Privacy statement
Privacy Notice and Register Description under the Personal Data Act
This privacy notice describes how Helsinki International Film Festival – Rakkautta & Anarkiaa ry (“Controller,” “we”), in cooperation with Eventio Oy (“Data Processor” or “Eventio”), process the personal data of their customers and online service users (“Registered Person”) and how Registered Persons can influence the processing of their personal data. Personal data refers to any information by which an individual can be directly or indirectly identified. The Controller and the Data Processor comply with applicable data protection legislation in their operations.
Controller
Helsinki International Film Festival – Rakkautta & Anarkiaa/ Love & Anarchy ry (1516764-7)
Bulevardi 5 A 12 00120 Helsinki
info@hiff.fi
hiff.fi
Contact person
Executive Producer
Claire Delhom
info(at)hiff.fi
Data Processor
Eventio Oy (Business ID 1925337-4)
Tierankatu 4 B
20520 Turku
asiakaspalvelu@eventio.com
Collected Personal Data
The Controller and Eventio process personal data only to the extent necessary for the purposes described in this privacy notice. The personal data collected and the scope of their processing vary depending on the relationship between the Controller and the Registered Person, the consents given, and the privacy settings of the browser used by the Registered Person.
Customer and Participant Data
Data is collected from the Registered Person when they make purchases or reservations in the online service, register for an event, sign up for the online service, or join, for example, a marketing list. Of the categories of personal data listed below, only those necessary at any given time are collected. Some of the data may be optional.
- Basic information, such as name
- Contact information, such as postal address, email address, telephone number
- Detailed personal information, such as date of birth, gender, municipality of residence, profession
- Consent and opt-out data, such as marketing consent or publication ban
- Detailed information related to event participation, such as participant groups, background information, or choices related to event participation
- Identifiers and validity information for customer cards, e.g., membership cards or loyalty cards
- Authentication information, such as encrypted username and password data or other similar identifiers
- Any additional information provided by the Registered Person
- Other information required for the use of services
In certain situations, the data may be provided by a person authorised by the Registered Person instead of the Registered Person themselves, for example, the contact person of a group.
Order Data
Order data is collected when the Registered Person makes purchases, reservations, or registrations via the online service or by email, phone, or in person.
- Source data of the order, e.g., how the order was placed
- Desired payment and delivery method, as well as information about completed payments
- Order content and products, including any modifications and cancellations
- Additional information related to order processing, such as invoicing information or processing history
Information Related to Event Visits
Visit-related data may be collected during or after the Registered Person’s visit to an event. Collected data includes, for example:
- Information related to the time of the visit, such as arrival and departure times at the event
- Movement-related data, such as ticket checkpoint or visits to different service points
- Information related to developing customer service, such as feedback given during the event
Online Service Usage Data
Data is collected about the use of online services when the Registered Person uses the Eventio online service provided to the Controller. Collected data includes, for example:
- Device or application data, such as browser version, device type, screen size, and IP address
- Information about the use of online services, such as page load data, time spent in the service, and navigation within the service
Users of online services may be identified, for example, based on social media integrations or identifiers contained in email messages.
Data is collected when:
- Purchasing/reserving tickets
- Subscribing to an electronic newsletter
- From the Eventio customer register of a collaborative partner — only customers of events organised by the Controller
- Using cookies or similar technologies
Use of Third Parties
Third parties do not have an independent right to use the data they receive from us beyond the scope of the assignment. We ensure that all our service providers comply with data protection legislation.
The Controller uses Eventio’s services to implement ticket sales.
We use Creamailer for sending newsletters and bulletins, where we collect customers’ email addresses. Creamailer is a data processor of the personal data register maintained by the Controller.
Accreditation for the festival, registration for events, recruitment, and responding to surveys take place through Airtable. Airtable is a data processor of the personal data register maintained by the Controller.
Purposes of Processing Personal Data and Legal Basis
The Controller uses the collected personal data for various measures necessary for managing the customer relationship, such as organising the event properly and safely, delivering ordered products or services, and providing customer service and other customer support. The collected data may also be used for customer communication and maintaining the customer relationship. The processing of personal data is based on the contract between the Registered Person and the Controller for the delivery of a product or service (such as a ticket or merchandise order) and on the legitimate interest to process data arising from a measure forming a customer or employment relationship (such as registering for an event).
