Privacy policy

Processing of personal data of clients and partners of Eversheds Attorneys Ltd (“Eversheds”) and processing of personal data related to marketing

Data processing in a nutshell

  • We collect your personal data for customer relationship management, business development and marketing planning, among other things.
  • The data we process is data that you provide yourself, for example, in connection with assignments or that we have acquired from various directories, registers and other public data sources, such as the Population Information System and credit information registers.
  • We process your personal data when handling an assignment and sending customer communications or marketing material.
  • We respect your privacy in all processing we carry out. We do not process data that can be directly linked to you unless it is necessary for the purposes of the processing.
  • You can influence how we process your personal data. We will inform you about your rights as a data subject and how you can exercise them in the section Rights of the data subject.

Who processes your data?

Eversheds Attorneys Ltd, Business ID: 2556202-6, address Fabianinkatu 29 B, 00100 Helsinki and Heinonen &; Co, Attorneys-at-Law, Ltd. | Fabianinkatu 29 B, 00100 Helsinki, Finland (together “we”) processes your personal data as a controller for the purpose of carrying out assignments, implementing cooperation or marketing.

Who can you contact regarding data protection Issues?

If you have questions about data protection or want to exercise your rights, you can contact:

Eversheds Attorneys Ltd
Data protection organisation
Fabianinkatu 29 B
FI-00100 Helsinki
tietosuoja@eversheds.fi 

We make changes to this privacy policy as necessary and whenever the ways or purposes of processing your personal data change. You should check the privacy policy regularly.

If you visit our website ([https://www.eversheds-sutherland.com/fi/finland], Eversheds Sutherland may process information collected through cookies, such as your location when you visit our website, which parts of our website you visit and which browser you use. More detailed information on the use of cookies is available in our Cookie Policy [here]. If you visit our newsroom website ([https://www.newsroom.eversheds.fi], we process information collected through cookies, such as where you visit our website, which parts of our website you visit and which browser you use. More detailed information on the use of cookies is available in our Cookie Policy [here].

Our company has a reporting channel, the privacy policy of which can be found [here].

The privacy policy for job applicants can be found [here].

What personal data do we process?

We process the following basic information about you in order to manage the customer relationship and for marketing, such as:

  • Name and, in the case of private customers, personal identity code
  • Contact information: address, telephone number and e-mail address
  • Particular interests, profession and position in the company, if the marketing is aimed at the company you work for or if you represent a corporate customer

Information related to the customer relationship:

  • Communication and communication related to the customer relationship
  • to carry out assignments, e.g. with: Our client’s counterparty or counterparty’s representative, our client’s customers, the client’s personnel member or other contractual partner, depending on the nature of the assignment, another person related to the assignment.
  • Information related to invoicing and debt collection
  • information related to customer due diligence required by law. Identification data of our private customers, company representatives and beneficiaries; identification data referred to in the Act on the Prevention of Money Laundering and Terrorist Financing (444/2017) (e.g. name, date of birth, personal identity code, nationality, passport copy and information to determine the customer’s financial position and level of political influence).
  • Information related to insider assignments and rules , including personal identity code or date of birth, nationality, information related to employment or service relationship (e.g. organisation, job title), insider’s role and reason why the person has been entered in the insider list, information on position in the company’s management or membership of the board, copy of passport or driving licence or identification of such document, ownership and affiliation information information on transactions, whether the person, currently or in the past, a politically exposed person or a family member or associate of such a person. In addition, whether the person is subject to EU sanctions.
  • For some assignments, we need to process special categories of personal data, such as data concerning health and personal identification numbers of persons related to criminal convictions, offences and security measures.
  • In certain situations, if identification with online banking credentials is not possible, we process biometric data to know the customer. We use Suomen Tunnistetieto Oy, which acts as an independent controller when processing personal data, to know our customers.
    • – We process the data described above only to the extent necessary to comply with our legal obligations and carry out the assignment.
  • Information about appointments

Marketing and event related information

  • Interest information you have provided
  • your participation in training and customer events
  • marketing activities targeted at you and information you provide or receive in connection with them

We use the Lime CRM system. Lime collects information about the targeted interest and use of our newsroom.eversheds.fi pages and services through automated data collection, and uses the information for various statistical and analytical purposes. Lime may also provide Users with relevant information related to the Services, such as sending targeted product news and information about relevant features of the Services. Personal data may be processed in connection with data processing and communications. Lime is the data controller for this processing. By entering into this Agreement, the Customer expressly consents to the processing of personal data by Lime for communication purposes. Lime will process personal data for these purposes only to the extent necessary for these purposes. Lime shall ensure appropriate data security during the processing of the data. Lime’s Privacy Policy, which describes the processing of personal data (linkki).

