Privacy policy

The Finnish BrainData website (service.braindata.fi) is maintained and hosted by Aalto University (“we”, “us” or “our”). The means and purposes of processing your personal data are described in further detail in this privacy notice. The privacy notice is limited to describing our policy for handling personal data collected and used by Aalto University when you visit this website (service.braindata.fi). Other policies apply to handling personal data collected from participants in a scientific study stored in the Finnish BrainData collection. This privacy notice is subject to change and will be updated when changes are implemented.

1. Why do we process personal data?

We collect and process personal data in order to

In addition, we will also process personal data for the purposes of data security and to prevent and resolve possible misconduct.

2. What personal data do we process?

We will only process personal data that is necessary for the processing purposes defined in this privacy notice. The personal data that we collect can be grouped into the following categories:

3. Sources of information

Personal data is collected from the users themselves during their visits on the website, or from their organizations, when they enter data into data upload or data request forms, or otherwise interact with us.

4. Lawful Basis for Processing

Legitimate interest to maintain and develop website, to control access to the database and to communicate:

5. Processing of information by third parties

We disclose personal data only to the extent necessary for the purposes personal data is processed:

I) Service providers

In the maintenance of this website and in its service provision, we use partners to process data for the purposes detailed in this data protection policy. We transfer your personal data to such partners only to the extent that the partners need to be able provide services for the purposes specified in this data protection policy.

II) Research use

In some situations, we may disclose your personal data for the purposes of research. In these cases, all personal data is processed in accordance with the General Data Protection Regulation and national data protection legislation.

This website automatically logs information about requests made to it. This information is used for system administration and for tracking problems affecting this site. Summary statistics, such as number of users, may be extracted from this data and made publicly available. These will not include information that would allow individual users to be identified.

When you upload datasets into the database the (e.g. name of responsible researcher, name of contact person, organization, physical address) that you provide will be stored in the database. This information will be available to users that are logged into the system.

When you request access to datasets that are stored in the database, the personal data that you enter into the web request forms (e.g. name, organization, email, physical address) will be stored on the web server. Your contact details may be made available to the researcher in charge or the contact person of the requested dataset for approval of data access.

III) Statutory reasons

We may disclose your personal data to third parties if access to personal data or other processing of personal data is required to i) fulfill statutory responsibilities or a court order; ii) detecting, preventing or handling misuses, security risks or technical issues.

6.. International transfers of personal data

The server on which the Finnish BrainData website is operated is located in the European Union (EU). We strive to carry out all services related to our website using operators and services located within the EU or the European Economic Area (EEA). In some cases, however, services related to the use of our website may also be carried out by operators and on servers located in third countries. In such cases, your personal data may also be transferred outside the EU or EEA in accordance with applicable legislation. In regards to transfers of personal data to countries where local data protection legislation does not provide an adequate level of data protection, transfers are protected utilizing appropriate safeguards, such as standard contractual clauses approved by the European Commission, a competent supervisory authority, or binding corporate rules. To learn more about the appropriate safeguards we use, please contact us by using the contact information provided below.

7. Retention period

Personal data will be retained for the period of validity of the legal basis for processing and for as long as necessary for the processing purposes mentioned in this privacy notice. The information is retained for as long as Aalto´s legitimate interests can reasonably be deemed valid. We determine the validity of our legitimate interest by, for example, your use of our online services as well as the communication between us.

8. Your rights

The General Data Protection Regulation grants the data subject a number of rights with which the data subject can govern the processing of their personal data. The data subject may use the following rights in relation to Aalto insofar as Aalto acts as the controller for the data subject’s personal data:

Right of access and right to rectification

You have the right to receive confirmation on whether we process personal data relating to you and the right to access any such personal data. We may ask you to specify your request where necessary, for example with regards to the details of the provision of information. In addition, you have the right to request the rectification of incorrect personal data relating to you, or to supplement incomplete personal data that we are processing.

Right to data erasure

You have the right to request erasure of your personal data from our data systems. We will comply with your request, provided that there is no legitimate reason to retain the data, such as a statutory obligation to continue processing the personal data. Personal data may not be deleted instantly from backup copies and other such data systems, but will be deleted through regular database retention practices.

Right to object

You also have the right to object to the processing of your personal data if your personal data is processed for other purposes than the fulfillment of legal responsibilities or the provision of services. You may object to the processing of your personal data for purposes of direct marketing, even if the basis for such processing is consent given by you in the past. Objecting to the processing of your personal data may lead to limitation of the usage of the website.

Right to restriction of processing

If you contest the correctness of the data which we have registered about you or the lawfulness of processing, or if you have objected to the processing of the data in accordance with your right to object, you may request us to restrict the processing of these data to only storage. The processing will only be restricted to storage, until the correctness of the data can be established, or until it is assured that our legitimate interests override your interests.

If you are not entitled to erasure of the data which we have registered about you, you may instead request that we restrict the processing of these data to only storage. If the processing of the data which we have registered about you is solely necessary to assert a legal claim, you may also demand that other processing of these data be restricted to storage. We may process your data for other purposes if this is necessary to assert a legal claim or if you have granted your consent to this.

Right to data portability

You have the right to receive your personal data from us in a structured, commonly used format so that you may transfer your personal data to another controller, provided that the processing of your personal data is based on consent or a contract between you and Aalto.

9. Who is the controller and who can I contact?

If you have questions about the processing of your personal data, please contact Lauri Parkkonen at Aalto University. You can also use your rights by contacting Aalto's data protection officer at tietosuojavastaava@aalto.fi. The extent of your rights is subject to the legal basis for processing, and exercising your rights requires identification.

Controller:

Aalto-korkeakoulusäätiö sr, which functions as Aalto University
Mailing address: PO BOX 11000, FI-00076 AALTO
Phone number: +358 (9) 47001
Visiting address: Otakaari 24, 02150 Espoo
Contact person: Lauri Parkkonen
Contact information: braindata-admin@aalto.fi

Data protection officer:

Anni Tuomela
Contact information: tietosuojavastaava@aalto.fi

Right to lodge a complaint

If the processing of your personal data is in breach of applicable legislation, you have the right to lodge a complaint with the national supervisory authority. You can lodge the complaint with a competent supervisory authority. In Finland, this is the Data Protection Ombudsman, and the complaint must be lodged in accordance with instructions provided by the Office of the Data Protection Ombudsman. Please see https://tietosuoja.fi/en/home for more information.