The Controller may use the collected personal data for marketing and advertising and other commercial purposes, provided the Registered Person has given consent. The processing of personal data for commercial purposes is based, with regard to electronic direct marketing, on the Registered Person’s consent.
The Controller may use the collected personal data for the development of products and services and for improving the service offering. Development and improvement measures include, for example, product recommendations or personalisation of communications. The processing of data is then based on the Controller’s legitimate interest to utilise the collected data for the benefit of the Registered Persons.
Sharing and Disclosure of Personal Data
The Controller and Eventio have agreed between themselves on the processing of personal data in the manner described in this privacy notice and in compliance with applicable data protection legislation. Eventio acts as a data processor and solely on behalf of the Controller. Eventio does not disclose data to any third party unless the Controller expressly instructs it to do so in writing. An exception to this is some data related to the use of online services, the disclosure of which the online service user may prevent using the methods described in the Cookie Policy.
In addition to Eventio, the Controller may use other third-party services for processing personal data. In such cases, the Controller ensures the lawful processing of personal data through contractual arrangements and written instructions given to the third party.
Furthermore, the Controller or Eventio may disclose personal data to third parties if applicable legislation so requires or if it is necessary to protect the rights or safety of the Controller, Eventio, or the Registered Person.
Transfer of Personal Data Outside the EU/EEA Area
Personal data may be transferred outside the EU, as data is stored and processed almost exclusively in electronic form, and some of the service providers we use for data storage and processing may be located in countries outside the EU. We always ensure that the transfer of personal data outside the EU is carried out using adequate safeguards required by data protection legislation. Primary options include transfer to a country recognised by the European Commission as having adequate data protection, transfer to an EU-US Privacy Shield-certified company (recipients located in the United States), or the use of EU Standard Contractual Clauses.
Use of Cookies
To improve the user experience of our online services, as well as to monitor and facilitate usage, we use cookies. Cookies allow short text-based data to be stored in the user’s browser for later use.
We use the Google Analytics tool on our website. More information about Google Analytics’ data protection is available in the Google Analytics privacy notice.
Collection and Use of Location Data
The Controller or Eventio generally do not collect or use precise location data of Registered Persons.
However, when using online services, the user’s IP address is stored, which can be associated with a geographical location, generally at the municipality level. Additionally, for example, in connection with the use of event-time services, data that can be linked to a specific location is stored, such as a specific entrance at a venue during ticket inspection.
Retention of Personal Data
The Controller and Eventio retain personal data for as long as is necessary to fulfill the purpose for which the data was collected. However, prevailing accounting or other mandatory legislation may require data to be retained for a longer period. In such cases, the retention periods determined by legislation are followed.
Data collected from the use of online services is retained for approximately 12 months in a form from which an individual user can be identified.
The Registered Person’s basic information, contact information, consent and opt-out data, detailed personal information, and general information about the Registered Person’s participation in a specific event or information about the Registered Person’s order are retained for generally 36 months from the date the Registered Person last interacted with the Controller or Eventio.
Detailed participant and registration data related to a specific event are retained for generally 36 months after the conclusion of the event.
Order-related data is retained for generally 36 months after the conclusion of the event or, if the order is not related to a specific event, after the date of the order. Data on cancelled orders is retained for generally 36 months after the event or cancellation date.
Payment transaction data, such as receipt copies, is retained in accordance with legal requirements.
Rights and Opportunities for Influence of the Registered Person
The Registered Person has the right to access their own personal data and the right to verify and correct personal data concerning them. Additionally, the Registered Person has the right to request the deletion of personal data concerning them, to the extent possible within the framework of other legislation. The Registered Person has the right to transfer their personal data to another Controller.
The Registered Person has the right to object to direct marketing and to oppose the processing of their personal data for direct marketing purposes.
Requests regarding the exercise of these rights shall be submitted to the Controller using the contact information provided in this privacy notice.
Information Security
The Controller and Eventio ensure the secure processing of personal data through appropriate physical and technical security measures to protect data from loss, destruction, misuse, and unauthorised access and disclosure. The Controller strives for secure processing of personal data, for example, by restricting access to personal data and ensuring that employees and subcontractors use personal data in accordance with given instructions, agreements, and legislation.