1. Data Controller
Kaskas Media Oy
Mechelininkatu 3d
00100 Helsinki

2. Contact Person for the Register
Laura Tahkokallio
Kaskas Media Oy
laura.tahkokallio@kaskas.fi

3. Name of the Register
Kaskas Media Oy’s Customer and Marketing Register

4. Why Do We Process Personal Data?
We process personal data based on your consent, a contract, or our legitimate interests (e.g., managing customer relationships). We use the data for communication, maintaining customer relationships, and marketing purposes.

5. What Data Do We Collect?
We store only necessary data, such as your name, contact information (email and phone number), organization, and information related to the customer relationship (e.g., offers, delivered services, and billing details).

6. How Is My Data Collected and Used?
We collect data for the register through messages sent via website forms, emails, phone calls, contracts, event registrations, customer meetings, and other situations where customers provide their information.

We also use cookies on our website. Cookies are small text files stored on your device by your browser when you visit our website. They help the website remember your input and preferences, such as login information and language settings, to enhance the user experience. Cookies are also used for analyzing visitor statistics and for improving our website’s usability, as well as for remarketing.

We use Google Ads Remarketing to target ads at visitors to our website. These ads promote Kaskas Media’s services. Information about site visits is collected by storing cookies on your device provided by third-party service providers. You can opt out of targeted advertising by disabling cookies at http://www.google.com/settings/ads.

Personal data may also be processed using automated decision-making and profiling, for example, in Google Analytics or Google Ads.

7. Who Are the Recipients of Personal Data?
We do not disclose your data to third parties without your consent unless required by law. In some cases, we may transfer data to servers located outside the EU or EEA, but we always ensure that your data is protected. For instance, data processed via Google Analytics may be transferred outside the EU. You can find more information about Google’s data processing and privacy policies here: https://business.safety.google/compliance/.

In addition to the previously mentioned services, data in the customer and marketing register may also be processed in systems such as MailChimp (newsletter distribution) and PipeDrive (CRM software).

8. How Long Is Data Retained?
We regularly assess the necessity and accuracy of personal data and delete unnecessary customer data as needed.

9. How Is My Data Protected?
We ensure appropriate data protection measures and limit access to personal data to authorized personnel trained for their roles. All systems are secured with strong passwords and user authentication. Employees processing customer register data are bound by confidentiality obligations. We disclose data to third parties only in accordance with legal obligations, such as at the request of the customer or a government authority.

10. What Are My Rights?
As a data subject, you have the right to influence how your personal data is processed. Below are your key rights:

10.1 Right of Access
You have the right to confirm whether we process your personal data. You can also request a copy of your personal data and additional information about how it is processed.

10.2 Right to Rectification
If you find that your data is incorrect or incomplete, you have the right to request its correction.

10.3 Right to Erasure (Right to Be Forgotten)
You can request the deletion of your personal data if it is no longer needed for its original purpose or if the processing is based on your consent and you withdraw it.

10.4 Right to Restriction of Processing
In certain situations, you have the right to request a restriction on the processing of your personal data, for instance, if you contest its accuracy or object to its processing.

10.5 Right to Object
You have the right to object to the processing of your personal data if it is based on our legitimate interests or if used for direct marketing purposes.

10.6 Right to Data Portability
If the processing of your personal data is based on consent or a contract and carried out automatically, you have the right to receive your data in a structured, commonly used, and machine-readable format and to transfer it to another data controller.

10.7 Right to Withdraw Consent
If your personal data is processed based on your consent, you have the right to withdraw your consent at any time. This does not affect the legality of processing carried out before the withdrawal of consent.

10.8 Right to Lodge a Complaint
If you believe that your personal data is being processed unlawfully, you have the right to lodge a complaint with a supervisory authority. In Finland, the supervisory authority is the Data Protection Ombudsman, whose contact details can be found at https://tietosuoja.fi/.