Thinkin' Rocks

Privacy policy

Last updated:

This policy explains how Thinkin'Rocks Oy (TR) and its owner, Hardware Systems Alliance Ry (HSA), use personal data for events, community activities, support programmes, memberships, and commercial services.

For any privacy question or request, email team@thinkinrocks.com.

Data controllers

  • Shared events: TR and HSA are joint controllers for registration and event administration. Any different arrangement is identified when you register.
  • HSA: association membership, community chats, support programmes, community communications, and fundraising.
  • TR: paid services, commercial memberships, customer relationships, and marketing.

For jointly controlled activities, you can contact either organisation through our shared email address to exercise your rights or request details of how responsibilities are divided for a particular activity.

Information we collect

Depending on the activity, we collect your name, contact details, organisation, profiles you share, application and project information, registration and attendance details, membership status, payment records, messages, feedback, and subscription preferences. Our website also processes technical information, including IP addresses and security logs.

Information comes from you, services used for registration or payment, a person registering your team, and activity organisers. We may review public professional profiles you include in an application.

Use of information

  • Registrations, memberships, and services: to handle requests, deliver activities, and send related updates, based on our agreement with you or steps taken at your request before an agreement.
  • Applications and administration: to assess applications, allocate support, answer enquiries, improve activities, and prevent misuse, based on our legitimate interests in running our community and services.
  • Record keeping: to meet association, accounting, and other legal obligations.
  • Communications and marketing: to send newsletters, event invitations, TR promotions, and HSA fundraising updates according to your subscriptions, based on consent.

Forms identify required information. Without it, we may be unable to process your request. Applications are reviewed by people, without solely automated decisions that have legal or similarly significant effects.

Sharing and service providers

Authorised staff, volunteers, reviewers, and service providers access data as needed for their work. Providers support hosting, registration, email, payments, and security under appropriate data protection terms. Relevant information may also be shared with organisers, mentors, or funding partners as described for the activity, or where required by law.

External registration, payment, and community services have their own privacy notices for data they use for their own purposes.

International transfers

Some providers may process data outside the European Economic Area. These transfers require safeguards such as a European Commission adequacy decision or standard contractual clauses. Details and copies of applicable safeguards are available on request.

Data retention

We keep registration, application, and membership records for the activity or relationship and its related follow-up and reporting. Payment and funding records follow applicable legal and funding requirements. Enquiries and security logs are kept as needed to resolve issues. Subscription records are kept until you unsubscribe or the purpose ends, with a minimal record retained to respect your preferences. Data is then deleted or anonymised unless needed for a legal obligation or claim.

Your rights and contact

Under applicable data protection law, you can request access, correction, deletion, restriction, or portability of your data, and object to processing based on legitimate interests. You can object to direct marketing or withdraw consent at any time. Withdrawal does not affect processing carried out lawfully beforehand.

Use the unsubscribe link in an email or contact team@thinkinrocks.com. We normally respond to rights requests within one month. You can also lodge a complaint with Finland's Office of the Data Protection Ombudsman or another competent data protection authority.

Changes to this policy

We update this policy when our practices change. The date above shows the latest revision. We provide notice of material changes where required.