GDPR & Data Protection
European Union & Finland – Last updated: April 27, 2026
Our Commitment
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Finnish data protection law, including the Finnish Data Protection Act (1050/2018) and the EU ePrivacy framework where relevant.
Legal Basis (EU & Finland)
We process personal data only where we have a valid legal basis under GDPR Article 6, such as:
- Your consent (e.g. marketing, non-essential cookies)
- Performance of a contract (e.g. providing our services and managing your account)
- Legal obligation (e.g. tax, accounting, and regulatory requirements)
- Legitimate interests (e.g. security, fraud prevention, improving our platform), where these are not overridden by your rights
Your Rights Under GDPR
Under the GDPR and Finnish law, you have the right to:
- Access your personal data (Article 15)
- Rectification of inaccurate data (Article 16)
- Erasure (“right to be forgotten”) where applicable (Article 17)
- Restriction of processing (Article 18)
- Data portability (Article 20)
- Object to processing (Article 21), including to profiling
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a supervisory authority (in Finland: the Office of the Data Protection Ombudsman, tietosuoja.fi)
Data Controller & EU/EEA Presence
We process personal data as data controller. Where we operate or direct our services to the European Economic Area (EEA) and Finland, we ensure that our processing complies with GDPR and Finnish data protection requirements. We may use processors that provide adequate safeguards (e.g. standard contractual clauses or adequacy decisions) for any transfers outside the EEA.
Data Retention
We retain your data only for as long as necessary for the purposes described in our Privacy Policy, or as required by EU and Finnish law (e.g. accounting and legal obligations). When data is no longer needed, we delete or anonymise it in a secure manner.
Security & Confidentiality
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with GDPR Article 32. We also require our processors to protect your data in accordance with applicable European and Finnish standards.
Contact & Data Protection Enquiries
For any request related to your rights under GDPR or Finnish data protection law, or for general data protection enquiries, please contact us at privacy@plugingenerator.com or visit our Contact page. We will respond within the time limits set by the GDPR (generally one month).