eKampus Privacy Policy and Data Protection Statement

Last updated: August 18, 2025

This statement describes how PeDaTa Oy processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and Finnish Data Protection Act.

This data protection statement has been prepared in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.

1. Data Controller

PeDaTa Oy

Business ID: 2521004-7

Address: Willebrandintie 1 B 11, 00840 HELSINKI, Finland

Email: asiakaspalvelu@ekampus.fi

Data Protection Officer: Pekka Immonen

pekka@ekampus.fi

2. Registry Inquiries

Our customer service responds to registry-related questions and feedback within three business days.

Contact us: asiakaspalvelu@ekampus.fi

3. Registry Name

eKampus Customer Registry

4. Purpose and Legal Basis for Processing Personal Data

The purpose of processing is:

Legal basis: Performance of a contract (GDPR Article 6(1)(b))

Legitimate interest in service development and security assurance

5. Registry Data Content

The registry may contain the following information about users:

6. Regular Data Sources

The registry is compiled from information provided by users themselves during registration, service use, and contacts.

Social login (Google, Microsoft) provides only name and email address with user consent.

7. Data Disclosures and Transfers

The data controller does not disclose personal data to third parties, except:

8. Data Retention and Deletion

Personal data is retained as long as:

Data deletion:

Upon expiry of access rights, users are responsible for transferring or deleting their own saved content before access expires.

9. Registry Security Principles and Data Processors

Personal data is processed confidentially and is protected with appropriate technical and organizational measures.

Security measures:

Data processors:

DigitalOcean LLC – Server infrastructure provider

DigitalOcean's responsibility is limited to ensuring the operational reliability and security of the server environment and network

Servers are located within the EU

Laravel Holdings Inc – Server infrastructure provider

Laravel Holdings Inc's responsibility is limited to ensuring the operational reliability and security of the server environment and network

Servers are located within the EU

GDPR-compliant processing agreements have been made with all data processors.

10. Connection Logs and Log Data

Connection log stores:

Error logs store:

Log data retention period:

11. Data Subject Rights

Data subjects have the right to:

Exercising rights:

Contact our customer service: asiakaspalvelu@ekampus.fi

We respond to requests within one month

Supervisory authority:

Office of the Data Protection Ombudsman

www.tietosuoja.fi

tietosuoja@om.fi

12. Automated Decision-Making and Profiling

The service does not perform automated decision-making or profiling as defined in Article 22 of the EU Data Protection Regulation that would have legal effects on the data subject.

The service analyzes learning progress and provides feedback, but these are not automated decisions in the sense meant by GDPR.

13. Response to Data Security Breaches

In the event of personal data security breaches, we act in accordance with the EU Data Protection Regulation (GDPR):

14. Anonymization and Pseudonymization

The service does not anonymize or pseudonymize user basic data (name, email, address) because they are necessary for:

However, data is processed only to the extent required by service operation (data minimization).

15. Cookies

The service uses necessary cookies:

The service does not use tracking cookies or analytics cookies without user consent.

Contact Information

If you have questions about data protection or wish to exercise your rights, contact us:

asiakaspalvelu@ekampus.fi

Data Protection Officer: pekka@ekampus.fi