Privacy policy

This document is the Privacy policy of ENZALGU (“Enzalgu” or “we”). Read more about how we protect your privacy and personal data.

ENZALGU provides management consulting services, creative services and products and educational services (“Services” or “Products”) related to social responsibility, including but not limited to Diversity, Equity and Inclusion consulting and procurement services, art and education services. Any Service or Product may be provided by us individually or jointly with another business or partner. We comply with the applicable data protection legislation for the processing of personal data, including but not excluded to the General Data Protection Regulation of the European Union EU 2016/679 and the Data Protection Act 1050/2018.

This privacy policy (“Privacy Policy”) applies to the processing of personal data collected by ENZALGU in connection with the provision of the Services (as defined above) and other business operations, and where Enzalgu acts as the data controller. 

In this Privacy Policy, the word “User” or “you” refers to individuals as private customers as well as representatives of our customer organizations and business partners. This privacy policy may be updated to reflect changes in our data processing practices. We are happy to answer any questions you may have regarding the processing of your personal data or help if you choose to use you right as a data subject. In these cases please contact us in the addresses provided below.

This Policy applies as between you, the User of this Web Site and Enzalguthe owner and provider of this Web Site, and use of any and all Data collected by us in relation to your use of the Web Site and any Services or Systems therein.

0. Data Controller

Name: Enzalgu
Business ID: FI34315959
Address: PL 12, 01361 Vantaa Finland
https://enzalgu.fi

Contact person:
Mirva Haltia-Holmberg
mirva@enzalgu.fi

If there are any questions regarding this privacy policy you may contact us.

1. Definitions and Interpretation

In this Policy the following terms shall have the following meanings:
"Personal data'": in this Privacy policy we refer to the personal data we process as “Personal Data”. We collect and process primarily the data you provide us directly. This data includes but is not limited to: 1. Basic information, such as: your first name and last name, contact information, such as email, telephone number and address, other information you directly provide us at any stage, such as payment information, company name, company address and title in the company and survey data.
"Account": means collectively the personal information, Payment Information and credentials used by Users to access Material and / or any communications System on the Web Site;
"Content": means any text, graphics, images, audio, video, software, data compilations and any other form of information capable of being stored in a computer that appears on or forms part of this Web Site;
"Cookie": means a small text file placed on your computer by Enzalgu when you visit certain parts of this Web Site. This allows us to identify recurring visitors and to analyse their browsing habits within the Web Site.
"Data": means collectively all information that you submit to the Web Site. This includes, but is not limited to, Account details and information submitted using any of our Services or Systems;
"Enzalgu" means Enzalgu (FI34315959), PL 12, 01361 Vantaa, Finland
"Service": means collectively any online facilities, tools, services or information that Enzalgu makes available through the Web Site either now or in the future;
"System": means any online communications infrastructure that Enzalgu makes available through the Web Site either now or in the future. This includes, but is not limited to, web-based email, message boards, live chat facilities and email links;
"User" / "Users": means any third party that accesses the Web Site and is not employed by Emzalgu and acting in the course of their employment; and
"Website": means the website that you are currently using enzalgu.fi and any sub-domains of this site unless expressly excluded by their own terms and conditions.

2. Data Collected

Without limitation, any of the following Data may be collected:
  • 2.1 first name(s) and last name;
  • 2.2 date of birth;
  • 2.3 job title & profession;
  • 2.4 contact information such as email addresses and telephone numbers;
  • 2.5 demographic information such as post code, preferences and interests;
  • 2.6 financial information such as credit / debit card numbers;
  • 2.7 other information you directly provide us at any stage, such as company name, company address, survey data;
  • 2.8 IP address (automatically collected);
  • 2.9 web browser type and version (automatically collected);
  • 2.10 operating system (automatically collected);
  • 2.11 a list of URLS starting with a referring site, your activity on this Web Site, and the site you exit to (automatically collected); and
  • 2.12 Cookie information (see Clause 10 below).

