This description is based on EU General Data Protection Regulation (679/2016) and Personal data act (523/1999)
Date of drafting: 24 May 2019

1. Subject of the privacy policy: Database of registered users of Apros Forum.

2. Controller, Data Protection officer and Contact person:
Controller

Name: VTT Technical Research Centre of Finland Ltd ("VTT"), Business ID 2647375-4
Address: Vuorimiehentie 3, FI-02150 Espoo, Finland

Data protection officer
Name: Seppo Viinikainen
Address: VTT Technical Research Centre of Finland Ltd, Koivurannantie 1, FI-40400 Jyväskylä, Finland
Email address: tietosuoja@vtt.fi or seppo.viinikainen@vtt.fi

Contact person
Name: Pasi Laakso
Address: VTT Technical Research Centre of Finland Ltd, Kivimiehentie 3, FI-02044 VTT, Finland
Email address: apros.support@vtt.fi or pasi.laakso@vtt.fi

3. Handled user information and user groups: Stored information includes Email address, Company (if applicable), First name, Second name, date of registration and last activity, Time zone and all the messages user has written to Apros-forum. System also logs activity data including e.g. which pages in the forum have been visited and when.

Handled user groups are either users of Apros-forum or user registered to it.

4. The purpose of processing personal data and its legal justification: The data is stored to offer services to Apros customers and verify that is eglible to use its services. Apros-forum is used to inform users that can use Apros-Forum to ask and comment the functionality of Apros.

The legal justification for storing the data is either direct contract relation between VTT and the customer or because of customer requesting Apros-Forum services.

Storing personal data is necessary to give Apros-Forum services and to form a contract relationship between the data subject and the controller.

5. User Data source: Information is given by the user during the registration. The date of registration and last activity information are collected automatically.

6. Regular destinations of disclosed data: Data is not disclosed by VTT to other parties. However some of the personal data can be read manually by any registered user.

7. Transfer of personal data to countries outside the the European Union or the European Economic Area: Data is not disclosed outside of European Union or European Economic Area.

8. Automatic decision making, profiling: Personal data stored shall not be used for profiling or automated decision making.

9. Time limit of storing personal data: Information shall be permanently kept in the system unless users requests removal. At that case user data is anonymized from the system.

10. The principles how the data file/register is secured: Data is stored to Linux server located in to the internet. It has a limited number of Administrators that have access to all the data stored and are committed to keep the data secure. Personal data is stored to mysql database and User management is done using system provided by vBulletin Forum software. User roles are Administrator and regular user. Administrators have access to all information. Regular users can see partial information of the other Regular users.

No manual register is related to the Apros-forum database.

11. Rights of the data subjects: Data subjects have the following rights. These could be limited or there could be exceptions based on the Data Protection Regulation.

Data subject can fulfill these right via contacting to the contact person of the controller mentioned in the item 2, preferably via email using the email address used to register the data to the database. The controller has rights to ask further information to verify the identity of the data subject.