Privacy Policy – Customer and Marketing Register
This Privacy Notice explains how the UTU Group companies listed below process the personal data of customers, prospective customers, business partners, event participants, newsletter subscribers and website users. This Privacy Notice provides the information required under the EU General Data Protection Regulation (EU) 2016/679, in particular Articles 12–14. In Finland, the GDPR is supplemented by the Data Protection Act (1050/2018).
Updated 2 July, 2026
1. Controller
The controller is the UTU Group company with which the individual has a relationship as a customer, prospective customer or business partner, or whose service the individual has contacted. Each company, in its capacity as controller, is responsible for the processing of personal data carried out in its own operations.
UTU Group:
UTU Group Oy (0143919-7)
UTU Oy (1707453-2)
UTU Automation Oy (0108443-4)
The companies have agreed on the allocation of their respective responsibilities as joint controllers of the register. Data subjects may exercise their rights through any of the joint controllers. The essence of the joint-controller arrangement is available upon request from tietosuoja@utu.eu.
2. Contacts for matters concerning the register
For enquiries concerning data protection and the exercise of data subject rights, please contact:
Johanna Teinilä, Marketing and Communications Manager, or Tiina Rajala, IT Specialist
Email: tietosuoja@utu.eu
3. Name of the register
UTU Group Customer and Marketing Register
4. Purpose of processing personal data
The purposes of the register are to manage and develop the company’s customer relationships, provide services, develop and plan business operations, conduct marketing and customer acquisition, carry out opinion and market research, and manage customer communications.
| Purpose of processing | Legal basis |
|---|---|
| Responding to enquiries, requests for quotation, service requests and customer service matters, and taking steps prior to entering into a contract | Taking steps prior to entering into a contract or performance of a contract; with regard to contact persons of corporate customers, also the controller’s legitimate interest in managing the business relationship |
| Managing orders, deliveries, services, contracts, invoicing and payments | Performance of a contract and compliance with legal obligations; with regard to contact persons of corporate customers, also legitimate interests |
| Managing customer relationships and customer communications, ensuring service quality, processing feedback, and developing operations and services | The controller’s legitimate interest in developing its services and managing its customer and stakeholder relationships |
| Managing registrations for and participation in events and webinars, and requests for recordings | A contract or steps prior to entering into a contract; where appropriate, consent or a legitimate interest in organising and communicating about the event |
| Newsletters, electronic direct marketing and the management of marketing preferences | Consent where prior consent is required by law; in other situations permitted by law, legitimate interests. The recipient always has the right to object to direct marketing. |
| Targeting sales and marketing and identifying prospective corporate customers | The legitimate interest in conducting customary B2B sales and marketing; a documented balancing test is carried out when legitimate interests are relied upon |
| Analysing and personalising website use and targeting marketing through non-essential cookies | Consent |
| Ensuring the security of the website, services and information systems, preventing misuse, and establishing, exercising or defending legal claims | Compliance with legal obligations and the controller’s legitimate interest in protecting its services, information and rights |
| Using AI-assisted tools for the tasks described in Section 14 below | The same legal basis as applies to the original purpose served by the AI-assisted processing. The use of AI does not in itself constitute a new legal basis for processing. |
When processing is based on legitimate interests, we assess the necessity of the processing and balance UTU’s interests against the rights of the data subject before beginning the processing. Further information about the balancing test may be requested from tietosuoja@utu.eu.
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5. Personal data processed
The register may contain the following information:
- name, telephone number, email address, postal address and other contact details
- the individual’s duties, position and area of responsibility within an organisation, as well as the organisation’s name, Business ID, address and website
- information concerning the customer relationship, contracts, quotations, orders, deliveries, service requests, invoicing and payments
- enquiries, customer service communications, feedback, notes concerning calls or meetings, and information and attachments submitted through online forms, chat or email
- information concerning registration for and participation in events and webinars, requests for recordings, newsletter subscriptions, consents, objections and other marketing preferences
- technical information concerning the website and digital services, such as IP addresses, cookie and device identifiers, browser and device information, log data and information about website use
- interests and target groups inferred from marketing activities and website use, where profiling is permitted and consent has been obtained where required
- information generated or processed in connection with AI-assisted processing, such as conversations, prompts, summaries, classifications, drafts and quality-assurance notes, where they relate to the purposes described in this Privacy Notice
- log and event data required to ensure the security of the processing and demonstrate compliance.
We do not seek to collect special categories of personal data in the Customer and Marketing Register, such as health data, political opinions, religious beliefs or trade union membership. Please do not provide such information through online forms or chat unless it is expressly necessary and you have been separately instructed to do so.
6. Sources of personal data
We obtain personal data:
- directly from the data subject by telephone or email, at meetings and events, through online forms or chat, or by other similar means
- from the organisation represented by the data subject and in connection with the customer relationship, orders or the use of services
- from other UTU Group companies where the sharing of information has a purpose and legal basis described in this Privacy Notice
- from providers of event, webinar, marketing, customer service and online services
- from public and lawful sources, such as company websites, the Trade Register, professional directories and professional online services
- from business partners or business information services that are authorised to disclose the information for this purpose.
When we obtain personal data from a source other than the data subject, we provide the information contained in this Privacy Notice within the period required by the GDPR, generally no later than one month after obtaining the data or, at the latest, when we first contact the data subject.
7. Recipients and processors of personal data
To the extent necessary for the purposes of processing, personal data may be disclosed or made available for processing to the following categories of recipients:
- UTU Group companies
- providers of website, hosting, information security, IT support, cloud and information system services
- providers of customer relationship management, sales, marketing automation, newsletter, analytics, advertising and cookie management services
- providers of customer service, chat, event, webinar and recruitment services
- providers of AI and language technology services when these services are used for the purposes described in Section 14
- providers of logistics, maintenance, installation, invoicing, payment, auditing, legal and other professional services
- public authorities and other parties to whom information must be disclosed under applicable law or a binding order
- parties to and advisers involved in a corporate transaction, where required in connection with an acquisition, merger or other corporate arrangement.
