Updated 19th September 2026
1. Controller
Oksidia Oy, Business ID 2452164-4 (hereinafter “the controller”) Viipurintie 4 13200 Hämeenlinna, Finland tel. +358 50 565 9403 email: info@oksidia.fi
2. Name of the register
Oksidia Oy’s partner and stakeholder register
3. Purpose of and legal basis for processing personal data
Personal data is processed for communication and the sharing of information between the controller and the people belonging to its stakeholder groups. Partners’ personal data is processed in order to carry out, maintain, manage, and develop the cooperation between the controller and its partners.
The processing of personal data is based on:
The processing of personal data in connection with the customer relationship, including the processing of customers’ personal data for marketing purposes, is described in our customer register privacy policy.
4. Data contained in the register
The content of the register consists, in whole or in part, of the following categories of data: first name, surname, company or organisation name, job title or role, telephone number, email address, and other information provided voluntarily by the person.
5. Sources of data
Personal data is collected from the person themselves, from the organisation they represent, or from publicly available sources — in particular the websites of the organisations concerned.
Where personal data has been collected from a publicly available source rather than from the person directly, we inform the person of this when we first contact them, and provide a link to this privacy policy.
6. Disclosure and transfer of data
Personal data may be transferred to the controller’s data processors, subject to confidentiality obligations and a binding data processing agreement as required by legislation. Personal data may also be disclosed, within the limits permitted and required by the legislation in force at the relevant time, to parties that have a legal right to receive personal data.
The controller uses processors located outside the European Economic Area, including providers of email marketing services and work management services. Personal data is therefore transferred outside the EEA as part of the controller’s normal operations. These transfers are made on the basis of the standard contractual clauses approved by the European Commission, or another transfer mechanism permitted by data protection legislation. The controller will provide a copy of the safeguards used at the data subject’s request, in accordance with section 10.
7. Retention period for personal data
Personal data is retained for as long as its processing is necessary for the purposes for which it was collected.
The controller reviews the register annually. Personal data relating to a person with whom there has been no interaction for three years is deleted or anonymised. The three-year period runs from the last meaningful interaction — such as an email exchange, a meeting, a contract, or a support conversation — rather than from the date the record was created.
Personal data relating to a person connected with a current agreement or an ongoing working relationship is retained for the duration of that relationship regardless of the above.
Where a person has asked not to receive communications from the controller, their contact details are retained for the purpose of honouring that request and ensuring that they are not contacted again.
Personal data is deleted from the register or anonymised as soon as there is no longer a need or a basis for processing it, and it is no longer necessary for the controller in order to fulfil an obligation imposed by law, by decree, or by another official source.
8. Automated decision-making and profiling
Personal data in this register is not used for automated decision-making or profiling.
9. Protection of the register
The controller maintains an information security management system certified to ISO 27001:2022, subject to regular internal review and periodic external audit.
Access to the register is limited to those Oksidia personnel whose role requires it, using individual accounts protected by multi-factor authentication. Access rights are reviewed twice a year. Personnel who process personal data are bound by confidentiality obligations and complete information security training annually.
Third-party services used to process personal data are subject to a documented security assessment before they are adopted. Suspected information security incidents are handled under a documented incident management process overseen by Oksidia’s ISMS board.
10. Contact person
Tuomas Oksanen, CEO tel. +358 50 565 9403 tuomas@oksidia.fi
The data subject should contact the person named above in all matters relating to the processing of personal data and in situations relating to the exercise of the data subject’s rights.
11. The data subject’s rights
Requests relating to the rights described below can be made by email or by post to the contact person named in section 10. We may ask for additional information in order to confirm your identity before acting on a request. We respond to requests within one month; if a request is complex, we may extend this period and will inform you if we do so.
Right of access to your own personal data
The data subject has the right to obtain confirmation from the controller as to whether personal data concerning them is being processed, and to check what personal data concerning them has been stored in the register. The data subject also has the right to receive a copy of the personal data being processed. A request for access may be refused on the grounds laid down in law.
Right to require rectification or erasure of personal data, or restriction of processing
The controller rectifies, deletes, or supplements personal data in the register that is incorrect, unnecessary, incomplete, or out of date in relation to the purpose of the processing, either on its own initiative or at the data subject’s request. The data subject also has the right to require the controller to restrict the processing of their personal data — for example, where the data subject is awaiting the controller’s response to a request to rectify or erase their data.
Right to object to the processing of personal data
The data subject has the right to object to processing operations that the controller carries out on their personal data, to the extent that the basis for processing is the controller’s legitimate interest. The data subject has the right to prohibit the processing and disclosure of personal data concerning them for the purposes of direct advertising, distance selling, and other direct marketing, as well as market and opinion research.
A person who no longer wishes to receive communications from the controller may say so at any time, either by using the unsubscribe link included in our messages or by contacting the person named in section 10.
Right to data portability
To the extent that the data subject has themselves provided data to the register that is processed in order to perform the agreement between the controller and the data subject, the data subject has the right to receive that data in a structured, commonly used, and machine-readable format, and the right to transfer that data to another controller (where this is technically possible).
Right to lodge a complaint with a supervisory authority
The data subject has the right to lodge a complaint with the competent supervisory authority if the controller has not complied with applicable data protection rules in its operations. In Finland, the supervisory authority is the Data Protection Ombudsman (Tietosuojavaltuutettu), whose contact details can be found at https://tietosuoja.fi/en/home. A data subject may also lodge a complaint with the supervisory authority of the EU member state in which they live or work.