  • direct marketing permissions and prohibitions

Partner information

  • Name
  • Name and position of the company representative in the company (when the partner is a company)
  • Contact information (email address, phone number, address)

For what purposes do we process your personal data?

We process your personal data for the execution of assignments and for the management, analysis and development of customer relationships, including electronic customer communications, as well as opinion polls and market research. In addition, we may use your personal data to analyse, plan and develop the business of Eversheds and companies belonging to the same group from time to time.

We process your personal data for planning, targeting, sending, developing and implementing marketing. If you are a partner or a representative of a partner, we process your data in order to carry out the cooperation.

On what basis do we process your data?

We process your data to provide you with the offer you have requested and to prepare and execute the assignment agreement or cooperation agreement.

We also process your data on the basis of a customer relationship or potential customer relationship, or on the legitimate interest created by the customer relationship or possible customer relationship of the company you represent, and on the basis of a statutory obligation to know your customer.

We process your personal data on the basis of your consent when we ask for your marketing consent to send direct marketing and newsletters. You may withdraw your consent at any time by notifying tietosuoja@eversheds.fi.

Where do we get your personal data from?

If you are our customer, we primarily collect your personal data from you when we enter into an assignment agreement with you.

If you represent a corporate customer, we will primarily collect your data from you. We may also receive your information from the corporate customer you represent. We collect your data from websites and other public sources, from the business information service provided by Asiakastieto Oy and from other commercial operators, which provide information about companies and their representatives.

In order to identify our customers, we search for information on beneficial owners and company representatives from the limited liability companies register, remember from the registers

We also collect personal data when administering our marketing activities and communicating with data subjects for marketing purposes. For example, we collect personal data to send invitations to our seminars and events or to send newsletters or other news related to our services and company.

We collect your personal data primarily from you if you have subscribed to our newsletter to receive event invitations and news about our services and company. You can unsubscribe at any time to stop receiving this information.

We also collect personal data from you if you participate in surveys or report subscriptions.

If you have been one of our employees, you are part of our alumni network. Your contact information may be in our alumni register to communicate and send invitations to alumni events or to exchange ideas with you. You can unsubscribe at any time to stop receiving this information.

To whom do we disclose your personal data?

We disclose your personal data within the limits permitted and required by current legislation and good legal practice. We disclose personal data when required for the execution of assignments to authorities, courts and counterparties, other law firms belonging to the Eversheds Sutherland chain and our subsidiary Heinonen &; Co Attorneys Ltd. In order to check if we have a conflict of interest. We disclose personal data (mainly the customer’s name and contact person, as well as the nature of the assignment) to Eversheds Sutherland LLP in the UK. As Eversheds Sutherland is a network that operates globally, we sometimes need to transfer your personal data outside the EU or EEA. Transfers of personal data to third countries always take place on the basis of transfer in accordance with the General Data Protection Regulation. Primarily, we have ensured an adequate level of data protection in accordance with the requirements of the EU’s General Data Protection Regulation in situations where data is transferred outside the EU or EEA by complying with the equivalence decisions issued by the European Commission. If we transfer your personal data to a country for which an adequacy decision has not been made, we will use standard contractual clauses and additional safeguards approved by the European Commission.

In order to handle assignments, we have outsourced the processing of clients’ personal data to the following service providers who process your personal data on our behalf:

  • Document management system providers
  • Virtual Data Room (VDR) for system providers
  • Signature and authentication solution providers  

In order to maintain customer relationships and for marketing purposes, we have outsourced the processing of personal data to the following service providers who process your personal data on our behalf:

  • Communication service providers
  • Event invitation and marketing tool providers
  • Customer management tool providers

If we organise marketing events in cooperation with other partners and you register for such events, we will share your contact information with the co-organisers.

Joint controllers

Social media programs and websites process your data as joint controllers with us, and you can read about their privacy policies on the services’ own websites.

Contact details for Meta Platforms Ireland and their Data Protection Officer are available in the Meta Platforms Ireland Privacy Policy at https://www.facebook.com/about/privacy. The Meta Platforms Ireland Privacy Policy applies to most services and products offered by Meta, including Instagram.