3. Our Use of Data

  • 3.1 Any personal Data you submit will be retained by Enzalgu for as long as you use the Services and Systems provided on the Web Site. Data that you may submit through any communications System that we may provide may be retained for a longer period of up to one year.
  • 3.2 Unless we are obliged or permitted by law to do so, and subject to Clause 4, your Data will not be disclosed to third parties. This includes our affiliates and / or other companies within our group.
  • 3.3 All personal Data is stored securely in accordance with the principles of the Data Protection Act 1998. For more details on security, see Clause 9 below.
  • 3.4 Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Web Site. Specifically, Data may be used by us for the following reasons:
  • 3.4.1 internal record keeping;
  • 3.4.2 improvement and development of our products and services. When ever possible, our analytics does not include data that could personally identify an individual, but rather work with non-identifiable and aggregated data. In case the analytical data includes Personal Data we will ask your explicit consent for the data processing. Processing of this nature is based on the GDPR Article 6(1)a.
  • 3.4.3 transmission by email of promotional materials that may be of interest to you;
  • 3.4.4 contact for market research purposes which may be done using email, telephone, fax or mail. Such information may be used to customise or update the Web Site.
  • 3.4.5 to provide services and process contact requests for future partnerships, to provide services and maintain customer relations. We also process data to when entering into contract with you, to carry out our contractual obligations. Processing of this nature is based on the GDPR Article 6(1)b and 6(1)f.
  • 3.5.6 to fullfill our obligations under law. Processing of this nature is based on the GDPR Article 6(1)c.
  • 3.5.7 to hande legal claims and legal processes. We may process Personal Data to be able to respond or defend against legal claims, such as claims handling, debt collection, fraud prevention and other legal processes. We may also Processing of this nature is based on the GDPR Article 6(1)c.
  • 3.5.8  for marketing and communication. We may process Personal Data for analytics on our website, for purpose of contacting Users regarding the Services and Products, for informing Users changes in services and for marketing our services. We may also process information of ownership of sold art to contact the owner regarding owned art use in exhibitions or other purposes.

4. Third Party Web Sites and Services and Data Transfer

Enzalgu may, from time to time, employ the services of other parties for dealing with matters that may include, but are not limited to, payment handling, delivery of purchased items, search engine facilities, advertising and marketing. The providers of such services do not have access to certain personal Data provided by Users of this Web Site. Any Data used by such parties is used only to the extent required by them to perform the services that Enzalgu requests. Any use for other purposes is strictly prohibited. Furthermore, any Data that is processed by third parties must be processed within the terms of this Policy and in accordance with the Data Protection Act 1998.

Transfer of Personal Data:
 We process personal data primarily within the EU area. However, we or our service providers may transfer personal data to or access it in jurisdictions outside the EU/EAA area. We will take steps to ensure that your personal data receives an adequate level of protection in the jurisdictions in which it is processed. We provide adequate protection for the transfers of Personal Data to countries outside of the EEA through a series of agreements with our service providers based on the Standard Contractual Clauses.
For more information on the transfer of personal data, you can contact us by using the contact details indicated above.

Sharing of Personal data:
 We only share your Personal Data within our organisation as far as reasonably necessary for the purposes of this Privacy Policy. We do not share your Personal Data with third parties outside of our organisation unless one of the following circumstances applies:
- For the purposes set out in this Privacy Policy and to authorized service providers: We may provide your personal data to authorised service providers who perform services for us (for example: data storage, accounting, sales and marketing service providers), provide the data based on your consent as well as supply data to third parties based on legal obligation or legitimate interest. When your personal data is processed by third parties as service providers on behalf of Enzalgu, the appropriate contractual and organizational measures measures are taken to ensure that personal data is processed exclusively for the purposes specified in this Privacy Policy and in accordance with applicable laws and regulations. In addition, measures are taken to ensure approppriate confidentiality and security measures are taken according to our instructions regarding your Personal Data.
- For legal reasons and legal process: We may share your Personal Data with third parties outside our organisation if we have a good-faith belief that access to and use of the Personal Data is reasonably necessary to: (i) meet any applicable law, regulation, and/or court order; (ii) detect, prevent, or otherwise address fraud, crime, security or technical issues; and/or (iii) protect the interests, properties or safety of Enzalgu, the partners or the public as far as in accordance with the law. When possible, we will inform you about such processing.
For other legitimate reasons: If Enzalgu is involved in a merger, acquisition or asset sale, we may transfer your personal data to the third party involved. However, we will continue to ensure the confidentiality of all personal data. We will give notice to all the partners concerned when the personal data are transferred or become subject to a different Privacy Policy. With your excplicit consent We may share your personal data with third parties outside Enzalgu when we have your explicit consent to do so. You have the right to withdraw consent at all times.

5. Changes of Business Ownership and Control

  • 5.1 Enzalgu may, from time to time, expand or reduce its business and this may involve the sale of certain divisions or the transfer of control of certain divisions to other parties. Data provided by Users will, where it is relevant to any division so transferred, be transferred along with that division and the new owner or newly controlling party will, under the terms of this Policy, be permitted to use the Data for the purposes for which it was supplied by you.
  • 5.2 In the event that any Data submitted by Users will be transferred in such a manner, you will be contacted in advance and informed of the changes. When contacted you will be given the choice to have your Data deleted or withheld from the new owner or controller.

6. Controlling Access to your Data

  • 6.1 Wherever you are required to submit Data, you will be given options to restrict our use of that Data. This may include the following:
  • 6.1.1 use of Data for direct marketing purposes; and
  • 6.1.2 sharing Data with third parties.

7. Your Right to Withhold Information

  • 7.1 You may access certain areas of the Web Site without providing any Data at all. However, to use all Services and Systems available on the Web Site you may be required to submit Account information or other Data.
  • 7.2 You may restrict your internet browser’s use of Cookies. For more information see Clause 10 below.

