We’re currently working hard on updating the English pages. Thanks for your patience!
This Privacy Statement (hereinafter referred to as the “Statement”) describes how the Professionals of Business and Technology collects, processes, and discloses personal data in connection with the membership and its management and the provision of member services, or in connection with the personal data of potential members obtained at events or otherwise, as well as in its operations with different stakeholders.
Data Controller: The Professionals of Business and Technology (“the Association”) is responsible for ensuring that your personal data is processed in accordance with this Statement and the applicable data protection laws.
The Association’s contact information: Address: Ratavartijankatu 2 a, 00520 Helsinki, Telephone: +358 20 155 880
E-mail: tietosuoja@tradenomi.fi
The personal data of the Association’s members and persons related to them, applicants for membership, persons who have participated in or registered for events or who have otherwise contacted the Association, and former members is processed in the register. In addition, the personal data of the contact persons of the organisations involved in the operations of the Association and its shop stewards (“Data Subject”) is processed.
We only collect and process personal data that is necessary for the operation and development of our operations and the establishment and/or management of our membership.
We process your personal data for the following purposes:
We process personal data primarily for managing the membership, union activities, advocacy, the implementation of member services, and other agreed matters, as well as for the collection of membership fees. The processing of personal data is based on the membership between you and us (agreement) and the Association’s statutory obligation to keep a member register.
We may process your data to inform you about our operations and member benefits and to provide you with membership-related services. We may also process your personal data for research concerning advocacy, member services, and other topics and member surveys. On these grounds, we can also contact you for a maximum of 3 years after the end of your membership. The processing of personal data is based on the membership and our legitimate interest in providing information as part of the service and in marketing our other services to you.
We also process your personal data to ensure the data security of the member services and the website, to improve the quality of the member service and the website, and to develop the member services.
We may also compile internal reports on the basis of personal data for our internal use for the appropriate management and development of our operations. In these cases, the processing of personal data is based on the membership and our legitimate interest in ensuring the appropriate data security of the member services and our website and in obtaining sufficient and appropriate information for the development of the member services and the management of our operations.
We may process your personal data in order to fulfil our legal obligations, e.g. regarding accounting or in order to fulfil legal requests for data from authorities (e.g. tax authorities).
We may also process your personal data for other purposes if you have consented to such processing, e.g. when subscribing to a newsletter.
The personal data and contact information of the Association’s members and other necessary information related to membership is processed in the register. This data includes:
We may collect your personal data in different ways. As a rule, we collect and process personal data that:
You are not obliged to provide us with your personal data, but if you choose to not do so, we may not be able to provide you with our services.
The personal data processed digitally is protected and stored in the Association’s System, to which access is restricted only to persons who need the data in order to perform their duties. These persons have personal usernames and passwords. An agreement has been concluded with the system supplier, which requires the data to be protected in accordance with the requirements of the General Data Protection Regulation.
Paper documents are stored locked away and are only accessible to persons who need them for their duties.
We may disclose personal data to third parties:
Data is disclosed for direct marketing purposes and electronic direct marketing only with the written or electronic consent of the Data Subject, which can be revoked at any time.
For the processing of personal data, the Association may also use other service providers that are located outside the European Union or the European Economic Area (e.g. the Mailchimp newsletter application) or that may transfer data to a certain extent outside the European Economic Area (e.g. Vitec Avoine Oy, Novellus Palvelut Oy). Personal data is always transferred outside the European Union or the European Economic Area on one of the following lawful bases:
Access to personal data is not granted beyond what is necessary for the provision of the services. The transfer of personal data outside the European Union or the European Economic Area is always based on the applicable legislation on the processing of personal data and is carried out in accordance with that legislation.
The retention periods are defined in the Association’s archiving plan and the data is stored accordingly. For example, a member’s personal data is stored in the register for as long as the Data Subject is a member of the Association. After the termination of the membership, personal data will be stored for a maximum of ten years after the termination of the membership on the basis of the Association’s legitimate interest, i.e. to defend against possible legal claims (KKO 2017:15). Personal data may also be stored for longer if applicable legislation or the Association’s contractual obligations towards third parties require a longer storage period.
