Privacy Policy

1. DATA CONTROLLER

Who is responsible for your data?

The data controller for this website and the VIA 2026 programme is:

G-Gravity Srl

Via Legnone, 4 — 20158 Milan, Italy

Email: r.gilardi@g-gravity.it

Website: www.g-gravity.it

The programme is delivered in partnership with the City of Vantaa and co-delivered by Digiole and HBC. Where these organisations act as joint controllers or processors, this is specified in the relevant context (e.g. event registration forms, community platform terms).

For all data protection enquiries: privacy@vantaa.innovation-activator.eu

2. PERSONAL DATA WE COLLECT

What information do we process?

2.1  Website visitors

  • IP address and technical browsing data — collected automatically for security and performance monitoring.
  • Cookie data — as described in Section 9 (Cookie Policy) below.
  • Contact form submissions — name, email address, company name and any message you voluntarily provide.

2.2  Programme participants

  • Identification data — name, job title, company name, email address, phone number.
  • Professional data — industry sector, company size, innovation activities, Business Finland funding history, participation tier (Champion / Pioneer / Community).
  • Session data — challenge signals and outputs generated during VIA workshops and events. Published outputs are anonymised or aggregated unless you have consented to attribution.
  • Communication data — emails and messages exchanged with the VIA team.

2.3  Community platform (Circle.so)

  • Profile data, posts and interactions within the private VIA community. Circle.so operates as an independent data processor; their privacy policy applies in addition to this one.

3. LEGAL BASIS FOR PROCESSING

Why are we legally permitted to process your data?

Under Article 6 GDPR, we rely on the following legal bases:

Processing activity Legal basis (GDPR Art. 6)
Responding to contact form enquiries Art. 6(1)(b) — Contractual necessity / pre-contractual steps
Managing programme participation and events Art. 6(1)(b) — Contractual necessity
Sending programme updates and newsletters (opt-in) Art. 6(1)(a) — Consent
Website analytics (anonymised) Art. 6(1)(f) — Legitimate interest (improving the website)
Security logging (IP, access logs) Art. 6(1)(f) — Legitimate interest (security)
Reporting to the City of Vantaa (anonymised/aggregated) Art. 6(1)(c) — Legal obligation / public task

 

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

4. HOW WE USE YOUR DATA

What do we do with the data we collect?

We use personal data exclusively for the following purposes:

  • Operating and managing the VIA programme, including event coordination, participant communication and cluster facilitation.
  • Responding to enquiries submitted via the website contact form.
  • Sending programme updates, session reminders and ecosystem news to participants who have opted in.
  • Compiling anonymised or aggregated reporting for the City of Vantaa and programme partners.
  • Improving the website and digital platforms based on anonymised usage analytics.
  • Maintaining the security and integrity of our systems.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.

5. DATA SHARING & THIRD PARTIES

Who do we share your data with?

We do not sell, rent or trade personal data. We share data only in the following circumstances:

5.1  Programme delivery partners

Digiole and HBC may access participant data strictly for programme coordination purposes, under equivalent data protection obligations.

5.2  City of Vantaa

As the commissioning body, the City of Vantaa receives aggregated and anonymised programme reports. Individual participant data is not shared without explicit consent, except where required by applicable public sector obligations.

5.3  Technology service providers (processors)

The following third-party platforms are used, each bound by a Data Processing Agreement (DPA) or equivalent contractual protections:

 

Provider

Purpose / Data processed

Circle.so

Private community platform — profile, posts, interactions

Website hosting provider (TBC)

Web hosting — access logs, IP addresses

Email / newsletter platform (TBC)

Programme communications — email address, engagement data

Analytics provider (TBC)

Website analytics — anonymised usage data

 

Where providers are located outside the EEA, transfers are protected by Standard Contractual Clauses (SCCs) or adequacy decisions as applicable under Chapter V GDPR.

