Concise version
FINSAI Privacy Policy
Finnish Network for Secure AI
- Version
- 1.2
- Effective date
- 23.8.2026
- Last updated
- 31.8.2026
About FINSAI
FINSAI — Finnish Network for Secure AI — is an informal professional community operated by individuals. It is not a registered association, company, foundation, public authority, separate legal entity or legal person distinct from its operators.
In this Policy, FINSAI, we, us and our mean the individuals who jointly decide the purposes and essential means of processing personal data under the FINSAI name. FINSAI membership is personal: an employer or other professional affiliation is not a member, does not own the membership and has no automatic right to the member register. The register is an internal community register, not a statutory association register.
Contact details for the controller: Sami Vellonen; contact: contact@finsai.fi
The shared email address is an administrative contact point. You may exercise your rights through it.
Scope
This Policy covers the public website, technical logs, cookies, contact forms, membership applications and admissions, the member register and optional directory, meetings, events, working groups, speakers and guests, operational communications, optional newsletters, public profiles, photographs and quotations, complaints, confidentiality or security incidents, and data-protection requests.
It applies to website visitors, people who contact FINSAI, applicants, current and former members, guests, speakers, event participants, newsletter subscribers, references and others communicating with FINSAI.
Personal data and purposes
We process only information that is relevant to the activity. The table below summarizes the main categories, purposes and legal bases.
| Activity | Typical data | Purpose and legal basis |
|---|---|---|
| Website and contact | IP address, device/browser and security logs; name, contact details, message and attachments | Operate and secure the website and answer enquiries. Legitimate interests, requested pre-contract steps, legal obligations and consent for optional cookies or analytics. |
| Membership and admissions | Identity and contact details; role, affiliation, biography, expertise, contribution, conflicts, references, interview notes and decision | Assess applications and administer personal membership in a trusted, contribution-based community. Requested pre-contract steps, membership relationship, legitimate interests and legal claims. Admission is decided by people, not solely by automated means. |
| Members, events and working groups | Membership/access data, attendance, group participation, agreed actions, feedback, speaker and presentation details, and requested arrangements | Organize secure professional activities and provide requested arrangements. Membership or event relationship, requested pre-contract steps, legitimate interests and consent where optional information is collected. Health-related arrangements require explicit consent. |
| Directory and public content | Member-selected name, photograph, title, affiliation, biography, expertise, participation and contact details; approved public quotations or profiles | Support member collaboration and approved public communications. Directory participation and public publication are voluntary and based on separate consent. Membership alone never authorizes publication. |
| Communications | Operational messages and newsletter subscription/consent | Administer membership, events, security, governance and deliverables. Operational messages are necessary; optional newsletters are separate, voluntary and can be stopped at any time. No paid third-party advertisements are sent. |
| Complaints and incidents | Reports, witness accounts, correspondence, logs, findings and measures | Protect people and the community, investigate concerns, enforce rules and handle legal obligations or claims. Legitimate interests, legal obligations, legal claims and vital interests in exceptional emergencies. Access is strictly limited. |
Optional directory information may be hidden or removed without ending membership. A member-facing directory is restricted to individually authorized members and must not be copied, exported or used for sales, marketing or recruitment.
Sources, required information and safe submission
We obtain data mainly from you through forms, correspondence, website use and participation records, and from nominated references and relevant service providers. For membership assessment, we may check limited public professional information, such as an employer profile, professional-networking profile, published research or conference programme. References are informed at or before first contact; applicants should obtain permission before submitting another person's details.
Required information is needed to answer an enquiry, assess or administer membership, register an event or provide a requested arrangement. Optional fields and consent are identified separately. Membership does not depend on a public profile, photograph, quotation, newsletter, optional analytics or optional directory information.
FINSAI does not ordinarily request: a Finnish personal identity code, identity-document copy, payment-card details, health information, criminal-record information or biometric identifiers.
Do not submit passwords, credentials, access tokens, private keys, live exploit code, directly exploitable vulnerability details, patient or health information, national identity numbers, payment-card information, government-classified information, unauthorized third-party confidential information or active incident details through general forms. Share sensitive AI-security, vulnerability or incident information only through an agreed secure channel. Report accidental submissions immediately to contact@finsai.fi.
Access, service providers and international transfers
Access is limited by role and need, such as authorized volunteers, admissions-panel members, event or working-group coordinators, appointed investigators and contracted service providers. Authorized people must follow FINSAI instructions, access only what they need, keep it confidential and delete or return it when their task ends.
Data may be disclosed to authorities when legally required, legal advisers, affected people where needed to contain an incident, courts or insurers for legal claims, and event co-organizers where disclosed in advance and a legal basis exists. FINSAI does not sell personal data, give sponsors access to the register, provide participant lists for sales, or disclose member details to employers merely because participation is funded.
Service providers may support hosting, domains/CDN, forms, email and collaboration, membership administration, meetings and events, cookie consent, analytics, backups and security monitoring. Processors must be bound by appropriate confidentiality, security and data-protection terms. FINSAI data should be stored in community-designated accounts; any employer-managed system and possible employer access must be assessed and disclosed. The current provider list and processing locations must be kept up to date before publication.
