Privacy policy

13.03.2025
Kutikuti ry
Veturitallinkuja 5
00520 Helsinki

Business ID: 2132211-3

Privacy, Terms of Use, and Cookies

This privacy policy applies to the website at kutikuti.com.

Kutikuti ry is responsible for this website and strives to ensure the rights of data subjects in accordance with current legislation. This privacy policy is in compliance with the Data Protection Act and the EU General Data Protection Regulation (GDPR). Efforts have been made to follow the guidelines from the Data Protection Ombudsman’s office, the table of information requirements published by the office, and the guidelines of the Article 29 Working Party.

Collection of Personal Data

We follow the EU data protection regulation (GDPR) which came into effect in May 2016 and has been applicable nationally since May 25, 2018. We process only those personal data for which the processing is justified based on the user relationship, contracts, use of the website, legal obligations, or the consent of the individual.

Online Forms

Our website uses a comment form. The personal data collected through this form is always based on the consent of the data subject. Using the forms is voluntary.

When users leave comments on the site, we collect the information provided in the comment form, along with the user’s IP address and browser version information to help with spam detection.

When visitors leave comments on this site, we collect the data that is visible in the comment fields, as well as the IP address and browser version details. An anonymized hash of the email address may be sent to the Gravatar service to determine whether the commenter is a user of the service. The privacy policy of the Gravatar service can be found at Automattic Privacy.

Kuti Magazine Subscription Register

The register is primarily located on Kutikuti’s WordPress site. The access to this register is restricted to the board members and the producer of the association. Data protection is based primarily on the diligence of the data processor and compliance with the personal data protection law.

Member Register

The member register is a separate system located on another server. Membership applications are made informally.

Purpose of Processing

Inquiries sent through the contact form are forwarded to our email and are processed similarly to other emails received by the organization. We use the information sent through the contact form for purposes such as developing our services and assisting the inquirer, depending on the content of the inquiry.

Contact Register

We store personal data related to membership and all communications on the Brevo platform for those on our mailing lists.

Legal Basis for Processing

Online Forms
The legal basis for processing personal data through online forms:

  • The data subject has given consent to the processing of personal data for one or more specific purposes (Article 6, paragraph 1a of the GDPR).

Member Register
The legal basis for processing personal data in the member register:

  • The data subject has given consent to the processing of personal data for one or more specific purposes (Article 6, paragraph 1a of the GDPR).

Retention of Personal Data

Online Forms
We retain the personal data collected through online forms for as long as necessary for the user relationship and provision of services. Submissions from the contact form are not stored permanently on the website server. Emails forwarded to us are stored like any other organizational emails.

Member Register
We retain members’ personal data in the member register for as long as required by law and as necessary for the membership relationship.

Recipients of Personal Data

Personal data is not disclosed to third parties without a specific legal basis.

Personal data is processed by the employees of the organization responsible for the website as part of their duties. Additionally, personal data is processed by system suppliers and service providers whose services the organization uses to provide its own services, and for whom data processing agreements are in place.

Automated Decision-Making

We do not use personal data for automated decision-making. We do not use personal data for profiling.

Rights of the Data Subject

As a data subject, you have the following rights:

  • The right to know if we are processing your personal data.
  • The right to know for what purposes and how we are processing your personal data.
  • The right to know if automated decision-making exists, including its logic and consequences.
  • The right to access your personal data.
  • The right to rectify or delete your personal data.
  • The right to restrict the processing of your personal data.
  • The right to object to the processing of your personal data.
  • The right to transfer your personal data to another system.
  • The right to withdraw consent to the processing of your personal data.
  • The right to lodge a complaint with the supervisory authority.

Data Protection Officer Contact Information

If you have any questions about data protection or wish to exercise your rights as a data subject, please first contact Kutikuti at .

Supervisory Authority

If you believe that personal data is being processed in violation of applicable law, you have the right to file a complaint with the supervisory authority (external).

Data Protection Commissioner Contact Information
Data Protection Commissioner’s Office
Website: Tietosuoja.fi
Email:
Phone: 029 566 6700 


Subscriber Register and Privacy Policy

13.03.2025
Data Controller:
Kutikuti ry
Veturitallinkuja 5
00520 Helsinki

Business ID: 2132211-3

We collect personal data to manage customer relationships.
The legal basis for processing personal data is the contract between the customer and the association, and the resulting legal obligations. Providing personal data is a condition for entering into the contract.
You cannot subscribe to the magazine without providing personal data. The legal basis for processing personal data is consent.
We do not perform profiling or automated decisions based on your data.

Use of Third Parties

If you order the magazine through the online store, the WooCommerce platform (WooCommerce Privacy Policy) and the Stripe payment system (Stripe Privacy Policy) are used during the ordering process.

Recipients of your personal data include:

  • Our association and its employees.
  • The payment processor who receives your payment.
  • The delivery company that delivers the item to you.
  • The auditor who checks our accounting.

We retain your personal data:

  • For five years in the online store.
  • For three years after the subscription ends in the subscriber register.
  • For seven years in the email archive.
  • For seven years in accounting records.

You have the following rights:

  • The right to check your personal data.
  • The right to rectify the data.
  • The right to restrict processing (e.g., you can opt out of marketing).
  • The right to object to processing.
  • The right to withdraw consent (e.g., you can withdraw consent for marketing).
  • The right to lodge a complaint with the supervisory authority.

Please note that your “right to be forgotten” only applies if we do not have legal obligations to continue processing your personal data.

Also, note the Brevo newsletter register and privacy policy if you subscribe to the Kutikuti newsletter together with the magazine order.


Brevo Newsletter Register and Privacy Policy

13.03.2025
Data Controller:
Kutikuti ry
Veturitallinkuja 5
00520 Helsinki

Business ID: 2132211-3

Register Name:
Kutikuti Newsletter

Basis for Keeping the Register and Purpose of Use:
The processing of personal data is based on the consent of the data subject, cooperation relationships, or similar grounds. The purpose of the Kutikuti newsletter register is to inform Kuti magazine subscribers, readers, and partners by email about content of the Kuti magazine, publications and events organized or participated by the association or its members.

Data in the Register:
The data in the register includes the subscriber’s email address, and possibly first and last name and address.
Read here what data Brevo collects and how Brevo processes it. https://www.brevo.com/legal/privacypolicy/

Data Sources:
The data is collected when the individual subscribes to the list (e.g., filling out the newsletter subscription form on Kutikuti’s website) or requests to be added (e.g., with a magazine subscription).

Disclosure of Data:
Kutikuti does not disclose the register data to third parties. Read here what data Brevo collects and how Brevo processes it. https://www.brevo.com/legal/privacypolicy/

Storage of Register Data and Protection of the Register:
The register is stored on the GDPR-compliant Brevo platform. The access to the register is limited to the Kutikuti board and producer. The protection of data relies primarily on the diligence of the data processor and compliance with the data protection law.

Correction and Deletion of Data:
Anyone who has provided their data can request the removal or correction of their data from the register. Brevo provides users the ability to unsubscribe from the newsletter.

Right of Inspection:
Under Section 26 of the Personal Data Act, a person has the right to inspect what data has been stored about them in the personal register. This can be done by contacting the register administrator.