visiting e.g. http://preferences-mgr.truste.com/ or http://optout.aboutads.info/#/.
The Services may feature advertisements served by third parties that deliver cookies to your device so the content you access and advertisements you see can be tracked. A list of the third-party advertisement platforms can be provided upon request.
As a Data Subject, you have a number of rights under applicable data protection laws. You can:
• access the Personal Data processed and obtain a copy of your Personal Data on request in a structured, commonly used and machine-readable format insofar as you have provided the information to Hilla. Hilla provides no guarantee that this information will be compatible, relevant or useful to any other service.
• require Hilla to change incorrect, incomplete, outdated, or unnecessary Personal Data stored about you by contacting Hilla.
• request that Hilla transfer the information you gave to us to another organisation, or to you, in certain circumstances.
• You may request Hilla to restrict processing of certain Personal Data. Your Personal Data will then only be stored and not processed otherwise; this may however lead to fewer possibilities to use the Services. If such restriction means that we are no longer able to provide the Services to you, we shall be entitled to stop providing the Services.
• object to the processing of your data where Hilla is relying on its legitimate interests as the legal ground for processing. For example, you may object to your Personal Data being used for marketing purposes at any time. You may opt-out of receiving such marketing emails by following the instructions in those emails. If You opt-out, we may still send you non- promotional customer information.
Data Subject may exercise the aforementioned rights by sending a written request to email@example.com. We may contact you to request the provision of additional information. Hilla may reject requests that are unreasonably repetitive, excessive or manifestly unfounded.
If you consider Hilla’s processing activities of Personal Data to be inconsistent with the applicable data protection laws, you have the right to lodge a complaint with a supervisory authority for data protection. In Finland, that is the Data Protection Ombudsman.