Privacy policy
This document is the GDPR-compliant privacy and register description of Suomen Pelinkehittäjät ry (hereinafter "the Association"). The description is updated regularly, and its latest version can always be found on our website. Effective date of the latest version: 21.8.2026.
Suomen Pelinkehittäjät ry is committed to the principles of the EU General Data Protection Regulation (GDPR). Our operations and services comply with the requirements of the Regulation.
1) Data Controller
Suomen Pelinkehittäjät ry (2671521-5)
Address: c/o Neogames / Eteläranta 10, 00130 Helsinki
2) Contact Person Responsible for the Register
Contact person, agent: Koopee Hiltunen
Email: koopee@neogames.fi
3) Registers in Which We Collect Data
- The Association's member contact information register
- The Association's email newsletter
- Register of Finnish companies operating in the games industry
4) Legal Bases and Purposes of Personal Data Processing
- Association contact register and register of domestic games industry companies
- The Association collects and maintains a register of companies operating in the games industry in Finland and their contact persons for the purposes of member recruitment and organizing events.
- The Association collects personal data of representatives of its stakeholders in its contact register in order to maintain member and stakeholder relationships, for communication purposes, and for organizing events.
- For representatives of companies and organizations, the legal basis under the GDPR for processing personal data is the legitimate interest of the controller.
- A balancing test has been carried out in relation to the controller's legitimate interest.
- Association email newsletter
- The Association publishes an email newsletter that regularly communicates news about the domestic games industry. The newsletter is intended only for members.
- For newsletter subscribers, the legal basis under the GDPR for processing personal data is membership in the Association. The contact person / company is defined by company itself.
5) Data Content of the Registers and Data Retention
- Association contact register and register of domestic games industry companies
- Person's name, position, company/organization, the person's contact details (email address, company address), website addresses, billing information in the case of membership or a customer relationship, other information related to membership, customer relationships, and subscribed services, and information related to participation in events.
- No sensitive data is stored in the register. In connection with event registration, dietary information may be collected in the register when necessary for arranging catering for that event. Dietary information is deleted after the event.
- Data is retained for as long as cooperation or communication between the Association and the stakeholder continues, and the person acts as a representative of that stakeholder.
- Company data is retained for as long as the company falls within the scope of our industry-related research activities. Personal data is retained for as long as the company operates in the games industry.
- Association email newsletter
- Email address, information on newsletter subscriptions and changes thereto.
- Data is retained for as long as the person remains a subscriber to the newsletter.
6) Regular Sources of Data
Contact information for representatives of companies and other organizations may be collected via, among other things, email, telephone, social media services, contracts, meetings, messages submitted through web forms, in connection with events, and other situations in which a person discloses their information.
Information on companies and organizations, contact persons' information, and information on persons in public roles may also be collected from public sources such as websites, directory services, and other companies.
7) Regular Disclosures of Data and Transfer of Data Outside the EU/EEA
- Association contact register
- Personal data is processed and stored using the domestic Gruppo system. An agreement on data processing has been concluded between the Association and Gruppo Oy, stating that the service complies with the EU GDPR. Gruppo also states that its subcontractors' services comply with the Regulation. The service's primary servers and primary backup system are located in Finland.
- Information on membership (the member list) is published on the Association's website.
- Association email newsletter
- The delivery of the email newsletter and related services operate through a cloud-based system, in which data processing also takes place outside the EU/EEA area. The service provider has committed to the EU's standard contractual clauses for data processing.
8) Principles of Register Protection
Data collected by the Association is stored appropriately, and access to it is restricted through personal access rights. When register data is stored on internet servers, appropriate care is taken regarding the physical and digital security of the hardware.
The cloud services used by the Association for storing documents, as well as email communication, are protected by means such as firewalls.
In addition, parties cooperating with the Association — such as Gruppo, which maintains the contact information and email newsletter system, the accounting firm, and the event organizer — restrict access to the data provided to them to only those persons for whom access is necessary for carrying out the service.
9) Right of Inspection, Right to Demand Correction and Deletion of Data
Every person included in the register has the right to check the data stored about them in the register and to demand correction of any incorrect data or completion of incomplete data. If a person wishes to check the data stored about them or demand a correction, the request must be sent in writing to the data controller. The data controller may, if necessary, request that the person making the request prove their identity. The data controller responds to the request within the time period prescribed by the GDPR (as a rule, within one month).
A person included in the register has the right to request the deletion of their personal data from the register ("the right to be forgotten"). Likewise, data subjects have other rights under the GDPR, such as the right to restrict the processing of personal data in certain situations. Requests must be sent in writing to the data controller. The data controller may, if necessary, request that the person making the request prove their identity. The data controller responds to the customer within the time period prescribed by the GDPR (as a rule, within one month).
10) Cookies
The website (www.pelinkehittajat.fi) uses cookies.
Visitors' IP addresses and cookies necessary for the functioning of the service are processed on the basis of legitimate interest, e.g. to ensure information security and to collect statistical data on website visitors in cases where this may be considered personal data. Consent for third-party cookies is requested separately where necessary.