Privacy Policy

The NetTicket.fi´s legal statement and privacy policy

Use of the internet pages found under the address www.NetTicket.fi as well as the internet service and internet shop (henceforth “Services”) is restricted by the terms of use conditions given below. Use of the services requires the user to agree to abide by these terms of use. Any use of the service not complying with these conditions is prohibited. Read the conditions carefully.

The service follows official directives regarding personal information. All information is treated according to implemented directives. More information below.

The gathered personal information is used for delivering tickets, maintaining customer relations and to enable us to maintain the contact needed for the service. The customer must also provide contact details when booking a ticket; otherwise the purchase/booking of tickets will not be valid.

This information will not be given to a third party, except to the promoter whose event the customer has purchased a ticket for.
 

Database information according to Personal Data Act (523/1999) 10 § and 24 § and General Data Protection Regulation (GDPR) within EU.
Created 30.4.2018. Last modification 7.10.2026.

1. DATA CONTROLLER

Oy NetTicket Finland Ab
Harstadinkatu 4
65350 Vaasa

2. PERSON RESPONSIBLE FOR DATA MATTERS

Jonny Mandell
tel +358 40 5066011
jonny.mandell @ netticket.fi
 

3. DATABASE NAME

Customer, organizer and user databases required to maintain NetTicket Finland Oy:s ticket selling services 
 

4. PURPOSE OF USING PERSONAL INFORMATION

Personal information is used due to customer relationship, with the permission of the registered person, .

Personal information regarding a registered user is utilised to maintain customer relationships, develop, plan and analyse them, and to compile statistics. Personal information is also used to be able to offer services and products and develop them, as well as to follow-up and monitor misuse.

If the user chooses to log in with a Google account, the information received from Google is used only to identify the user, log the user in and create or link the user's NetTicket.fi user account.
 

5. DATABASE CONTENT

The personal database contains personal data of buying customers, handlers and suppliers

The database contains the following data:
- Name and company or society name if person represents a community
- Contact information (street address, postal code, city, mobil phone number, e-mail address)
- Information on permissions and refusals concerning direct marketing
- Information on customer relations, i.e. customer specific order history that has been stored in a database
- Logs and information needed between systems
- Usercode and password needed to use the service
- Google account identifier, if the user has logged in with a Google account
- Personal identification number och Business ID in the case of a credit transaction

When the user logs in with a Google account, the service receives the user's name, e-mail address and Google account identifier from Google. The user's Google password is never shared with the service.

The registry does not contain sensitive information.

The online store does not contain the customers' payment information, personal identifiers or ticket codes.

Personal data is stored as long as is needed to fullfill the purpose of the register or to comply with the storage time of laws and regulations, however, not less than the current year + 6 years and not more than the current year + 10 years.

6. DATABASE INFORMATION SOURCES

 The database contains
- information provided by the user in connection with the use of the service
- information provided by the customer during customer contact by phone, e-mail, onlineservices or other means of communication
- information about the use of the service stored by the user during the use of the web service
- information received from Google (name, e-mail address and Google account identifier) when the user chooses to log in with a Google account
 

7. REGULAR TRANSFER OF DATA

The service functions as a ticket agent for different events and the information is given to the promoter of the event in question.

The organizer may transfer personal data to subcontractors (eg transportation, accommodation, catering) that are necessary to produce the event. These act as a handler of the organizer's customer data.

Even the external services event organizers use to produce newsletters or automated marketing and information acts as a handler of the organizer's customer data.

Information of the subcontractors and other external services are handled by the event organizer.

As a handler of customer data acts:

- Visma Pay provides payment services,
- Link Mobility Oy provides NetTickets SMS-services and
- Newsletters and marketing automation are provided by Liana Technologies.
- Newsletters and marketing automation are provided by Hubspot.
- Digital mail services are provided by OmaPosti


Information will not be handed over to third parties.

Login with a Google account:

The user can choose to log in to the service with a Google account. The login takes place at Google, and Google LLC acts as an independent data controller for it in accordance with Google's own privacy policy (https://policies.google.com/privacy). The service does not hand over the customer's personal data, order history or other register data to Google.



8. TRANSFER OF INFORMATION OUTSIDE EU OR EEA

Information will not be transferred or handed over outside the EU or EEA.