For more information about Meta Platforms Ireland’s processing of personal data, including the legal basis on which Meta Platforms Ireland relies and how to exercise your rights with respect to Meta Platforms Ireland, please read Meta Platforms Ireland’s Privacy Policy at https://www.facebook.com/about/privacy.

Contact details of LinkedIn Ireland and their Data Protection Officer and information about LinkedIn Ireland’s processing of personal data, including how to exercise your rights with respect to LinkedIn Ireland, are available in LinkedIn Ireland’s Privacy Policy at https://www.linkedin.com/legal/privacy-policy.

For more information about YouTube and Google and the way they process personal data, including information on how you can exercise your rights with respect to YouTube and Google, is available at https://policies.google.com/privacy?hl=fi.

What rights do you have?

You can exercise your rights by contacting tietosuoja@eversheds.fi or

Eversheds Attorneys Ltd
Data protection issues
Fabianinkatu 29 B
FI-00100 Helsinki

Right of access

You have the right to receive confirmation from us as to whether we process personal data concerning you. You also have the right to access your personal data and information on the processing of your personal data in accordance with the General Data Protection Regulation.

When you exercise your right of access, we will provide you with a copy of the personal data we process about you. If you request multiple copies, we may charge a reasonable fee based on administrative costs.

Some of the data we process is subject to a special obligation of secrecy and secrecy based on legislation and good legal practice, which prevents the implementation of the right of access to the data.

Right to rectification

You have the right to ask us to rectify inaccurate and incorrect data without undue delay. You also have the right to have incomplete personal data supplemented by providing us with additional information.

Right to erasure

You have the right to obtain from us the erasure of your personal data without undue delay if:

  • your personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
  • you withdraw the consent on which the processing is based and there is no other legal basis for processing the data in question;
  • you object to the processing of your personal data on grounds relating to your particular situation and there are no overriding legitimate grounds for the processing, or you object to the processing of your personal data for direct marketing purposes;
  • we have processed personal data unlawfully; or
  • Personal data must be erased in order to comply with a legal obligation to which we are subject.

Right to restriction of processing

You have the right to have us restrict the processing of your personal data so that, in addition to storage, your personal data may only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person if:

  • you contest the accuracy of your personal data, in which case we will restrict processing for the duration of verifying the accuracy of the data;
  • we process your personal data unlawfully and you object to the erasure of your personal data and request the restriction of the use of your personal data instead;
  • we no longer need your personal data for the purposes of the processing, but you need it for the establishment, exercise or defence of legal claims; or
  • you have objected to the processing of your personal data on grounds relating to your particular situation and are waiting for it to be established whether our legitimate grounds override those for your objection.

Right to data portability

You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and have the right to transmit such data to another controller in the cases in which:

  • data has been processed automatically; and
  • The processing is either based on your consent or is necessary for the performance of a contract between us or for taking steps at your request prior to entering into a contract.

The right to data portability is limited to a procedure that does not adversely affect the rights or freedoms of others.

Right to object to the processing of personal data

You have the right to object to the processing of your personal data on grounds relating to your particular situation if there are no overriding legitimate grounds for the processing.

You have the right to object to the processing of your personal data for direct marketing purposes. You can prevent the sending of electronic direct marketing by clicking on the link in the messages to unsubscribe from marketing messages.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with the Data Protection Ombudsman if you consider that your rights under the General Data Protection Regulation have been violated in the processing of personal data.

How long do we keep your personal data?

We retain personal data for as long as it is necessary for the purposes of processing personal data or to comply with our legal obligations. In our retention periods, we take into account, for example, the claim periods permitted by law, accounting obligations, the requirements of anti-money laundering legislation and the Finnish Bar Association’s recommendation on the retention of documents.

Customer due diligence data is stored for five years after the end of the permanent customer relationship. Accounting records are stored for six years from the end of the year during which the financial year ended.

If you have not paid the invoice and any collection costs by the end of the retention period, we will store the data until the amount has been paid in full or can no longer be demanded.

We store personal data collected for marketing purposes until we are asked to stop processing personal data for marketing purposes.

How do we ensure data security in the processing of personal data?

We store your personal data in systems that are protected by firewalls, passwords and other technical and organisational means generally accepted in the industry at any given time.

The materials we maintain manually are located in premises to which unauthorized access is prevented.

Only those of our employees who need to process personal data in order to perform their work duties have access to the personal data we process.

© Eversheds Sutherland 2024. All rights reserved. Eversheds Sutherland is a provider of legal and other services operating through various separate and distinct legal entities. For further information about these entities and Eversheds Sutherlands’ structure please see the Legal Notice page of this website.