5.4  Legal obligations

We may disclose personal data to competent authorities if required by law, court order or to protect the rights and safety of participants or third parties.

6. DATA RETENTION

How long do we keep your data?

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law:

 

Data type

Retention period

Programme participant records

3 years after the end of the programme cycle in which you participated

Contact form submissions

12 months from the date of the enquiry, or until resolved

Event registration data

3 years (programme reporting and continuity)

Community platform data (Circle.so)

Duration of active participation + 12 months after account closure

Website security / access logs

12 months, then deleted

Newsletter consent records

Until consent is withdrawn + 12 months for audit purposes

 

At the end of the retention period, data is securely deleted or anonymised. Anonymised or aggregated data that cannot identify individuals may be retained indefinitely for research, reporting and programme improvement.

7. YOUR RIGHTS UNDER GDPR

What rights do you have?

As a data subject, you have the following rights under the GDPR. To exercise any right, contact us at the address in Section 1.

 

Right

What it means

Access (Art. 15)

Request a copy of the personal data we hold about you.

Rectification (Art. 16)

Request correction of inaccurate or incomplete data.

Erasure (Art. 17)

Request deletion of your data, subject to legal obligations and legitimate interests.

Restriction (Art. 18)

Request that we limit processing in certain circumstances.

Portability (Art. 20)

Receive your data in a structured, machine-readable format where processing is automated and based on consent or contract.

Objection (Art. 21)

Object to processing based on legitimate interests. We will cease unless we demonstrate compelling legitimate grounds.

Withdraw consent (Art. 7)

Withdraw consent at any time without affecting prior lawful processing.

 

We will respond to all requests within 30 days. In complex cases, this may be extended by a further two months; we will notify you if this applies.

You also have the right to lodge a complaint with the Finnish supervisory authority:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)

PO Box 800, FI-00531 Helsinki, Finland

tietosuoja@om.fi  ·  www.tietosuoja.fi

8. DATA SECURITY

How do we protect your data?

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration:

  • Access controls limiting data access to authorised personnel on a need-to-know basis.
  • Encryption in transit (TLS / HTTPS) on all web-facing systems.
  • Regular review of third-party provider security practices and Data Processing Agreements.
  • Incident response: in the event of a breach likely to result in risk to your rights and freedoms, we will notify the Finnish Data Protection Ombudsman within 72 hours and affected individuals without undue delay, as required by Art. 33–34 GDPR.

9. COOKIE POLICY

How do we use cookies?

A cookie is a small text file placed on your device when you visit a website. We use the following categories of cookies:

9.1  Strictly necessary cookies

Essential for the website to function. They cannot be disabled and do not store personally identifiable information. No consent is required for these cookies.

9.2  Analytics cookies (consent required)

Where used, analytics cookies (e.g. configured with IP anonymisation) help us understand how visitors use the website. These are placed only with your consent, which you can provide or withdraw via the cookie banner on first visit.

9.3  Managing your cookie preferences

You can manage or disable cookies at any time via your browser settings or our cookie preference centre. Disabling strictly necessary cookies may affect website functionality.

10. CHILDREN’S PRIVACY

Do we collect data from children?

The VIA website and programme are directed at business professionals and are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. THIRD-PARTY LINKS

External links

This website may contain links to third-party websites, including partner organisations, event platforms and social media channels. This Privacy Policy does not apply to those sites. We encourage you to read their privacy policies independently.

12. CHANGES TO THIS POLICY

How will we notify you of updates?

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page indicates when it was last revised.

For material changes that affect your rights, we will notify active programme participants by email before the changes take effect. Continued use of this website after the effective date constitutes acceptance of the revised policy.

13. CONTACT

How to reach us

For any questions, requests or concerns relating to this Privacy Policy or the processing of your personal data:

VIA 2026 — Data Protection Contact

Email: privacy@vantaainnovationactivator.fi

G-Gravity Srl, Via Legnone 4, 20158 Milan, Italy