Data Controller
Data Controller: swype.fi (“The Service”)
Address: Riihimiehentie 2, 01720 Vantaa, Finland
Phone: +358 (0) 45 7833 1086
Email: hello (at) swype.fi
Data Subjects
The register processes the personal data of the Service’s subscribers and former subscribers, contact persons of organizations related to the Service’s operations, and its trustees (“Subscriber”).
Basis and Purpose of Processing Personal Data
The purpose of the register is the up-to-date management of Subscribers’ personal data during their membership, its maintenance and marketing, as well as the management of documentation for terminated memberships within the personal data system (“System”).
The processing of personal data is based on the Service’s legal obligation to maintain a membership register and, in certain cases, on the performance of a contract.
Processed Personal Data
The register processes the personal and contact details of the Service’s members, other necessary information related to the membership, and information added by the Subscriber themselves. This information includes:
User’s provided name
User’s phone number
User’s home address
User’s email address
Electronic communication identification data (e.g., IP address)
Information added by the User (via forms)
User’s physical location
Regular Sources of Information
Personal data is collected directly from the Subscriber themselves.
Protection of Personal Data and Data Security
Digitally processed personal data is protected and stored in the Service’s System, which is accessible only to those persons who require the data to perform their work duties. These individuals use personal user IDs and passwords.
Personal data is protected from unauthorized access, and the use of member data is monitored. Members have personal user IDs and password protection. Personal data sent outside the Service is encrypted. The workstations and storage media used are also encrypted.
Regular Disclosures and Transfers of Personal Data
Personal data may be disclosed to the Service’s partners to carry out operations and services related to the Service’s membership. Personal data is made available to independent partners connected to the Service to improve subscriptions. If a subscription is paid online, the following information is shared with the Service’s partner, Stripe Ltd. (Stripe Privacy Policy):
User’s full legal name
User’s payment card (in encrypted format)
User’s home address
User’s email address
User’s physical location
Personal data may also be transferred to other service providers for the implementation of the System. The controller’s partner responsible for the technical maintenance of the personal data register may transfer personal data in accordance with applicable privacy legislation and this privacy policy.
Transfers of Personal Data Outside the EU or the EEA
The Service may also use other service providers located outside the European Union (EU) or the European Economic Area (EEA) for processing personal data. The transfer of personal data outside the EU or the EEA is always carried out on one of the following lawful grounds:
The European Commission has decided that an adequate level of data protection is ensured in the recipient country.
The Service has implemented appropriate safeguards for the transfer of personal data by using standard data protection clauses approved by the European Commission. In this case, the Subscriber has the right to obtain a copy of these standard clauses by contacting the Service.
The Subscriber has given their explicit consent to the transfer of their personal data, or there is another lawful basis for the transfer.
Access to personal data is granted only to the extent necessary to provide the services. Transfers of personal data outside the EU or the EEA are always based on valid personal data processing legislation and are carried out in accordance with that legislation.
Retention Period of Personal Data
Personal data is kept in the register for as long as the Subscriber is a member of the Service. After the membership ends, personal data is stored for a maximum of ten years based on the Service’s legitimate interest, i.e., for defending against potential legal claims (Supreme Court precedent KKO 2017:15). Personal data may be stored longer if applicable legislation or the Service’s contractual obligations to third parties require an extended retention period.
Please also note that data backups affect the final removal of deleted data from information systems. If necessary, verify with the registry system’s service provider (e.g., from their contract or terms of use) how long they retain deleted data in backups.
Profiling
As part of its personal data processing activities, the Service may carry out automated profiling of the Subscriber. As a result of this profiling, the Subscriber will receive better-targeted marketing messages.
Subscriber’s Rights
The Subscriber has the right to object to the processing of their personal data for direct marketing purposes at any time. The Subscriber can provide the Service with channel-specific direct marketing consents and prohibitions (for example, prohibiting marketing messages sent by email).
Additionally, the Subscriber generally has the right, under applicable data protection legislation, to do the following at any time:
Receive information about the processing of their personal data;
Access their own data and review the personal data processed by the Service concerning them;
Demand the rectification of inaccurate or incorrect personal data and the completion of incomplete data;
Demand the erasure of their personal data;
Withdraw their consent and object to the processing of their personal data, insofar as the processing is based on the Subscriber’s consent;
Object to the processing of their personal data on grounds relating to their particular situation, insofar as the processing is based on the Service’s legitimate interest;
Receive their personal data in a machine-readable format and transmit those data to another data controller, provided that the Subscriber has provided the data to the Service themselves, the Service processes the data based on consent, and the processing is carried out by automated means; and
Demand the restriction of the processing of their personal data.
The Subscriber must submit requests concerning the exercise of the aforementioned rights via email, as outlined in this privacy policy. The Service may ask the Subscriber to specify their request in writing and verify their identity before processing the request. The Service may refuse to fulfill the request on grounds provided by applicable law.
Right to Lodge a Complaint with a Supervisory Authority
Every Subscriber has the right to lodge a complaint with the relevant supervisory authority, or the supervisory authority of the EU member state where their residence or workplace is located, if the Subscriber believes that their personal data has not been processed in accordance with applicable data protection legislation.
Contact Information
Requests concerning the exercise of Subscriber rights, questions about this privacy policy, and other inquiries should be made by email to hello (at) swype.fi. The Subscriber can also make contact in person or in writing at the address below:
Email: asiakaspalvelu@swype.fi
Company: Swype (Helpponetti Oy)
Address: Riihimiehentie 2, 01720 Vantaa, Finland
Changes to this Privacy Policy
This privacy policy may be updated from time to time, for example, due to changes in legislation. This privacy policy was last updated on May 24, 2026.