This is LECLOOP Oy's Privacy and Data Protection Statement in accordance with the EU General Data Protection Regulation (GDPR). Prepared on Dec 1, 2025. Last updated on Dec 5, 2025.
1. Personal data controller
LECLOOP Oy
00180, Helsinki Finland
Reg.No: 3534645-8
Contact in matters related to personal data files
Sari Sarome-Nykänen. +358 44 74 38 723, sari@lecloop.fi
2. Name of the Register
The Company’s customer register, marketing register, stakeholder register, and online service user register.
3. Purpose and Lawful Basis of Processing Personal Data
Personal data is processed in accordance with the EU General Data Protection Regulation (GDPR) on the following lawful bases:
· Consent – documented, freely given, specific, informed, and unambiguous.
· Legitimate interests of the controller, including customer relationship management, customer prospecting, maintaining and developing existing customer relationships, and marketing and service-related communication.
· Personal data is collected and processed in a fair, transparent, and lawful manner.
Personal data is not used for automated decision-making or profiling.
4. Personal Data Recorded in the Register
The register may contain the following categories of personal data:
· Name, position, company/organisation
· Business contact details (telephone number, e-mail address, postal address)
· Website addresses
· Ip address of the network connection
· Information on ordered services and any changes to them
· Billing information
· Other information related to the customer relationship and the services provided
Data Retention
Personal data is retained only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required by law.
Data may be anonymised after the retention need has ended.
Data may also be stored until the data subject requests its deletion, provided no legal obligation requires continued retention.
Accounting-related information is retained in accordance with the Finnish Accounting Act (1336/1997).
5. Rights of the Data Subject
Requests to exercise these rights must be submitted in writing to: sari@lecloop.fi.
The data subject has the following rights under the GDPR:
· Right of access – to obtain confirmation whether their data is processed and access the data.
· Right to rectification – to correct inaccurate or incomplete data.
· Right to object – to object to processing if the data subject believes their data is processed unlawfully.
· Right to restrict processing – to request limitation of processing in certain situations.
· Right to object to direct marketing – may be exercised at any time.
· Right to erasure (“right to be forgotten”) – to request deletion of data when no lawful basis for processing remains.
· Right to withdraw consent – when processing is based solely on consent.
· Right to lodge a complaint – with the Data Protection Authority if the data subject considers that data processing violates applicable legislation.
Supervisory authority contact: www.tietosuoja.fi/en/index/yhteystiedot.html
The controller may request verification of identity where necessary.
All requests will be answered within the timeframe required by the GDPR (as a rule, within one month).
Cookies and Technical Data
IP addresses and essential cookies required for the technical operation and security of the website are processed on the basis of legitimate interest, e.g. for ensuring information security and collecting statistical usage data.
Consent is requested separately for third-party cookies where required.
6. Regular Information Sources
Personal data is obtained directly from the data subject through website forms, e-mail, telephone, social media, contracts, customer meetings, and other situations where the customer provides information.
Contact details of representatives of companies and organisations may also be collected from public sources, such as websites, directory services, and other companies.
7. Regular Disclosure of Data and Transfers Outside the EU/EEA
Personal data is not regularly disclosed to external parties.
Customer information is not shared with entities outside LECLOOP except:
· When required by law, or
· When separately agreed with the customer in written.
Personal data is not transferred outside the EU or EEA. All data is stored and processed within the EU.
Data may be disclosed to authorities only where legally required, such as for accounting, taxation, or law-enforcement purposes.
8. Principles of Register Protection
The register is processed with due care, and personal data handled through information systems is appropriately protected.
When data is stored on internet servers, both physical and digital security are ensured.
Access to stored data, server credentials, and all information critical to data security is restricted to employees whose duties require such access and is handled confidentially.
9. Note on LECLOOP Oy practices related to EU AI Act’s transparency rules, applicable since 2 August 2026.
LECLOOP uses AI-supported tools selectively for research support, drafting, editing and content development. All published and client-facing material is reviewed by a human, and responsibility for the final content and professional judgement remains with LECLOOP.
Photos on the website are actual images taken by Photographer Petja Sirola Harati for portraits and landscape images Sari Sarome-Nykänen. AI generated images are being marked separately if utilised.
T&C 2026 57.85 KB