EU GDPR (2016/679) & Tietosuojalaki (1050/2018)

Privacy Policy & Member Register Notice

Principles governing personal data processing and statutory member records for Makan Ry.

Makan Ry · Y-tunnus: 3657266-8
Rekisterinpitäjä: Makan Ry (Vantaa)
# PRIVACY POLICY & MEMBER REGISTER NOTICE (GDPR) In accordance with the EU General Data Protection Regulation (2016/679) and the Finnish Data Protection Act (1050/2018). Updated: 29 September 2026 --- ### 1. Data Controller **Makan Ry** Business ID (Y-tunnus): 3657266-8 Registered Office: Vantaa, Finland Postal Address: Normannikuja 6, 01200 Vantaa, Finland Email: [email protected] ### 2. Contact Person for Register Matters Chairperson of the Board: Leyla Sadat Ghazanfari Email: [email protected] ### 3. Name of the Register Makan Ry Official Member Register and Membership Application Register. ### 4. Legal Basis and Purpose of Processing Personal Data The legal basis for processing personal data is Section 11 of the Finnish Associations Act (503/1989), which requires the board of an association to maintain a list of its members. The purposes of processing are: - Processing membership applications and board approval procedures; - Maintaining the legally required register of members (full name and municipality of residence); - Internal association communications, statutory notices, and General Assembly invitations; - Verifying active membership and voting rights during association meetings. Data is never used for automated profiling, credit assessments, or commercial marketing. ### 5. Data Content of the Register The following information is recorded: - First Name and Last Name - Street Address, Postal Code, and City/Municipality of residence (statutory requirement under Finnish Associations Act) - Email Address - Telephone Number - Date of application, membership approval date, and membership status - Record of consent to association purposes and data processing terms ### 6. Regular Data Sources Personal data is received directly from the applicant via the website membership application form (/join) or direct written application. ### 7. Disclosure of Data and Transfers Outside EU/EEA All personal data is kept strictly confidential. Data is never sold, leased, or disclosed to third parties for commercial or advertising purposes. Personal data is not transferred outside the European Union (EU) or the European Economic Area (EEA). ### 8. Data Retention Period Data of approved members is retained for the duration of active membership. Following resignation or expulsion, records are removed within a reasonable timeframe, subject to statutory accounting or archival requirements under Finnish law. Unsuccessful application records are purged within 12 months. ### 9. Data Security Principles Electronically stored data is hosted on secured server infrastructure with encrypted data stores and restricted access. Only authorized members of the Board of Directors with operational duties have access to the member register. ### 10. Rights of the Data Subject Under the EU GDPR, data subjects have the right to: - Request access to and inspection of their personal data; - Request correction of inaccurate or incomplete records; - Request erasure of personal data upon resigning from the association; - Lodge a complaint with the competent supervisory authority (Office of the Data Protection Ombudsman, www.tietosuoja.fi) if they consider that the processing violates data protection legislation. All requests should be submitted in writing to: [email protected].