PRIVACY POLICY

Last updated: 19 August 2026

Vision Finland respects your privacy and processes personal data transparently, fairly and securely. This Privacy Policy explains how personal data is collected and used when you visit visionfinland.com, contact us, work with us, submit content or event information, or otherwise interact with Vision Finland.

1. Joint controllers and contact details

Vision Finland is jointly operated by the following data controllers, which jointly determine the purposes and means of the processing described in this Privacy Policy:

Dataprint Oy Business ID 0410548-3 | P.O. Box 75, FI-01801 Klaukkala, Finland

 

Smart Synergy Co., Ltd. Company registration number 0105564160460 | 19/125 Sukhumvit Suite, 13th Floor, Zone Y7, Soi Sukhumvit 13 (Saengchan), Sukhumvit Road, Khlong Toei Nuea, Watthana, Bangkok 10110, Thailand

 

The controllers have designated info@visionfinland.com as the contact point for privacy matters. You may exercise your rights against either controller, regardless of the designated contact point.

2. Scope of this Privacy Policy

This Privacy Policy applies to website visitors, people who contact Vision Finland, customers and prospective customers, representatives of companies and chambers of commerce, partners, contributors, authors, interviewees, event organisers and other professional contacts.

Where personal data is processed solely for journalistic or editorial purposes, applicable rules protecting freedom of expression and information, including any statutory exemptions, may also apply.

3. Personal data we collect

  1. Contact and enquiry data. Name, email address, company or organisation, job title, telephone number where provided, message content and related correspondence.
  2. Customer and partner data. Business contact details, service requests, proposals, contracts, billing information, meeting notes and records of the business relationship.
  3. Editorial and event data. Contributor and organiser contact details, professional biography, organisation and role, submitted text, images, quotations, event information and other publication material.
  4. Website and device data. IP address, browser and device information, timestamps, requested pages, referring page, server logs and security-related data.
  5. Analytics data. Cookie or device identifiers, page views, sessions, traffic source, approximate location derived from IP address and interactions with website elements, but only where the required consent has been provided.
  6. Public-source data. Professional information obtained from company websites, official registers, chambers of commerce, professional networks, event sources and other publicly available business sources.
  7. Consent and rights-request data. Cookie choices, consent records, opt-out information and communications relating to privacy rights.

Please do not submit special-category or otherwise sensitive personal data through the website unless it is specifically requested and there is a lawful reason to do so.

4. Purposes and legal bases

We process personal data for the following purposes and on the following legal bases:

Processing activityPurposeLegal basis
Enquiries and proposalsResponding to messages, arranging discussions and preparing requested proposals.Steps requested before a contract; legitimate interests in professional communication.
Services and relationshipsProviding services and managing customer, partner and chamber relationships.Performance of a contract; legitimate interests.
Editorial workPreparing, reviewing, publishing and archiving articles, interviews, contributor profiles, images and related content.Legitimate interests and freedom of expression and information; consent where appropriate.
EventsReceiving, reviewing, publishing and managing event and organiser information.Legitimate interests; steps requested by the organiser; consent where appropriate.
Business communicationsRelevant B2B communications about Vision Finland's services, partnerships and opportunities.Legitimate interests where permitted by law; consent where required.
Optional updatesSending newsletters or similar electronic updates where a subscription is offered.Consent.
Website operationOperating, securing, troubleshooting and preventing misuse of the website and forms.Legitimate interests in security and service availability.
AnalyticsUnderstanding website use and improving content and services through Google Analytics and PostHog.Consent.
AdministrationBilling, accounting, compliance, legal claims and responding to authorities.Legal obligations; performance of a contract; legitimate interests.
Privacy requestsManaging consent, objections and data-subject requests.Legal obligations; legitimate interests in demonstrating compliance.

 

Where we rely on legitimate interests, we assess the necessity of the processing and balance our interests against the rights and reasonable expectations of the individual concerned.

5. Where the data comes from

We normally obtain personal data directly from you, your employer or organisation, a partner or chamber that introduces you, your use of the website, or publicly available professional and business sources. If we obtain your data indirectly, we provide the information required by applicable law unless an exemption applies.

6. Is providing personal data required?

Fields marked as required in a form are necessary for us to receive and respond to the request. Other information is voluntary. If required information is not provided, we may be unable to respond, prepare a proposal, publish a submitted event or provide the requested service.

7. Cookies and analytics

Necessary technologies may be used to operate and secure the website. Google Analytics and PostHog are used only after the visitor has consented to analytics. Consent may be refused or withdrawn at any time without affecting access to the core website.

More information and controls are available in Cookie Settings.

