Legal

Privacy notice

This notice explains how Black Bird Group processes personal data. Under the General Data Protection Regulation a controller must inform data subjects clearly, and this notice discharges that duty.

Updated 9 September 2026.

1. Controller

Black Bird Group is two separate legal persons, and each is the controller for its own processing. Which one holds your data depends on how you contacted us:

  • Black Bird Group ry (Register of Associations 3388403-3) — the think tank. Controller for the public newsletter and for general and media enquiries.
  • Black Bird Group Oy (Business ID 3651724-7, registered in Espoo) — the company. Controller for commercial enquiries sent through the form on the business site, and for customer relationships.

The association owns the company.

Contact in matters concerning this register

[email protected]

Every request and question mentioned in this notice goes to that address.

2. Data subjects

  • Newsletter subscribers — people who subscribed through the form on this site and confirmed by email.
  • People who send an enquiry — those who used the form on the business site, or wrote to us directly.
  • Customers — contact people at client organisations with an engagement or a contract.
  • Site visitors — so far as technical data is processed to run the site and keep it secure.

Members of the association, and the employment and payroll data of either entity, are outside this notice.

3. Purpose of processing

Legal basis

  • The newsletter rests on consent (Article 6(1)(a)).
  • Enquiries and customer relationships rest on a contract, or steps taken before entering one (Article 6(1)(b)).
  • Accounting is a legal obligation (Article 6(1)(c)).
  • Keeping the site running and secure, and contacting representatives of organisations, rest on legitimate interest (Article 6(1)(f)).

What the data is used for

Personal data is used only for purposes defined in advance:

  • sending the newsletter
  • answering enquiries and discussing possible work
  • managing customer relationships and delivering engagements
  • invoicing and accounting
  • keeping the site running and secure

We do not use personal data for advertising, and we do not profile visitors.

4. Personal data collected

Newsletter subscribers

  • email address (required)

The enquiry form

  • first name and last name (required)
  • country (required)
  • organisation (required)
  • email address (required)
  • telephone number (optional)
  • what you tell us you are working on (optional, free text)

The free-text field holds whatever you choose to write. Please do not put confidential or classified information in it: it is an ordinary web form and it reaches an ordinary business inbox.

Consent records

Each submission is written to a separate append-only log, which is not altered afterwards. Every entry holds:

  • email address
  • which form was used
  • the time, in UTC
  • the IP address the form was sent from
  • the browser identification string (user agent)
  • the wording of the consent shown to you, and its version (currently v1-2026-09)

The only purpose of this log is to show when and to what each person consented. It is not used for marketing, targeting or tracking.

Customers

Name, organisation, role, email address, telephone number, notes of contact, and information about engagements, offers and invoicing.

Site visitors

The web server records ordinary technical data: IP address, time and the address requested.

5. Your rights

You have the rights below. Requests go to [email protected]. We may need to confirm your identity before releasing data.

Right of access

You may check what personal data we hold about you, including the consent-log entries that concern you.

Right to rectification

You may ask us to correct data about you that is wrong or incomplete.

Right to object

You may object to processing if you believe it has been unlawful.

Direct marketing

You may refuse the use of your data for direct marketing. The newsletter can be cancelled with the link at the end of every message, without giving a reason and without contacting anyone.

Right to erasure

You may ask us to delete your data where processing is no longer necessary. We will either delete it or tell you the reason it cannot be deleted. Accounting material must be kept for the period set in the Finnish Accounting Act (chapter 2, section 10) and cannot be deleted before that expires.

Withdrawing consent

Where processing rests on consent alone, you may withdraw it. Withdrawal does not affect the lawfulness of processing carried out before it. The log entry recording the withdrawal is kept, as the evidence that it was carried out.

You may also require us to restrict processing of disputed data until the matter is resolved.

Right to complain

You may complain to the Data Protection Ombudsman if you believe we are breaking data protection law: tietosuoja.fi.

6. Sources of data

Data comes from you:

  • the newsletter form on this site
  • the enquiry form on the business site
  • email, telephone or meetings, in a customer relationship or in preparing one

We also use publicly available sources, such as an organisation's own website, to identify the right contact person. That rests on legitimate interest, and no address found that way is added to the newsletter.

No addresses are bought, rented or harvested for the newsletter. Only an address whose holder subscribed and confirmed by email is on it.

7. Disclosures and processors

Personal data is not sold, and it is not disclosed for marketing purposes outside Black Bird Group. We use these service providers:

  • HubSpot, Inc. (United States, with this account in its EU data region) — customer relationship management, the newsletter subscriber register and message sending.
  • Cloudflare, Inc. (United States, servers in the EU) — traffic routing and protection for this site; visitors' IP addresses pass through it.
  • Hosting, in Finland — the site and the consent log run on servers in Finland, operated on Black Bird Group's behalf.
  • An accounting provider, once one is appointed.

Subscriber and enquiry data sits in HubSpot. The consent log is kept on our own server instead, so demonstrating consent does not depend on an outside service.

The site itself

This site loads no analytics, no advertising and no third-party scripts. Typefaces are served from this site rather than from a font service. It sets no cookies.

One thing is stored in your own browser, and it is not sent anywhere: on the map page, the time zone you last chose. Clearing your site data removes it.

There is one exception to the rule that our pages request nothing from other hosts. The base map under the front-line map is served by OpenFreeMap, which therefore receives your IP address and the address of the page you are on. It is contacted only on pages carrying a map, and only once that map loads. The front-line data itself does not leave this site: our own service reads it from Scribble Maps, so your browser never contacts them.

8. Retention

Personal data is kept only as long as it is needed for the purpose it was collected for. In practice:

DataKept for
Newsletter subscriptionuntil you unsubscribe, and removed after 24 months with no opens or clicks
Unsubscribed addresseskept indefinitely, on a suppression list only
Enquiries that do not lead to work24 months
Customer recordsthe relationship, and three years after it ends
Consent-log entriesfive years from the event recorded
Web-server logsa fixed-size rolling buffer, oldest overwritten first; not archived
Accounting materialsix years for vouchers, ten for the financial statements, from the end of the financial year

The accounting periods are set by the Finnish Accounting Act (chapter 2, section 10) and are not ours to choose. The others are our decision, and we have set them against what the data is actually for: an address nobody has opened a message from in two years is hard to call a live subscription, and three years after a customer relationship ends matches the general limitation period for claims.

Web-server logs are described by the rule rather than by a number because that is what happens to them: they are written to a buffer of fixed size and the oldest entries are overwritten as new ones arrive. They are not archived anywhere.

9. Who processes the data

Within Black Bird Group, personal data is handled by the people who need it for the purposes in section 3. Access to subscriber and customer data is limited to named accounts.

Processing is partly outsourced to the providers listed in section 7. In each case we ensure by contract that personal data is processed in accordance with data protection law.

Connections to the site are encrypted (TLS), and data is backed up regularly.

10. Transfers outside the EU

HubSpot is a United States company, but Black Bird Group's account is in its EU data region: contact details, enquiries and newsletter subscriptions are stored in the EU, not transferred out of it in the ordinary course of the service.

The site itself, and the consent log, are hosted in Finland.

Traffic to this site passes through Cloudflare's protection service, whose parent company is in the United States, so a visitor's IP address may be processed outside the EU in that connection.

Where data is transferred outside the EU or EEA, we ensure an adequate level of protection, including by agreeing terms on confidentiality and processing as the legislation requires.

11. Automated decision-making and profiling

We carry out no automated decision-making producing legal effects, and we do not profile visitors or subscribers. The newsletter goes to everyone who subscribed; it is not targeted on the basis of behaviour.