Legal
This notice explains how Black Bird Group processes personal data. Under the General Data Protection Regulation a controller must inform data subjects clearly, and this notice discharges that duty.
Updated 9 September 2026.
Black Bird Group is two separate legal persons, and each is the controller for its own processing. Which one holds your data depends on how you contacted us:
The association owns the company.
Every request and question mentioned in this notice goes to that address.
Members of the association, and the employment and payroll data of either entity, are outside this notice.
Personal data is used only for purposes defined in advance:
We do not use personal data for advertising, and we do not profile visitors.
The free-text field holds whatever you choose to write. Please do not put confidential or classified information in it: it is an ordinary web form and it reaches an ordinary business inbox.
Each submission is written to a separate append-only log, which is not altered afterwards. Every entry holds:
v1-2026-09)The only purpose of this log is to show when and to what each person consented. It is not used for marketing, targeting or tracking.
Name, organisation, role, email address, telephone number, notes of contact, and information about engagements, offers and invoicing.
The web server records ordinary technical data: IP address, time and the address requested.
You have the rights below. Requests go to [email protected]. We may need to confirm your identity before releasing data.
You may check what personal data we hold about you, including the consent-log entries that concern you.
You may ask us to correct data about you that is wrong or incomplete.
You may object to processing if you believe it has been unlawful.
You may refuse the use of your data for direct marketing. The newsletter can be cancelled with the link at the end of every message, without giving a reason and without contacting anyone.
You may ask us to delete your data where processing is no longer necessary. We will either delete it or tell you the reason it cannot be deleted. Accounting material must be kept for the period set in the Finnish Accounting Act (chapter 2, section 10) and cannot be deleted before that expires.
Where processing rests on consent alone, you may withdraw it. Withdrawal does not affect the lawfulness of processing carried out before it. The log entry recording the withdrawal is kept, as the evidence that it was carried out.
You may also require us to restrict processing of disputed data until the matter is resolved.
You may complain to the Data Protection Ombudsman if you believe we are breaking data protection law: tietosuoja.fi.
Data comes from you:
We also use publicly available sources, such as an organisation's own website, to identify the right contact person. That rests on legitimate interest, and no address found that way is added to the newsletter.
No addresses are bought, rented or harvested for the newsletter. Only an address whose holder subscribed and confirmed by email is on it.
Personal data is not sold, and it is not disclosed for marketing purposes outside Black Bird Group. We use these service providers:
Subscriber and enquiry data sits in HubSpot. The consent log is kept on our own server instead, so demonstrating consent does not depend on an outside service.
This site loads no analytics, no advertising and no third-party scripts. Typefaces are served from this site rather than from a font service. It sets no cookies.
One thing is stored in your own browser, and it is not sent anywhere: on the map page, the time zone you last chose. Clearing your site data removes it.
There is one exception to the rule that our pages request nothing from other hosts. The base map under the front-line map is served by OpenFreeMap, which therefore receives your IP address and the address of the page you are on. It is contacted only on pages carrying a map, and only once that map loads. The front-line data itself does not leave this site: our own service reads it from Scribble Maps, so your browser never contacts them.
Personal data is kept only as long as it is needed for the purpose it was collected for. In practice:
| Data | Kept for |
|---|---|
| Newsletter subscription | until you unsubscribe, and removed after 24 months with no opens or clicks |
| Unsubscribed addresses | kept indefinitely, on a suppression list only |
| Enquiries that do not lead to work | 24 months |
| Customer records | the relationship, and three years after it ends |
| Consent-log entries | five years from the event recorded |
| Web-server logs | a fixed-size rolling buffer, oldest overwritten first; not archived |
| Accounting material | six years for vouchers, ten for the financial statements, from the end of the financial year |
The accounting periods are set by the Finnish Accounting Act (chapter 2, section 10) and are not ours to choose. The others are our decision, and we have set them against what the data is actually for: an address nobody has opened a message from in two years is hard to call a live subscription, and three years after a customer relationship ends matches the general limitation period for claims.
Web-server logs are described by the rule rather than by a number because that is what happens to them: they are written to a buffer of fixed size and the oldest entries are overwritten as new ones arrive. They are not archived anywhere.
Within Black Bird Group, personal data is handled by the people who need it for the purposes in section 3. Access to subscriber and customer data is limited to named accounts.
Processing is partly outsourced to the providers listed in section 7. In each case we ensure by contract that personal data is processed in accordance with data protection law.
Connections to the site are encrypted (TLS), and data is backed up regularly.
HubSpot is a United States company, but Black Bird Group's account is in its EU data region: contact details, enquiries and newsletter subscriptions are stored in the EU, not transferred out of it in the ordinary course of the service.
The site itself, and the consent log, are hosted in Finland.
Traffic to this site passes through Cloudflare's protection service, whose parent company is in the United States, so a visitor's IP address may be processed outside the EU in that connection.
Where data is transferred outside the EU or EEA, we ensure an adequate level of protection, including by agreeing terms on confidentiality and processing as the legislation requires.
We carry out no automated decision-making producing legal effects, and we do not profile visitors or subscribers. The newsletter goes to everyone who subscribed; it is not targeted on the basis of behaviour.