Privacy Notice

Last updated: 24 Aug 2026

This notice explains how 1001 Lakes Oy handles personal data. It
covers our website, our client and partner relationships, our
recruitment, and our employment relationships.

Who we are

1001 Lakes Oy (business ID 2960382-5) is the controller of the
personal data described in this notice.

Porkkalankatu 5, 00180 Helsinki, Finland info@1001lakes.com

We have not appointed a data protection officer, because we are not
required to do so under Article 37 of the GDPR. Privacy questions go to
the address above.

What we process, why, and
on what basis

Client and partner contacts

We process the name, role, work contact details and correspondence of
the people who represent our clients, suppliers, subcontractors and
project partners. We use this to manage the relationship, deliver our
services, run procurement, and report to funders in EU-funded
projects.

Our basis is our legitimate interest in maintaining business
relationships (Article 6(1)(f)). Our contract is with your organisation,
not with you personally, so we rely on legitimate interest rather than
contract. Where an EU grant agreement or accounting law requires us to
keep records, our basis is our legal obligation (Article 6(1)(c)).

Assignment material

When we carry out an assignment, the working material may contain
personal data — normally the contact details of the people involved, and
any other personal data that is necessary for the assignment itself. We
do not seek out personal data we do not need, and we do not process
special categories of personal data in client assignments.

Our basis is our legitimate interest in performing the assignment we
have agreed with your organisation (Article 6(1)(f)).

Prospective
clients, event participants and newsletter recipients

We process names, organisations and work contact details in order to
send newsletters, invitations and information about our services.

Our basis is our legitimate interest in marketing our services to
organisations (Article 6(1)(f)). Where you have subscribed yourself, we
also rely on your consent (Article 6(1)(a)), which you can withdraw at
any time. Every message we send contains a one-click way to stop
receiving them.

Website visitors

Our website is at 1001lakes.com. When you visit it, the following
happens.

Cookies and consent. We use Cookiebot to ask for
your consent before any non-essential cookie is placed on your
device.

Analytics. We use Google Analytics 4 to see how our
site is used in aggregate. We run it with Google Consent Mode, which
means that unless you consent, no analytics cookies are stored
on your device
. Your IP address and a session-specific
identifier are still sent to Google so that we can count visits. We do
not use this to profile you or to build a picture of you as an
individual.

Spam protection. We use Google reCAPTCHA to protect
our contact form from automated abuse.

Fonts. Our site loads typefaces from Google
Fonts.

Our basis for all of the above is our legitimate interest in running
a functioning, secure website and understanding in general terms how it
is used (Article 6(1)(f)), except where we ask for your consent, in
which case our basis is your consent (Article 6(1)(a)).

People who contact us

If you use our contact form or write to us, we process your name,
contact details and whatever you tell us, so that we can answer.

Our basis is our legitimate interest in responding to enquiries, or,
if your message concerns a possible engagement, the steps taken at your
request before entering into a contract (Articles 6(1)(f) and
6(1)(b)).

Meeting participants

We sometimes record meetings using Microsoft Teams, so that we have
an accurate record and do not have to take notes during the discussion.
Teams shows everyone in the meeting a notice when recording
starts.
Recordings and transcripts stay inside our Microsoft
365 environment.

Our basis is our legitimate interest in documenting our work
accurately (Article 6(1)(f)). If you would rather not be recorded, tell
us and we will not record.

Job applicants

We process the application, CV, references and related correspondence
of people who apply to work with us, so that we can run the
recruitment.

Our basis is our legitimate interest in recruiting (Article 6(1)(f)).
For open applications sent to us on your own initiative, our basis is
your consent (Article 6(1)(a)). Under Finnish employment privacy law we
collect information primarily from you; if we need to get it elsewhere,
we will ask you first.

Employees,
the managing director, shareholders and board members

We process the personal data needed to run employment and management
relationships and to meet our obligations as an employer and as a
limited company — including pay, working time, absences, project hours,
shareholdings and beneficial ownership.

