Legal
Privacy Policy
V1.3. Last updated: 16 March 2026
This privacy policy has been prepared in accordance with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Originally drafted 13 February 2022. Last amended 16 March 2026.
1. Data Controller
Mastos Oy
Hannikaisenkatu 20, 40100 Jyväskylä, Finland
Y-tunnus / Business ID: 3262170-9
2. Contact Person for the Register
Tiia Hamro-Drotz, COO
3. Name of the Register
Mastos Oy Customer and Marketing Register
4. Legal Basis and Purpose of Processing
The legal basis for processing personal data under the EU General Data Protection Regulation is:
- The data subject's consent (documented, voluntary, specific, informed, and unambiguous)
- A contract to which the data subject is a party
- The legitimate interest of the data controller (customer relationship, employment relationship, membership)
Personal data is processed for the purpose of communicating with customers, maintaining customer relationships, and marketing.
5. Data Content of the Register
The following data may be stored in the register: name, position, company or organisation, contact details (phone number, email address), communications with Mastos, website addresses, information about ordered services and any changes to them, billing information, IP address, operating system, and any other information related to the customer relationship.
The register contains data further specified in the privacy policy of the following third-party service used to collect data:
In addition, the Mastos customer portal contains company-specific data processed under a separate agreement with each client.
6. Regular Sources of Data
Data stored in the register is collected from the customer through web forms, email, telephone, social media services, contracts, customer meetings, and other situations where the customer provides their information.
7. Regular Disclosures and Transfers Outside the EU/EEA
Data is not disclosed to third parties. Data may be published to the extent agreed with the customer. Data may also be transferred outside the EU or EEA by the data controller.
Servers and other technical tools used in data processing may be owned and managed by service providers other than the data controller. This may result in data transfers outside the EU or EEA, but only to countries assessed by the European Commission as providing an adequate level of data protection, or where service providers comply with the EU Standard Contractual Clauses.
For further information on data transfer practices, please refer to Lovable's privacy policy linked above.
8. Principles of Register Security
Personal data is handled with care and data processed through information systems is protected appropriately. Where register data is stored on internet servers, the physical and digital security of the hardware is maintained accordingly.
The data controller ensures that stored data, server access rights, and other information critical to the security of personal data are handled confidentially and only by employees whose job responsibilities require it. The register is protected with appropriate usernames and passwords.
Employees who handle customer register data are bound by a duty of confidentiality. Information is disclosed to third parties only where required by law, at the customer's own request, or pursuant to a lawful request by an authority.
9. Right of Access and Right to Rectification
Every person in the register has the right to review their stored data and to request the correction of any inaccurate information or the completion of incomplete data.
Requests should be sent in writing to the data controller or to mastos@mastos.fi. The data controller may request proof of identity where necessary and will respond within one month as required by GDPR.
10. Other Rights Related to the Processing of Personal Data
Data subjects have the right to request the deletion of their personal data from the register (the "right to be forgotten"). Data subjects also have all other rights provided under the EU General Data Protection Regulation, including the right to restrict processing in certain circumstances.
All requests must be submitted in writing to the data controller. The data controller may request proof of identity where necessary and will respond within one month.
Questions about privacy?
Contact Tiia Hamro-Drotz, COO. tiia@mastos.fi