Privacy Policy
This is Fuusiomedia Oy’s register and privacy policy statement prepared in accordance with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on 01 May 2023. Last amended on 07 June 2026.
1. Controller
Fuusiomedia Oy, Myllymäenkatu 7, 06100 PORVOO, FINLAND
2. Contact person responsible for the register
Mikko Sinkkonen, mikko@fuusiomedia.fi
3. Name of the register
The company’s customer register.
4. Legal basis and purpose of processing personal data
Under the EU General Data Protection Regulation, the legal basis for processing personal data is the legitimate interest of the controller (managing customer relationships and maintaining business operations), as well as the data subject’s consent when personal data is collected for marketing purposes or for targeting marketing activities.
The purpose of processing personal data is:
- ○ communication with customers
- ○ maintaining and managing customer relationships
- ○ providing and developing services
- ○ marketing and targeted advertising (e.g. Google Ads and Meta Ads)
- ○ invoicing and accounting
- ○ customer service and lead management
Cookies and similar technologies (e.g. analytics and advertising cookies) are used on the website to improve the user experience, analyse traffic, and target marketing activities.
The chatbot operating on the website (an AI-based conversational feature) may collect information voluntarily provided by the user, such as their name, email address, phone number, and the content of the message. The information collected through the chatbot is used for handling enquiries, providing customer service, and managing leads.
The data is not used for automated decision-making that produces legal effects concerning an individual or similarly significantly affects them.
5. Contents of the register
The information stored in the register includes:
○ person’s name
○ position
○ company/organisation
○ contact details (phone number, email address, address)
○ website addresses
○ social media usernames/profiles
○ information about ordered services and changes to them
○ billing information
○ messages and lead information submitted through chatbots or forms
○ other information related to the customer relationship
6. Regular sources of information
The information stored in the register is obtained from the customer, including:
○ website forms and chatbot
○ by email
○ by phone
○ from social media services
○ from contracts
○ from customer meetings
○ from enquiries received through advertising (e.g. Google and Meta).
7. Regular disclosures of information and transfer of data outside the EU or the EEA
The information is not regularly disclosed to other parties.
However, the data is processed by the following service providers:
○ Google (e.g. advertising and analytics)
○ Meta (advertising and targeting)
○ Zoho (CRM system, Zoho Bigin, EU-based servers)
Data may be transferred to and processed outside the EU or EEA when the service providers used (e.g. Google or Meta) process data within their global infrastructure. In such cases, appropriate safeguards required under the EU General Data Protection Regulation, such as Standard Contractual Clauses (SCCs), are used for the transfer of data.
Information may be published to the extent that this has been separately agreed with the customer.
8. Principles of register protection
Care is taken in the processing of the register, and information processed through information systems is appropriately protected.
Information systems are located in secure service environments, and access to data is restricted only to those individuals whose work requires it.
The use of the chatbot, CRM system, and other digital tools is protected through access controls, passwords, and appropriate technical and organisational security measures.
9. Right of access and right to request rectification of information
Every person registered in the register has the right to review the information stored about them and to request the correction of any inaccurate information or the completion of incomplete information. If a person wishes to review the data stored about them or request its correction, the request must be submitted in writing to the controller. The controller may, if necessary, request the person making the request to verify their identity. The controller will respond to the customer within the timeframe specified in the EU General Data Protection Regulation (as a rule, within one month).
10. Other rights related to the processing of personal data
A person registered in the register has the right to request the deletion of their personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be submitted in writing to the controller.
The controller may, if necessary, request the person making the request to verify their identity.
The controller will respond to the customer within the timeframe specified in the EU General Data Protection Regulation (as a rule, within one month).
Copyright © 2026 Fuusiomedia | All rights reserved. Privacy Policy | Myllymäenkatu 7 06100 Porvoo, Finland | FI33580128