8. Your rights and accessing your own Data

  • 8.1 Right to access: You may access your Account at any time to view or amend the Data. You may need to modify or update your Data if your circumstances change. Additional Data as to your marketing preferences may also be stored and you may change this at any time. You have the right to access and be informed about your Personal Data processed by us. We give you the possibility to request a copy of your Personal Data. (GDPR Article 12 and 15).
  • 8.2 Right to withdraw consent: In case the processing is based on the consent granted by you, you may withdraw the consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. (GDPR Article 7(3))
  • 8.3 Right to rectify: You have the right to have incorrect or incomplete Personal Data we have stored about you corrected or completed by contacting us. (GDPR Article 16).
  • 8.4 Right to erasure: You may also ask us to delete your Personal Data from our systems. We will comply with such a request unless we have a legitimate ground to not delete the data. (GDPR Article 17).
  • 8.5 Right to object: You may have the right to object to certain use of your Personal Data if such data are processed for other purposes than necessary for the provision of the purpose of this Privacy Policy or for compliance with a legal obligation. (GDPR Article 21)
  • 8.6 Right to restriction of processing: You may request us to restrict the processing of Personal Data for example when your data erasure, rectification or objection requests are pending and/or when we do not have legitimate grounds to process your data. (GDPR Article 18 4)
  • 8.7 Right to data portability: You have the right to receive the Personal Data you have provided to us yourself in a structured and commonly used format and to independently transmit those data to a third party. (GDPR Article 20) 
  • 8.8 How to use your rights: you can excercise your rights by sending an email or a letter to us on the contact addresses listed in this Privacy Policy. Should you choose to contact us, we recommend you to include in your message the information that helps us identify you: your full name, address, email address and phone number. If you do not provide this information, we may request additional information to confirm your identity. We will respond to inquiries usually within a month after request receipt. Please note that we may reject requests that are unreasonably repetitive, excessive, or manifestly unfounded.

9. Information Security

Data security is of great importance to Enzalgu and to protect your Data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure Data collected online.

We use administrative, organisational, technical, and physical safeguards to protect the Personal Data we collect and process. Measures include for example, where appropriate, encryption, pseudonymisation, firewalls, secure facilities, and access right systems. Our security controls are designed to maintain an appropriate level of data confidentiality, integrity, availability, resilience, and ability to restore the data. We regularly test the Services, systems, and other assets for security vulnerabilities.

Should despite the security measures, a security breach occur that is likely to have negative effects on the privacy of Users, we will inform you and other affected parties, as well as relevant authorities when required by applicable data protection laws, about the breach as soon as possible.

10. Storing time of Data 

Enzalgu does not store personal data longer than is legally permitted and necessary for the purposes of this Privacy Policy. The retention period depends on the nature of the information and on the purposes of processing, which means that the maximum period may vary. Most Personal Data will be deleted within 12 months from the completion of the partnership, but te maximum period may vary. Some of the Personal Data may be stored by us only as long as such processing is required by law or is reasonably necessary for our legal obligations or legitimate interests such as claims handling, bookkeeping, internal reporting, and reconciliation purposes.

Any data in relation to surveys executed by Enzalgu is destroyed after the survey has been completed and the report of the survey has been completed. In client commissioned surveys the data is stored until the deliverable has been approved. By latest all survey related data is removed during six 6 months from the closure of the survey.

11. Direct Marketing

You have the right to prohibit us from using your Personal Data for direct marketing purposes, market research or profiling made for direct marketing purposes by contacting us on the addresses indicated above. We offer the possibility to unsubscribe in connection with our direct marketing messages.

12. Data Processors

We use in a regular basis the following data processors:

Google Ireland Limited. See privacy documentation: https://policies.google.com/privacy

13. Right to Complain

In case you consider our processing of Personal Data to be inconsistent with the applicable data protection laws, a complaint may be lodged with the local supervisory authority for data protection. In Finland, the local supervisory authority is the

Tietosuojavaltuutettu / Data Protection Ombudsman. Contact details provided below. In case you reside in other EU member state you may contact your local supervisory authority. You may find exhaustive list of supervisory authorities as well as their contact details from European Data Protection Board website.

Tietosuojavaltuutetun toimisto / The Office of Data Protection Ombudsman Visiting address: Lintulahdenkuja 4, 00530 Helsinki, Finland Mailing address: PL 800, 00531 Helsinki, Finland Telephone: 358295666700 Email: tietosuoja@om.fi

14. Changes to this Policy

Enzalgu reserves the right to change this Privacy Policy as we may deem necessary from time to time or as may be required by law. Any changes will be immediately posted on the Web Site and you are deemed to have accepted the terms of the Policy on your first use of the Web Site following the alterations.
Created with