8. Recipients and service providers

Personal data may be disclosed or made available, where necessary, to:

  1. authorised personnel of Dataprint Oy and Smart Synergy Co., Ltd.;
  2. website hosting, maintenance, security, email, collaboration and other IT service providers;
  3. Google Ireland Limited for Google Analytics and PostHog Inc. for PostHog analytics, where analytics consent has been given;
  4. accounting, legal and other professional advisers;
  5. chambers of commerce, partners, event organisers or other recipients when this is necessary for the requested collaboration or publication and is reasonably expected; and
  6. public authorities or other parties where disclosure is required by law or necessary for legal claims.

Service providers may process personal data only for agreed purposes and under appropriate contractual and confidentiality obligations. We do not sell personal data.

9. International data transfers

Vision Finland is jointly operated from Finland and Thailand. Personal data may therefore be accessed and processed in both countries. Thailand is outside the European Economic Area (EEA) and is not currently covered by an EU adequacy decision.

Where the GDPR applies and personal data is transferred from the EEA to Thailand or another country without an adequacy decision, the transfer is protected by an applicable legal mechanism, such as the European Commission's Standard Contractual Clauses, together with supplementary technical and organisational safeguards where required. Some service providers may also process data outside the EEA under their applicable transfer mechanisms. Information about relevant safeguards may be requested using the privacy contact details above.

10. Retention periods

We retain personal data only for as long as necessary for the relevant purpose. The principal retention periods are:

Data or activityRetention
Contact enquiriesUp to 24 months after the enquiry is resolved, unless it develops into a business relationship or longer retention is needed for a legal reason.
Customer and partner recordsFor the relationship and generally up to 6 years after it ends. Accounting records are retained for the statutory period, generally 6-10 years depending on the record.
B2B marketing contactsUntil objection or opt-out, or after 24 months without meaningful engagement, unless a continuing relationship justifies retention.
Event organiser contactsUp to 24 months after the event or listing. Published event information may remain in the website archive.
Editorial and published contentFor as long as justified by publication, journalistic, historical or archival purposes. Requests are assessed case by case.
Security and server logsNormally up to 90 days, unless an incident, investigation or legal obligation requires longer retention.
Analytics event dataUp to 14 months. Cookie and browser-storage durations are described in the Cookie Policy.
Consent recordsFor the validity of the choice and generally for 3 years after withdrawal or expiry where necessary to demonstrate compliance.
Privacy-rights requestsGenerally 3 years after the request is closed, unless longer retention is needed for a legal claim or obligation.

 

Data may be deleted or anonymised earlier when it is no longer necessary.

11. Your rights

Depending on the applicable law and the legal basis for processing, you may have the right to:

  1. receive information about the processing of your personal data;
  2. request access to and a copy of your personal data;
  3. request correction of inaccurate or incomplete data;
  4. request deletion of personal data;
  5. request restriction of processing;
  6. object to processing based on legitimate interests and object at any time to direct marketing;
  7. receive data you provided in a portable format where the legal requirements are met;
  8. withdraw consent at any time, without affecting processing carried out before withdrawal; and
  9. lodge a complaint with a competent data protection authority.

These rights are not absolute. In particular, rights may be limited where data must be retained by law, where processing is required for legal claims, or where lawful journalistic or editorial exemptions apply. We may request information necessary to verify the identity of the person making a request.

To exercise your rights, contact info@visionfinland.com.

12. Direct marketing

You may object to direct marketing at any time by using an unsubscribe option where available or by contacting us. We will retain the minimum information necessary to respect the opt-out request.

13. Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure or access. Access is limited to people who need the data for their work and who are subject to confidentiality obligations. No online service can, however, guarantee absolute security.

14. Automated decision-making

Vision Finland does not use the personal data covered by this Privacy Policy to make decisions based solely on automated processing that produce legal or similarly significant effects.

15. Children

The website and services are intended for businesses and professionals and are not directed to children. We do not knowingly collect personal data from children through the website.

16. External links and social media

The website may link to external websites and social media services. Those services process personal data under their own privacy notices. Following an external link does not mean that Vision Finland controls the recipient's processing.

17. Changes to this Privacy Policy

We may update this Privacy Policy when our activities, technologies or legal obligations change. The current version and its last-updated date are published on this page. Material changes will be communicated through an appropriate additional notice where required.

18. Complaints and supervisory authorities

We encourage you to contact us first so that we can address any concern. You also have the right to lodge a complaint with the supervisory authority in the country where you live, work or where the alleged infringement occurred.

Finland: Office of the Data Protection Ombudsman

Thailand: Personal Data Protection Committee (PDPC)