EU GDPR (2016/679) & Tietosuojalaki (1050/2018)
Privacy Policy & Member Register Notice
Principles governing personal data processing and statutory member records for Makan Ry.
Makan Ry · Y-tunnus: 3657266-8
Rekisterinpitäjä: Makan Ry (Vantaa)
# PRIVACY POLICY & MEMBER REGISTER NOTICE (GDPR)
In accordance with the EU General Data Protection Regulation (2016/679) and the Finnish Data Protection Act (1050/2018).
Updated: 29 September 2026
---
### 1. Data Controller
**Makan Ry**
Business ID (Y-tunnus): 3657266-8
Registered Office: Vantaa, Finland
Postal Address: Normannikuja 6, 01200 Vantaa, Finland
Email: [email protected]
### 2. Contact Person for Register Matters
Chairperson of the Board: Leyla Sadat Ghazanfari
Email: [email protected]
### 3. Name of the Register
Makan Ry Official Member Register and Membership Application Register.
### 4. Legal Basis and Purpose of Processing Personal Data
The legal basis for processing personal data is Section 11 of the Finnish Associations Act (503/1989), which requires the board of an association to maintain a list of its members. The purposes of processing are:
- Processing membership applications and board approval procedures;
- Maintaining the legally required register of members (full name and municipality of residence);
- Internal association communications, statutory notices, and General Assembly invitations;
- Verifying active membership and voting rights during association meetings.
Data is never used for automated profiling, credit assessments, or commercial marketing.
### 5. Data Content of the Register
The following information is recorded:
- First Name and Last Name
- Street Address, Postal Code, and City/Municipality of residence (statutory requirement under Finnish Associations Act)
- Email Address
- Telephone Number
- Date of application, membership approval date, and membership status
- Record of consent to association purposes and data processing terms
### 6. Regular Data Sources
Personal data is received directly from the applicant via the website membership application form (/join) or direct written application.
### 7. Disclosure of Data and Transfers Outside EU/EEA
All personal data is kept strictly confidential. Data is never sold, leased, or disclosed to third parties for commercial or advertising purposes. Personal data is not transferred outside the European Union (EU) or the European Economic Area (EEA).
### 8. Data Retention Period
Data of approved members is retained for the duration of active membership. Following resignation or expulsion, records are removed within a reasonable timeframe, subject to statutory accounting or archival requirements under Finnish law. Unsuccessful application records are purged within 12 months.
### 9. Data Security Principles
Electronically stored data is hosted on secured server infrastructure with encrypted data stores and restricted access. Only authorized members of the Board of Directors with operational duties have access to the member register.
### 10. Rights of the Data Subject
Under the EU GDPR, data subjects have the right to:
- Request access to and inspection of their personal data;
- Request correction of inaccurate or incomplete records;
- Request erasure of personal data upon resigning from the association;
- Lodge a complaint with the competent supervisory authority (Office of the Data Protection Ombudsman, www.tietosuoja.fi) if they consider that the processing violates data protection legislation.
All requests should be submitted in writing to: [email protected].