Version 05072023
Table of Contents
Tamhockey Oy (hereinafter referred to as the “Data Controller”)
Business ID: 153920-6
Address: Kansikatu 1 T 3, 2nd floor, 33100 Tampere, Finland
Telephone: +358 20 7457 500
Email: tappara@tappara.fi
Contact person for data protection matters:
Aki Hautamäki (aki.hautamaki@tappara.fi)
Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, personal identity code, location data, online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
Customers means, among the data subjects, consumers and contact persons of companies and other entities (hereinafter referred to as “companies”) with which the Data Controller has a customer relationship.
Potential customers means, among the data subjects, consumers and contact persons of companies with which the Data Controller seeks to establish a customer relationship.
Members means consumers who are members of the Data Controller's business activities, such as members of a fan club maintained by the Data Controller or players in non-professional teams.
Stakeholders means consumers and contact persons of companies with whom the Data Controller has a cooperative relationship (for example, representatives of companies providing services to the Data Controller) or another type of connection (for example, media representatives involved in communications activities or public decision-makers in connection with stakeholder relations).
The Data Controller processes the personal data of data subjects for the following purposes (one or more simultaneously):
Managing, analysing and developing customer, membership and stakeholder relationships
The Data Controller may use your personal data to manage, analyse and develop a customer, membership or stakeholder relationship established directly with you or with the company you represent.
Providing products and services
The Data Controller may use your personal data to provide products and services if, for example, you or the company you represent has purchased a product or service from us, used our digital services, subscribed to our newsletter, or participated in our training sessions or other events. Personal data is used to fulfil the rights and obligations arising from an agreement or other commitment between the Data Controller and the customer.
Customer and member communications
The Data Controller may use your personal data for customer and member communications, for example, to send you notifications concerning products and services, inform you of changes to services, and request feedback on products and services.
Marketing
The Data Controller may contact you to inform you about new products, services or benefits. The Data Controller may use personal data to tailor its offering and provide relevant content. This may mean, for example, that we provide recommendations or display personalised content and advertisements on our own services and third-party services.
Developing products and services
The Data Controller may use your personal data to develop its products and services.
The legal bases for processing personal data are the following provisions of Article 6 of the EU General Data Protection Regulation (GDPR):
a) you have given your consent to the processing of your personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract;
c) processing is necessary for compliance with a legal obligation to which the Data Controller is subject; and
d) processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms requiring protection of personal data.
The Data Controller processes your data in order to perform a contract with you or with the company you represent (e.g. organising a match related to a purchased ticket, fulfilling an agreement concerning participation in non-professional sports, processing an online store purchase, providing a digital service, or implementing a sponsorship cooperation agreement).
The Data Controller has legitimate interests related to conducting its business, such as the right to promote the sale of its products and services through marketing and sales activities. On the basis of its legitimate interest, the Data Controller may conduct direct marketing and sales using your contact details, including potentially processing personal data for profiling purposes as described in Section 6.
Other legitimate interests of the Data Controller that may constitute a legal basis for processing personal data include providing advice and other customer service to non-customers, further developing the business, and investigating potential misuse or abuse.
If the processing of personal data is not based on the performance of a contract or a legitimate interest, the Data Controller may request your consent to other forms of processing of your personal data.
The Data Controller may also process your personal data where required by law, for example, on the basis of statutory retention obligations under the Accounting Act.
The personal data collected by the Data Controller may include, among other things, the following types of information and any changes made to such information:
4.1 Basic information concerning all data subjects
4.2 Additional information concerning minor data subjects
4.3 Additional information concerning representatives of companies
4.4 Information concerning data subjects who have purchased the Data Controller's products or services, provided feedback on them and/or submitted a complaint
4.5 Information concerning data subjects who have participated in the Data Controller's events
4.6 Information concerning customers of the Data Controller's online services
Most of the information is obtained directly from you or, in the case of a minor, from their guardian, when the customer, membership or stakeholder relationship is established and during the course of that relationship, as well as from the applications and programmes through which you use our products and services.
The Data Controller also obtains personal data and updates to such data from public authorities, organisations and companies providing credit and personal data acquisition and updating services, as well as from public directories and other publicly available sources of information, such as company websites and social media channels.
The Data Controller may also obtain personal data concerning representatives of companies from their colleagues. For example, the primary contact person of a company or other entity may provide the Data Controller with personal data concerning other persons involved in the use of the Data Controller's products and services.
Profiling within the meaning of the EU General Data Protection Regulation means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
At present, we do not carry out profiling as described above. We may, however, otherwise analyse and utilise personal data contained in our registers and combine it with information obtained from third parties.
The Data Controller does not provide, sell or otherwise disclose your personal data to external third parties unless otherwise stated below.
The Data Controller may disclose your personal data to third parties that provide services to the Data Controller. Such services may include, for example, customer service, software services, research activities, marketing and event production. The Data Controller may disclose your personal data for the purpose of collecting payments for products and services and may, for example, transfer or sell unpaid invoices to third parties providing debt collection services.
The protection of your personal data is important to the Data Controller. Therefore, the Data Controller does not permit such parties to use the data for any purpose other than providing the relevant services and requires such parties to protect users' personal data in accordance with this Privacy Notice and applicable legislation.
The Data Controller shares your personal data with partners with whom the Data Controller jointly manages and implements projects.
