
This data protection notice has been drawn up in accordance with the EU General Data Protection Regulation (2016/679) on 8 April 2022 (last amended on 28 July 2026). Through this data protection notice, we provide you with information on why and how we process your personal data.
The data controller for your personal data is Taaleri Energia Oy (business ID: 2772984–6), located at Kasarmikatu 21B, 00130 Helsinki.
Our Data Protection Officer (DPO) is Pasi Erlin (tel. +358 40 057 1113 and email pasi.erlin@taaleri.com).
If you have any questions regarding your personal data, please contact our Data Protection Officer.
Taaleri Energia’s project portfolio stakeholder and online service user register.
Purpose and legal basis for the processing of personal data
The purpose of processing personal data is to communicate with stakeholders and maintain stakeholder relationships, as well as to store customer data and manage customer relationships.
The legal basis for the processing of personal data is the data controller’s legitimate interest in processing the data and communicating with the contact persons of stakeholder and customer groups.
Personal data is collected only from the data subjects themselves and from public sources, such as the internet, companies’ public websites, social media platforms or other similar registers, in accordance with data protection legislation.
The data is not used for automated decision-making or profiling.
The data stored in the register includes:
The data stored in the register is obtained from the customer via, messages sent via web forms, by email, by telephone, from contracts, during customer meetings and in other situations where the customer provides their data. Information on contact persons at companies and other organisations may also be collected from public sources such as websites, directory services and other companies.
Data may be disclosed to project co-owners, the service provider responsible for project management, or a consultant relevant to resolving issues. Data will only be disclosed to the extent necessary to address a matter raised by a stakeholder.
Data will not be disclosed to other parties as a matter of course. Data may be published to the extent agreed with the client.
However, the data controller may use the services of third parties in the processing of data, for example in relation to IT services, in which case the data controller shall ensure the lawful processing of data through contractual arrangements and by providing guidance to third parties on data processing. These third parties may vary. These third parties process data solely on the data controller’s instructions and on its behalf.
Some of the services used by the data controller in connection with the processing of personal data may be located outside the territory of the Member States of the European Union or the European Economic Area. In such cases, data transfers will comply with the requirements of Chapter V of the General Data Protection Regulation (GDPR) and appropriate transfer mechanisms will be used, such as the standard contractual clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), the European Commission’s adequacy decisions, or other safeguards in accordance with the GDPR.
Personal data is disclosed to public authorities within the limits permitted and required by applicable legislation.
Due care is exercised in the processing of the register, and data processed using information systems is protected appropriately. When register data is stored on internet servers, the physical and digital security of the hardware is ensured as appropriate.
The data controller ensures that stored data, as well as server access rights and other information critical to the security of personal data, is treated confidentially and only by those employees whose job description includes such duties.
Personal data is retained for as long as is necessary to fulfil the purpose for which it was collected in accordance with this privacy policy. The retention period is influenced in particular by the duration of the customer or stakeholder relationship, statutory retention obligations and any legal requirements. The necessity of retaining personal data is assessed regularly, and personal data that has become inactive is deleted unless there is a statutory or other justified reason for retaining it.
Data subjects have the right to check what data concerning them has been stored in the personal data register and to obtain a copy of that data. Data subjects must submit a request for access in writing to the data controller or by email to the contact person responsible for the register. In their request, the data subject must provide the information necessary to locate the data. If necessary, the data controller will ask for further information to verify the data subject’s identity.
The response to the request for access will be sent by email to the person who made the request, unless the data subject asks for the information to be sent by other means.
The data controller shall, to the best of its ability, ensure the quality of the personal data it processes. The data controller shall rectify, erase or supplement any inaccurate or unnecessary personal data either on its own initiative or at the data subject’s request.
The data subject has the right to have the controller restrict processing if, for example, the data subject disputes the accuracy of the personal data. In such cases, processing shall be restricted for a period during which the controller can verify the accuracy of the data.
The data subject has the right to object at any time to the processing of their personal data where the processing is based on a legitimate interest (Article 6(1)(f) of the General Data Protection Regulation). The right to object may be exercised on grounds relating to the data subject’s particular situation. The data controller shall no longer process the personal data, unless the controller can demonstrate that there are compelling legitimate grounds for the processing which override the data subject’s interests, rights and freedoms, or where the processing is necessary for the establishment, exercise or defence of legal claims. A request to object must be sent in writing to the data controller’s data protection officer.
Insofar as the processing of personal data is based on consent or a contract and the processing is carried out by automated means, the data subject has the right to receive the personal data they have provided to the data controller in a structured, commonly used and machine-readable format, and the right to transfer that data to another data controller.
The data subject may lodge a complaint regarding the processing of personal data with the supervisory authority.
Providing personal data is not a legal requirement. However, providing personal data is a prerequisite for maintaining stakeholder relations and managing customer relationships. If the data subject does not provide the necessary personal data, the data controller may not be able to maintain the stakeholder relationship or provide its services to the data subject.
The data controller may update this privacy notice as necessary. Data subjects are advised to review this notice regularly.