Skip to main content

Privacy policy

Privacy policy for Aisti Sport ry's member, participant and partner register

Date drawn up: 12 May 2026

1. Data controller

Aisti Sport ry, Business ID: 2892331-7

Hagelstamintie 15 K c/o Miika Honkanen, 01520 Vantaa

Tel. 044 569 6298

2. Contact person for data protection matters, and contact details

Antti Latikka, membership lead

tel. 050 469 1600

3. Name of the register

Member, participant and partner register

4. Purpose of and basis for processing personal data

For members of the association, processing is based on Aisti Sport ry's legitimate interest, that is, membership of the association; for participants, it is based on registrations for a particular activity or event. The purpose of processing personal data is:

  • To maintain a list of members as required by the Associations Act
  • Managing membership matters, such as communications, keeping in touch, awards, competitive activity, administration of membership and participation fees, and disciplinary measures
  • Organising activities, events, and discussion and training sessions
  • Evaluating, developing, compiling statistics on and reporting on our activities
  • the prevention, detection, blocking and investigation of misuse, fraud and other offences.

For the relevant officials — such as team manager, instructor, coach, communications officer — processing is based on Aisti Sport ry's legitimate interest, that is, the cooperation agreed.

For partners, processing personal data is based on a contract or on Aisti Sport ry's legitimate interest in direct marketing, and the purpose of using personal data is managing and developing the cooperative relationship between Aisti Sport ry and its partners, and compiling statistics on activities.

5. Content of the register and categories of data subjects

The register contains the following personal data on the association's individual members:

  • The member's name and place of residence (the personal data required by section 11 of the Associations Act)
  • Data relating to membership, such as membership number, membership type, and data relating to membership fees and other invoices
  • Contact details (postal address, email address, phone number)
  • For a member who is a minor
    • The guardian's consents and the data relating to them, for example regarding membership, publication of data, participation in activities, and the use of photographs and services
    • The guardian's name and contact details (postal address, email address, phone number)
  • Photographs
  • Data on participation in membership activities, activities, tournaments, events, and discussion and training sessions
  • Other relevant personal data provided by the data subject themselves, and health data of benefit to an event or activity

The register contains the following personal data on officials:

  • Contact details (postal address, email address, phone number)
  • Data relating to invoices
  • Photographs
  • Data on participation in activities and in discussion and training sessions
  • User log data

The register contains the following personal data on decision-makers and contact people at companies and organisations:

  • name, job title, company, postal address, email address, phone number

6. Regular sources of data

Personal data is obtained as a rule from the data subject themselves — for example on joining as a member, or when registering for or taking part in activities during membership or cooperation. Members are obliged to notify Aisti Sport ry of any change to their details without being asked.

7. Disclosure of data and transfer of data outside the EU or EEA

Personal data is not disclosed onward as a matter of course, nor is it transferred outside the EU or EEA. Personal data may be disclosed to the authorities and to other parties specified in law, within the limits permitted and required by legislation.

The data controller uses the electronic services of an external service provider, by means of which the controller manages the member and partner register, invoicing, event registrations, attendance tracking and member communications.

8. Security principles and data retention period

The member register is stored in a cloud service protected by two-factor authentication. Only designated people have access to the register's data, to the extent their duties require.

The member register's data is retained for as long as it is needed to fulfil the purpose of the register, or as required by law.

  • An official's personal data is retained for 10 years after the end of their service
  • A member of the association's personal data is retained for 10 years after the member resigns, unless there is a separate reason to retain it
  • The personal data of decision-makers and contact people at companies and organisations is retained for as long as it is needed for invoicing, sponsorship or cooperation. Otherwise personal data is kept up to date.

9. Rights of the data subject

Requests concerning data subjects' rights should be sent to the address given in section 2. The data subject has the following rights:

Right of access, and the right to require correction and erasure of data

  • The data subject has the right to check the data stored about themselves in the member register, and the right to require the correction of incorrect data and the erasure of data.

Right to withdraw consent

  • The data subject has the right to withdraw at any time the consent they have given to the processing of their personal data. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

Right to object and right to restriction of processing

  • The data subject has the right to object to, or to request the restriction of, the processing of their data, and to request its transfer.

Right to lodge a complaint with the supervisory authority

  • The data subject has the right to lodge a complaint with the supervisory authority, in particular in the EU member state where they habitually reside or work, or where the alleged infringement took place, if the data subject considers that the processing of their personal data infringes the EU General Data Protection Regulation.