We prefer providers processing data in Finland or the EEA. If data are transferred outside the EEA, we use an adequacy decision, standard contractual clauses or another lawful mechanism, with supplementary safeguards where needed. Details can be requested from contact@finsai.fi.
Retention
Personal data are kept only as long as necessary for the purpose, a legal obligation or a potential legal claim, then deleted, anonymized or securely archived where retention is required.
| Information | Standard period |
|---|---|
| Website and security logs | Normally 90 days; incident-related logs until the incident and follow-up are complete |
| Contact-form enquiries | 12 months after the matter is closed |
| Rejected or withdrawn applications | 12 months after the final decision or withdrawal |
| Accepted applicants' detailed interview and assessment notes | 24 months after acceptance, followed by deletion or minimization |
| Current and former membership information | Core register information for the membership; minimal former-member history normally 3 years after it ends |
| Directory and public profile information | Until consent is withdrawn, membership ends or the agreed publication period ends |
| Event information | Normally 12 months after the event; dietary/accessibility information normally 30 days |
| Newsletter and consent evidence | Newsletter until withdrawal; minimal evidence of consent/withdrawal normally 3 years |
| Complaints, incidents and rights requests | Normally 3 years after closure or completion |
| Backup copies | Documented rotation, normally no longer than 90 days |
A longer period may apply where required by law, needed for an unresolved dispute, legal claim or incident investigation, or agreed for a specific purpose.
Cookies and similar technologies
The website may use cookies, session or local storage, consent identifiers, embedded-content technologies and technical server logs. These may process IP address, identifiers, device/browser information, pages visited, consent choices and login status.
| Category | Default status | Purpose |
|---|---|---|
| Strictly necessary | Active where required | Website delivery, security, sessions, authentication and recording cookie choices |
| Functional preferences | Consent-based unless necessary for a requested function | Remember optional language, interface or display choices |
| Analytics | Disabled until consent | Understand aggregate website use and improve content |
| Embedded third-party content | Blocked until consent or deliberate activation | Display third-party video, maps or similar content |
| Advertising and cross-site marketing | Not used | FINSAI does not use behavioural advertising cookies |
Optional technologies are not preselected, can be accepted or rejected by category, and can be changed through the permanent Cookie Settings link. The current inventory must state each technology's name, provider, first- or third-party status, purpose, category, data, lifetime and applicable transfer information, and must be reviewed when the website or providers change.
AI use and information security
Personal data from contact forms, membership applications or the member register are not used to train public or general-purpose AI models. Non-public personal data must not be uploaded to public generative-AI services, personal AI accounts or unapproved transcription, meeting-assistant or summarization tools.
An AI-assisted service may be used only when the service and purpose are approved, a legal basis and required processor/transfer arrangements exist, access and retention are limited, unrelated model training is excluded and people are informed where required. Automated tools may support spam detection, security monitoring, form validation, login-failure detection and administrative organization, but membership decisions are not made solely by automated means. Human review may be requested if an automated measure incorrectly blocks a legitimate submission.
Safeguards may include individual accounts, multi-factor authentication, least privilege, encryption in transit, secure configuration, access logging and review, confidentiality commitments, data minimization, backups, deletion, incident response, provider review and separation from employer-controlled systems. No internet-based system is completely secure. Report suspected privacy or security incidents to contact@finsai.fi.
Your rights and complaints
Depending on the legal basis and circumstances, you may have the right to access your data, correct it, request erasure or restriction, object to processing based on legitimate interests, receive portable data where applicable, withdraw consent, object to direct marketing and request human review of a material automated measure. Not every right applies in every situation; withdrawal does not affect earlier lawful processing, and erasure or objection may be limited by law or legal claims.
Send requests to contact@finsai.fi. State who you are, the right you wish to exercise, the relevant data or processing and how the response can be delivered securely. We may request proportionate identity verification. Requests are normally answered within one month; where law permits an extension, we will explain it. If no action is taken, we will give the reason and information about your right to complain.
Finnish supervisory authority: Office of the Data Protection Ombudsman, Lintulahdenkuja 4, 00530 Helsinki; P.O. Box 800, 00531 Helsinki, Finland; tietosuoja@om.fi; +358 29 566 6700.
You may also contact the competent supervisory authority in another EU or EEA country, particularly where you live, work or believe the infringement occurred.
External services, changes and contact
External websites linked from FINSAI have their own privacy policies. Embedded third-party content may be blocked until consent or deliberate activation. This Policy may be updated when FINSAI's controllers, activities, services, cookies, retention periods or applicable requirements change. The current version and effective date are published on the website; material changes affecting members may also be communicated by email or through the member workspace. A new incompatible purpose requires information and a valid legal basis before processing begins.
Privacy enquiries, data-subject requests and security incidents: contact@finsai.fi
FINSAI is a community name, not a separate legal entity.
