Created: 17 Febuary 2023
Last updated: 17 February 2023 at 19.15
Harmless Consulting Oy (“Harmless” or “we”) provides technology ethics consulting services for organisations. This Privacy Policy may be updated from time to time in order to reflect the changes in data processing practices or otherwise. You can find the current version on this website.
This Privacy Policy applies to the processing of Personal Data carried out by Harmless as a data controller. Should you have any questions relating to the processing of your Personal Data, or should you wish to use your rights as a data subject, please contact us on the addressees set out below.
This document contains information on the information register and the privacy measures required by the Finnish Henkilötietolaki (10 ja 24 §) and the European General Data Protection Regulation (GDPR).
Harmless Consulting Oy
Satamakatu 3 C 59, FI-33200 Tampere Finland
Business ID: 3344160-3
info@harmlessconsulting.com
Salla Westerstrand
salla@harmlessconsulting.com
Customer register of Harmless Consulting Oy.
Your Personal Data we process for the purposes of this Privacy Policy is referred to as “Personal Data”. We primarily process Data (required and optional) which you provide us directly, via the contact form on our Harmless's webpage or otherwise. You are solely responsible for the content of your contact request. We also collect and process your Personal Data through any personal contacts, phone calls, or e-mail correspondence that you may have with us. Examples of the data, but are not limited to, are
We do not use cookies to collect any Personal Data. Our hosting service provider does not collect your Personal Data when you visit our website.
We collect your Personal data only for planned purposes, such as
A detailed description of other potential use cases can be found below.
We process your Personal Data based on multiple different legitimate grounds. This section describes the Personal Data we may process about you as well as the legal ground for the processing. In case we process your Personal Data based on a consent you have given you may withdraw your consent at any time by notifying us and if the processing is based on our legitimate interest, we will weigh your interest for privacy against our interest in accordance with the data protection laws.
We process the Personal Data for several purposes:
We only share your Personal Data within our organisation as far as reasonably necessary for the purposes of this Privacy Policy. We do not share your Personal Data with third parties outside of our organisation unless one of the following circumstances applies:
We always favour service providers with servers located in the EU/EEA, such as website hosting services and e-mail providers, When you contact us via Harmless website, your Personal Data will be handled in Finland and will not be transferred outside Finland. However, we may use service providers in several geographical locations to conduct our business.
As such, we and our service providers may transfer your Personal Data to, or access it in, jurisdictions outside the EU/EEA. We will take steps to ensure that your Personal Data receives an adequate level of protection in the jurisdictions in which they are processed. We provide adequate protection for the transfers of Personal Data to countries outside of the EEA through a series of agreements with service providers based on the Standard Contractual Clauses. More information regarding the transfers of Personal Data may be obtained by contacting us on any of the addresses indicated above
Harmless does not store your Personal Data longer than is legally permitted and necessary for the purposes of this Privacy Policy. Most Personal Data will be deleted in 12 months from the date of completion of the partnership. Some of the Personal Data may be stored by us only as long as such processing is required by law or is reasonably necessary for our legal obligations or legitimate interests such as claims handling, bookkeeping, internal reporting, and reconciliation purposes. Any data in relation to surveys performed by us is always removed after the survey has been completed and the report of the survey has been formed. By latest all survey related data is removed after 3 months from the closure of the survey.
We do not use your Personal Data to direct you with any automated marketing, profiling or personalised advertisement. In addition, you have the right to prohibit us from using your Personal Data for direct marketing purposes (direct e-mails or calls by our consultant to inform you of services our consultant finds relevant to you) and market research by contacting us on the addresses indicated above or by using the unsubscribe possibility offered in connection with any direct marketing messages.
We use administrative, organisational, technical, and physical safeguards to protect the Personal Data we collect and process. Measures include for example, where appropriate, encryption, pseudonymisation, firewalls, secure facilities, and access right systems. Our security controls are designed to maintain an appropriate level of data confidentiality, integrity, availability, resilience, and ability to restore the data. We regularly test the Services, systems, and other assets for security vulnerabilities.
Should despite the security measures, a security breach occurs that is likely to have negative effects on your privacy, we will inform you and other affected parties, as well as relevant authorities when required by applicable data protection laws, about the breach as soon as possible.
We use in a regular basis the following data processors:
Data processor name: Hostaan Oy
Privacy documentation: https://www.hostaan.fi/tietosuojaseloste/
We may occasionally use the following data processor:
Data processor name: Google Ireland Limited
Privacy documentation: https://policies.google.com/privacy
In case you consider our processing of Personal Data to be inconsistent with the applicable data protection laws, a complaint may be lodged with the local supervisory authority for data protection.
In Finland, the local supervisory authority is the Data Protection Ombudsman which contact details you find down below. In case you reside in other EU member state you may contact your local supervisory authority. You may find an exhaustive list of supervisory authorities as well as their contact details from the European Data Protection Board website.
Data Protection Ombudsman
Lintulahdenkuja 4
FI-00530 Helsinki Finland
Tel. +358 29 566 6700
tietosuoja@om.fi