The Data Controller may disclose your personal data to carefully selected third parties for joint or independent direct marketing purposes. Data may be disclosed for such purposes only where the intended use by the third party is not incompatible with the purposes defined in this Privacy Notice.
At its discretion, the Data Controller may disclose the personal data of participants in the Data Controller's events to other participants in the relevant event where this is appropriate due to the nature of the event (for example, a match event organised for representatives of companies).
The Data Controller may disclose your personal data in connection with a business transaction or other corporate restructuring, or where a service is transferred to another service provider. The Data Controller may also disclose your personal data pursuant to an order issued by a court or a corresponding authority.
When providing its services, the Data Controller may use resources and servers located in different parts of the world. The Data Controller may therefore transfer your personal data outside the country in which the services are used and potentially also to countries outside the EU whose data protection legislation differs from that applicable within the EU.
In such cases, the Data Controller ensures that there is a legal basis for the transfer and that users' personal data is protected, for example, by using, where necessary, standard contractual clauses approved by the relevant authorities and requiring appropriate technical and other data protection measures to be implemented.
The Data Controller processes your personal data in this register for as long as the Data Controller has a valid basis for processing the data as described in Section 3 of this Privacy Notice, and for a reasonable period thereafter.
In addition, the Data Controller may retain and process your personal data for longer than the period stated above in order to fulfil accounting obligations, where required by other legislation, or for the purpose of establishing, exercising or defending a legal claim or resolving a corresponding dispute.
The retention period for the personal data of different categories of data subjects is determined as follows:
Consumer customers
The Data Controller may process your personal data for the duration of your customer relationship and until the end of the third year following the year in which the customer relationship ended.
After this, the Data Controller may transfer the necessary personal data to its marketing register and process you again as a potential customer.
Representatives of corporate customers
The Data Controller may process your personal data for as long as you represent a corporate customer of the Data Controller and until the end of the third year following the year in which the customer relationship ended.
After this, the Data Controller may transfer the necessary personal data to its marketing register and process you again as a representative of a potential corporate customer.
Consumer members
The Data Controller may process your personal data for the duration of your membership relationship and until the end of the third year following the year in which the membership relationship ended.
Potential consumer customers and representatives of potential corporate customers
The Data Controller may process your personal data indefinitely until you become a customer or until you request that your data be deleted from the Data Controller's marketing register.
Stakeholders
The Data Controller may process your personal data for as long as you are a member of a stakeholder group, such as while you represent a partner or a media organisation of the Data Controller.
In order for the Data Controller to fulfil its contractual obligations arising from its relationship with you, the Data Controller must obtain and process personal data concerning you.
Without the necessary personal data, we cannot provide you with those products and services for which the processing of personal data is necessary.
As a data subject, you have various rights and means of influencing the processing of your personal data. As a general rule, we will respond to your request within one month.
Please contact the contact person mentioned in Section 1 of this Privacy Notice in order to exercise your rights.
Your rights include the following:
a) Right of access to personal data
You have the right to obtain access to the personal data collected about you. In practice, this means that, following an appropriate and verified request, we will provide you with a report of the personal data concerning you that has been collected in the register.
b) Right to request rectification of personal data
You have the right to request the rectification or correction of personal data collected about you. If you notice any errors or omissions in your data, you may request that we correct the information.
c) Right to request erasure of personal data
You have the right to request the erasure of personal data collected about you. We are required to delete the personal data you have requested from our register if one of the following grounds applies and there is no obligation under other legislation or an official order to retain the data:
d) Right to request restriction of processing
You have the right to request that the Data Controller restrict the processing of your personal data if:
e) Right to object to the processing of personal data
Where the Data Controller processes your data on the basis of a legitimate interest, you have the right to object to the processing of your personal data on grounds relating to your particular situation.
Everyone whose personal data is included in the registers covered by this Privacy Notice has the right to object to the processing of their personal data for direct marketing purposes.
f) Right to data portability
Where the automated processing of your personal data is based on your consent or a contract, you have the right to receive the personal data you have provided to the Data Controller in a structured, commonly used and machine-readable format and to transmit that data to another data controller.
g) Right to withdraw consent
If all or part of your personal data is processed in this register on the basis of your consent, you have the right to withdraw your consent.
h) Right to lodge a complaint with a supervisory authority
If a potential dispute concerning the processing of your personal data cannot be resolved amicably between you and the Data Controller, you have the right to refer the matter to the competent data protection supervisory authority.
We are a Finnish limited liability company operating in Finland.
This register and the processing of the personal data contained in it are governed by Finnish law and directly applicable EU legislation, such as the EU General Data Protection Regulation (GDPR).
At www.tappara.fi, you can watch video clips from YouTube through YouTube API Services, which are subject to YouTube's Terms of Service.
By watching video clips on our website, you accept YouTube's Terms of Service.
We do not collect personal data about you when you visit our website or watch our video clips. YouTube follows Google's Privacy Policy.
We continuously develop our business, which may also involve changes to the processing of personal data. Where necessary, we will update this Privacy Notice to reflect changes in our practices. Changes may also be based on amendments to applicable legislation.
We recommend that you review the contents of this Privacy Notice regularly.
If we begin to process your personal data for a purpose other than the purpose for which your personal data was originally collected, we will inform you of this and provide you with the updated Privacy Notice before carrying out such further processing.
For other changes, we will notify you on our website that the Privacy Notice has been updated.