As part of the processing of personal data, the Association may carry out automated profiling of the Data Subject. As a result of profiling, the Data Subject receives communications that are better targeted, such as up-to-date labour market information for their own collective agreement sector.
Profiling is carried out on the basis of the content of the communications selected by the Data Subject, the services used, the openings and clicks of newsletters, and the membership history using statistical methods.
The Data Subject has the right to prohibit or allow the processing of their personal data for direct marketing purposes at any time.
In addition, the Data Subject has the right, in accordance with applicable data protection legislation, to:
The Data Subject must request the implementation of the above-mentioned right in accordance with the Contacts section of this Privacy Statement. The Association may request the Data Subject to specify their request in writing and to verify the identity of the Data Subject prior to processing the request. The Association may reject the request on the grounds provided in relevant legislation.
Every Data Subject has the right to lodge a complaint with the competent supervisory authority or the supervisory authority of the member state of the European Union in which the Data Subject has their place of residence or workplace if the Data Subject considers that their personal data has not been processed in accordance with applicable data protection legislation.
Requests concerning the exercise of the Data Subject’s rights, questions about this Privacy Statement, and other contacts must be made by e-mail to the Data Protection Officer at tietosuoja@tradenomi.fi. The Data Subject may also contact us personally or in writing at the address below:
The Professionals of Business and Technology
Data protection officer
Ratavartijankatu 2, 00520 Helsinki
The Association reserves the right to update this Statement. The currently valid Statement can be found at tradenomi.fi/tietosuoja. This Privacy Statement was last updated on 30 August 2024.
This Privacy Statement outlines how The Professionals of Business and Technology collects, manages, uses, and safeguards personal data regarding members, applicants, former members, and operational stakeholders. It details the legal bases for processing, data categories collected, third-party disclosure policies, data retention periods, cross-border data transfers, and individual rights under GDPR.
Who is the data controller for personal data processed by the association?
The Professionals of Business and Technology ("the Association") acts as the Data Controller responsible for ensuring personal data is handled according to the Privacy Statement and applicable data protection legislation.
For what purposes is personal data collected and processed?
Personal data is processed primarily to manage memberships, union activities, advocacy, member services, fee collection, communications, service development, and compliance with statutory obligations.
What categories of personal data are collected?
Collected data includes contact details, education, membership and fee history, workplace data, event participation, communication records, electronic identification metrics, profiling categories, and website usage logs.
How long is personal data retained after membership termination?
Personal data is stored for the duration of the membership and for up to ten years after termination to defend against potential legal claims, or longer if required by statute or contractual duties.
What rights do data subjects hold regarding their personal data?
Data subjects have rights to access, rectify, or erase data, object to or restrict processing, revoke consent, opt out of direct marketing, obtain data portability, and lodge complaints with supervisory authorities.
The Association may contact former members for marketing and information purposes for up to three years after membership ends.
On these grounds, we can also contact you for a maximum of 3 years after the end of your membership.
Personal data is retained for up to ten years post-membership based on legitimate interest to defend against legal claims.
After the termination of the membership, personal data will be stored for a maximum of ten years after the termination of the membership on the basis of the Association’s legitimate interest, i.e. to defend against possible legal claims (KKO 2017:15).
Transfers of personal data outside the EU/EEA are conducted strictly under lawful mechanisms such as adequacy decisions, standard data protection clauses, or explicit consent.
The transfer of personal data outside the European Union or the European Economic Area is always based on the applicable legislation on the processing of personal data and is carried out in accordance with that legislation.
Inquiries and data subject rights requests can be directed via email to the Data Protection Officer at tietosuoja@tradenomi.fi.
Requests concerning the exercise of the Data Subject’s rights, questions about this Privacy Statement, and other contacts must be made by e-mail to the Data Protection Officer at tietosuoja@tradenomi.fi.
The professional association acting as the data controller for member and stakeholder data.
Key contractual partner managing the member register system.
Contractual partner providing IT services to the association.
Contractual partner responsible for back-office services relating to membership fees.
Partner organization involved in offering insurance benefits to association members.
Central confederation of trade unions for managerial and professional staff in Finland.
Public authority receiving statutory membership fee data for tax processing.