If the user chooses to log in with a Google account, the login is handled by Google LLC, which may process data outside the EU or EEA. That processing is governed by Google's privacy policy.


9. PRINCIPLES FOR PROTECTION OF THE REGISTRY


Information will not be transferred or handed over outside the EU or EEA.

The data in the registry is used strictly and confidentially only by the employees and persons to whose work it belongs.

The users of the registry have a username and password that allows each login to be verified and identified.

Due to the technical nature of handling data, certain parts of the data collected can physically be located on a server maintained by a third party, where it is handled using a encrypted user contact. The data collected is stored in common databases, which are protected by firewalls, passwords and other technical solutions. The databases and backups are located in locked and guarded premises, and access to the information is restricted.

Manual material is stored in locked spaces accessible only to those entitled to information.


10. RIGHT OF ACCESS

The data subject have once a year the right to free of charge control the information stored concerning themselves.

An informal request for verification must be made in writing, by email or by submitting it personally to the data controller.

Identifying a person from the system also requires notification of a mobile phone number and / or email address.

The identity of the customer is verified before handing over the information and the material is delivered by email as a rule within 30 days.



11. THE RIGHT TO SEEK INFORMATION CORRECTED

The data subject has the right to request that his or her information contained in the register must be corrected or to supplement the incomplete information.

An informal correction request must be made in writing, by email or by submitting it personally to the data controller.

Identifying a person from the system also requires notification of a mobile phone number and / or email address.

The identity of the customer is verified before the data is corrected and the information is corrected within 30 days.


12. OTHER RIGHTS CONCERNING HANDLING OF PERSONAL DATA

The data subject has the right to refuse access to direct mail, distance selling and other direct marketing as well as market and opinion surveys.

An informal direct marketing prohibition must be made in writing, by email or by submitting it personally to the data controller.

Identifying a person from the system also requires notification of a mobile phone number and / or email address.

Direct marketing authorization data will be updated to personal data without delay or within 30 days at the latest.

A user who has logged in with a Google account can at any time remove the service's access to the Google account in the Google account settings (https://myaccount.google.com/connections). The Google account identifier stored in the register is removed on request in the same way as other personal data.

The data subject has the right to request the removal of personal data relating to him or to transfer it to another.

An informal removal or transfer request must be made in writing, by email or by submitting it personally to the data controller.

The identity of the customer is ensured prior to handing over the transfer data and the transfer data is sent by email as a rule within 30 days.

Personal data will be deleted (anonymization) and data deletion will be made within the storage time of laws and regulations.

If the data controller does not delete all personal data, he or she must issue a written certificate stating the reasons why the information was not immediately removed.


13. GOOGLE USER DATA

This section describes how NetTicket.fi handles data received from Google when a user chooses to log in with a Google account. Logging in with Google is optional. The service can also be used with a NetTicket.fi user account or as a guest.

Data accessed: When you log in with Google, NetTicket.fi receives only your name, your e-mail address, information on whether Google has verified the e-mail address, and your Google account identifier. NetTicket.fi does not access any other data in your Google account, such as your contacts, calendar, files or e-mails, and never receives your Google password.

Data usage: The data is used only to identify you, log you in and create or link your NetTicket.fi user account. As with all user accounts, the e-mail address is used to deliver your tickets and order confirmations. Google user data is not used for advertising, and it is not used for marketing unless you have separately given permission for direct marketing.

Data sharing: NetTicket.fi does not sell Google user data and does not share, transfer or disclose it to third parties. The only exception is that, as with every order, the name and e-mail address of a customer who buys tickets are given to the organizer of the event in question (see section 7).

Data protection: Google user data is stored in the same protected customer database as other personal data and is protected as described in section 9. All data is transferred over encrypted (HTTPS) connections, and the login is confirmed directly between NetTicket.fi's server and Google.

Data retention and deletion: Google user data is stored for as long as your user account exists, within the storage times described in section 5. You can request deletion of your data as described in section 12, and the Google account identifier is then removed together with your other personal data. You can also remove NetTicket.fi's access to your Google account at any time in your Google account settings (https://myaccount.google.com/connections).

Limited Use: NetTicket.fi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Google user data is not sold, not used for advertising, not used to determine credit-worthiness or for lending purposes, and not used to develop, improve or train artificial intelligence or machine learning models.