Where a service provider processes personal data on behalf of UTU, a data processing agreement in accordance with Article 28 of the GDPR is concluded with the provider, and the processing is restricted to UTU’s instructions.
External AI services are used only in approved corporate environments in which the service provider is not permitted to use UTU’s inputs or outputs for its own purposes or to train general-purpose models, unless such use has been separately disclosed and has a lawful basis.
8. Transfers of personal data outside the European Economic Area
Personal data is primarily processed within the European Economic Area. Some service providers or their sub-processors may process personal data outside the European Economic Area or provide access to the data from a country outside the European Economic Area.
In such cases, we ensure the lawfulness of the transfer by using a transfer mechanism under Chapter V of the GDPR, such as an adequacy decision adopted by the European Commission or the standard contractual clauses approved by the Commission. Where necessary, we assess the risks associated with the transfer and implement supplementary technical and organisational safeguards.
Further information about the transfer mechanism used and a copy of the applicable safeguards may be requested from tietosuoja@utu.eu.
9. Protection of personal data
We protect personal data through technical and organisational measures appropriate to the level of risk. These measures include restricting access rights according to job duties, personal user accounts, strong authentication where applicable, protecting data in transit and at rest, logging, backups, security updates, staff instructions and training, and the contractual and risk-based oversight of service providers.
Paper records are stored in locked premises and securely destroyed.
10. Rights of the data subject
Contacts related to the data subject’s rights must be sent in writing: tietosuoja@utu.eu. The controller will respond to the contact Subject to applicable law, data subjects have the right to:
- obtain confirmation as to whether we process their personal data and access that data
- request the rectification of inaccurate or incomplete personal data
- request the erasure of personal data where there is no longer a lawful basis for processing it
- request the restriction of processing
- receive personal data they have provided in a structured, commonly used and machine-readable format and transmit it to another controller where the processing is based on consent or a contract and is carried out by automated means
- object to processing based on legitimate interests on grounds relating to their particular situation
- object at any time to the processing of their personal data for direct marketing; the objection to direct marketing also applies to related profiling
- withdraw consent at any time
- not be subject to a decision based solely on automated processing where the decision produces legal effects concerning them or similarly significantly affects them
- lodge a complaint with the competent supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman: https://tietosuoja.fi/en/.
Requests concerning data subject rights may be sent to tietosuoja@utu.eu. The identity of the person making the request will be verified only to the extent necessary. We respond to requests without undue delay and generally within one month. If a request is exceptionally extensive or complex, the time limit may be extended as permitted by the GDPR. If we do not comply with a request, we will explain the reasons for the refusal and the available legal remedies.
Not all rights apply in every situation. The applicability of a right depends on factors including the legal basis for the processing and statutory retention obligations.
11. Retention of personal data
As a general rule, we process personal data for as long as necessary to manage the customer contract. Personal data processed for marketing purposes is generally retained for the duration of the customer relationship. Materials classified as accounting records or supporting documentation are retained for the period required by law.
12. Responsibilities and changes to this Privacy Notice
UTU maintains documentation concerning the processing of personal data, defines access rights, monitors service providers, and ensures the protection, archiving and destruction of personal data.
We may update this Privacy Notice when our processing practices or applicable legislation change.
13. Cookies
3. Cookies and similar technologies
We use cookies and similar technologies on our website to ensure the technical operation of the website, remember user preferences, operate the customer service chat, analyse website use, develop content and target marketing.
Strictly necessary cookies are used to operate the website and provide services requested by the user. Analytics, personalisation and marketing cookies and similar identifiers are used only with the user’s consent. Non-essential cookies and third-party content that uses them, such as videos or other embedded content, are not activated before consent has been given.
Users can accept or reject non-essential cookies equally easily and change their choices at any time through the cookie settings. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Cookies and similar technologies may be used to process personal data such as IP addresses, cookie or device identifiers, browser and device information, page views, clicks and other usage data. Up-to-date information about cookies, service providers, purposes, categories, validity periods and any transfers outside the EEA is provided in the cookie settings.
Cookie collection:
14. Use of AI-assisted systems
We may use AI-assisted systems for limited tasks, such as:
- supporting the handling of customer service matters and enquiries
- classifying, summarising, translating or drafting messages, feedback and other materials
- providing a conversational assistant on the website or as part of customer service
- improving the quality, consistency and accuracy of customer and marketing data
- conducting analyses that support the development of services, communications and business operations.
In AI-assisted processing, the information listed in Section 5 may be processed only to the extent required by the original purpose of processing. We follow the principle of data minimisation and do not enter personal data or confidential material into AI services without a justified need and an approved method of use.
AI-generated content or recommendations are reviewed by a human when used to handle a matter concerning an individual or in external communications. We do not make decisions based solely on automated processing of data in the Customer and Marketing Register that produce legal effects concerning an individual or similarly significantly affect them.
If a user interacts directly with an AI system, we clearly inform the user of this at the beginning of the interaction. The conversation may be retained in order to handle the customer service matter, ensure the security of the service and improve quality, in accordance with the retention periods described in this Privacy Notice. Users are also given the option to continue the matter with a member of staff by email.
External AI service providers act as processors of personal data on behalf of UTU unless otherwise indicated in connection with a particular service. Service providers, processing locations, any transfers outside the EEA and retention periods are covered by the descriptions in Sections 7, 8 and 11.