GDPR (General Data Protection Regulation)

Privacy Policy – Valavia Oy

Data Controller and Contact Person

Valavia Oy (Business ID: FI34081443)

Peuranoronkatu 10, 37630 Valkeakoski, Finland.

Contact person: Joonas Tuominen (joonas.tuominen@valavia.fi)

All requests regarding data protection must be sent to the email address mentioned above.

"Hello, I am Joonas Tuominen, CEO of Valavia Oy. In our opinion, transparency—both in projects and in data processing—is the foundation of trust. We care for your data as if it were our own."

Data Subjects and Purpose of Processing

The processing of personal data is based on the legitimate interest of the data controller, which relates to managing customer relationships, conducting business, and providing technical services. Processing may also be based on an agreement with the data subject.

We process personal data for the following purposes:

  • Customers and Partners: To enable the maintenance of the customer relationship, communication required for a functional partnership, and customer service. (Basis: Legitimate interest of the data controller).
  • Potential Customers: Contact requests received through the website's contact form. (Basis: Legitimate interest of the data controller).
  • Drone Operations (Unmanned Aviation): Drones are used for technical inspections, mapping, modeling large areas (point clouds, map data), and monitoring. (Basis: Legitimate interest of the data controller to provide technical inspection and mapping services).

Data to be Stored in the Register

Data is obtained both directly from the data subjects themselves and from public business registers. We do not use automated decision-making or profiling.

  • Identification Data: Name, title, employer/company, communication language. Used for customer relationship management and communications.
  • Contact Details: Telephone number, email address, company's visiting and postal address. Used for communications and service delivery.
  • Customer History: Duration of the customer relationship, contact history, email, chat, and call records. Used for quality assurance and relationship history.
  • Drone Data: Technical raw data, log files, and visual material. Used for creating deliverables and ensuring flight safety.

Special Practices Regarding Drone Data:

I Visual Personal Data: The final technical deliverables (such as point clouds and maps) do not contain identifiable individuals. If bystanders in public places are accidentally captured in the raw data, they are anonymized (blurred) or removed during post-processing.

II Processing Duration: The processing of sensitive raw data is carried out as soon as possible and is deleted within two (2) months of the flight operation. Data is processed locally, and raw data subject to GDPR is not uploaded to cloud storage.

III Transparency: Valavia Oy is registered with Traficom (Finnish Transport and Communications Agency) as a drone operator. We wear high-visibility vests during flight missions whenever possible.


Cookies

We use cookies to ensure the functionality of the website. We have restricted their use to a minimum; we only collect general information regarding visitor numbers, location (country/region), and the type of device used to access the website. The use of cookies is managed through a cookie banner, where the user can accept or decline analytical cookies.


Data Storage and Retention Periods

We only store data that is necessary for our operations:

  • Short Projects: 5 years after the termination of the contract.
  • Long-Term Partnerships and Legal Protection: 10 years.
  • Website Form Data: Automatically deleted after 12 months.
  • Marketing Register: Unnecessary data is cleared every 12 months.
  • Drone Raw Data: Deleted immediately after anonymization, at the latest within two (2) months of the flight operation.

Data Disclosures and Transfers Outside the EU

Data is not disclosed outside Valavia Oy for marketing purposes. Our servers are primarily located within the EU. In some cases (such as backups or equipment manufacturers' systems), data may be transferred to the United States.

SCC: We have ensured that our service providers who transfer data outside the EU/EEA use transfer mechanisms approved by the European Commission, such as Standard Contractual Clauses (SCC) or the EU-U.S. Data Privacy Framework arrangement.


Principles of Register Security

  • Electronic Security: User IDs, passwords, firewalls, and other technical measures.
  • Physical Security: Paper-based materials are stored in office premises accessible only by authorized personnel.
  • Access Control: Data can only be accessed by personnel who require it for their specific work duties and who are bound by a confidentiality obligation.

Rights of the Data Subject

You have the right to:

  • Access data concerning yourself in a structured and machine-readable format, provided that the processing is based on an agreement or consent.
  • Object to the processing or request the deletion of your data.
  • Opt-out of Direct Marketing: You can object to marketing communication at any time by replying to our message or by contacting our contact person.
  • File a Complaint with the Data Protection Ombudsman (Tietosuojavaltuutettu) if you feel that we are violating data protection legislation.