Our basis is the contract with you and our legal obligations
(Articles 6(1)(b) and 6(1)(c)). Sickness absence data is processed to
meet our obligations in employment law (Article 9(2)(b)).

Where we get your data

Most of the time, we get your data from you, or from the organisation
you represent.

We also collect work contact details from publicly available sources,
from events we take part in or organise, and from people who introduce
us. If you are on our newsletter list and would like to know where we
got your details, ask us and we will tell you.

Who else sees it

We use service providers who process personal data on our behalf
under a written agreement:

  • Microsoft 365 — email, files, meetings and
    recordings
  • Visma Severa — project and time management
  • Visma Netvisor — financial administration
  • iCount Partners Oy — payroll and accounting
  • Cookiebot, Google — website consent management,
    analytics, spam protection and fonts

We also disclose personal data where the law requires it, or where an
EU grant agreement requires us to report to the funder. We do not sell
personal data, and we do not disclose it for anyone else’s
marketing.

Transfers outside the EU and
EEA

Microsoft has stated that it completed its EU Data Boundary in
February 2025, and that customer data and pseudonymised personal data in
its core cloud services are stored and processed within the EU and EFTA.
Limited transfers may still occur, for example for security
purposes.

The Google services on our website (Analytics, reCAPTCHA, Fonts)
involve transfers to Google LLC in the United States. These rely on the
European Commission’s adequacy decision for the EU–US Data Privacy
Framework.

Where a service provider is outside the EU and EEA and no adequacy
decision applies, we use the European Commission’s Standard Contractual
Clauses.

How long we keep it

What How long
Client and partner contacts 2 years after the relationship ends
Assignment material 10 years after the assignment ends, because claims under Finnish law
can be raised for that long
Newsletter and marketing list Removed immediately when you opt out; otherwise after 24 months of
no engagement
Meeting recordings 120 days; anything we need from a recording is written into the
assignment file before the recording expires
Enquiries 12 months, unless they lead to an engagement
Job applications 60 months after the recruitment closes
Employment records 10 years after employment ends, or longer where the law
requires
Accounting records Financial statements and ledgers 10 years from the end of the
financial year; vouchers and business correspondence 6 years from the
end of the year in which the financial year ended, as required by the
Finnish Accounting Act
Shareholder register Kept for as long as the company exists

Where different periods apply to the same data — for example, where a
contact detail also appears on an invoice — the longest applicable
period governs.

Your rights

You can ask us to:

  • give you a copy of the personal data we hold about
    you
  • correct anything that is wrong or incomplete
  • delete your data, where we have no continuing basis
    or obligation to keep it
  • restrict how we use it while a dispute or a
    correction request is being resolved
  • transfer data you gave us to another provider,
    where the processing is based on consent or a contract and is
    automated
  • stop processing based on legitimate interest, by
    objecting on grounds relating to your situation

Direct marketing is different. If you object to
direct marketing, we stop. There is no balancing test and you do not
need to give a reason.

Withdrawing consent. Where our processing is based
on your consent, you can withdraw it at any time. Withdrawing consent
does not affect processing that happened before you withdrew it.

To use any of these rights, write to info@1001lakes.com. We may need
to confirm who you are before we act.

Automated decision-making

We do not make decisions about you by automated means, and we do not
profile you.

Do you have to give us your
data?

No — but if you do not give us the contact details we need, we may
not be able to work with your organisation, answer your enquiry, or
consider your application. For employees, some data is required by law
and we cannot run the employment relationship without it.

Complaints

If you think we have handled your data wrongly, please tell us first
— it is usually the fastest way to fix it.

You can also complain to the Finnish Data Protection Ombudsman:

Tietosuojavaltuutetun toimisto PL 800, 00531 Helsinki
tietosuoja.fi

Changes to this notice

We update this notice when our processing changes. The date at the
top tells you when it was last changed.

This notice is published in English, Finnish and German. If the
versions differ, the English version applies.