Last updated: 6 October 2026
This policy explains which personal data are processed when you use arcticaedu.fi, its contact forms and Arctica Academy, why they are processed and your rights.
1. Scope and contact
This policy covers the website and online learning area operated under the ArcticaEdu brand. Controller details will be completed in the section above. Privacy questions and rights requests can be submitted through the Contact form with “personal data request” in the message.
2. Data we process
Contact submissions store your name, email address, message and its language. Accounts store your name, email address, one-way password derivation, account creation time and user role. Course assignments and session records support access management. The service infrastructure may process IP addresses, connection details, request times and error information for security. The current system does not record viewing duration or course completion percentages.
3. Purposes and legal bases
Responding to enquiries and preparing requested proposals may rely on pre-contractual steps. Account and course access management may rely on forming or performing a contract. Preventing abuse may rely on legitimate interests; applicable legal obligations may rely on compliance with law. Legitimate interests are assessed with regard to your rights and reasonable expectations. Separate consent is requested where necessary for marketing or optional tracking. The contact-form acknowledgement is not marketing permission.
4. Cookies and language settings
arctica_session manages login using HttpOnly, SameSite=Lax and, on the HTTPS deployment, Secure settings, with validity of up to 7 days. arctica_lang remembers your language for up to one year. A first visit selects Turkish, Finnish or English according to your browser language. The current version uses no advertising, analytics or retargeting cookies. You can delete cookies through your browser; blocking session cookies affects areas requiring login.
5. Retention and deletion
Enquiries are kept for the time needed to handle and follow up the request. Account and access records are kept while needed for the account and service relationship. Data no longer needed are deleted or anonymised following a valid deletion request, closure of the matter or termination of the service. Records needed for a legal obligation or specific dispute may be kept separately for that need’s applicable duration. Sessions are valid for 7 days; expired sessions cannot grant access. The final operational retention schedule will be documented when the company is established.
6. Providers and transfers
Website and course data are stored on the Hetzner server in Finland. Cloudflare may process connection and security data for DNS and website tunnel access. Training videos are delivered directly from Hetzner through a separate media hostname. Providers’ global infrastructure may involve processing outside the European Economic Area; the controller must assess applicable transfer conditions and contractual safeguards. Resend or another email provider has not yet been connected to this version. The policy is updated when providers or processing purposes change.
7. Security and access
Passwords are not stored in plain text; they use salted, one-way scrypt derivation. Administration is protected by role checks, and video access by account and course permissions. Video links are time-limited and signed, and entitlement is checked again for every request. Technical measures reduce risk, but absolute security cannot be guaranteed over the internet. Do not share your account password.
8. Your rights
Under applicable law, you may request access, correction, deletion, restriction and, in certain cases, data portability. You may object to processing based on legitimate interests and withdraw consent for future consent-based processing. Withdrawal does not affect earlier lawful processing. Only necessary identification may be requested to verify a rights request. GDPR requests are normally answered within one month; permitted extensions are explained. You may complain to Finland’s Data Protection Ombudsman or another competent supervisory authority.
9. Children’s data
Account registration and professional training enquiries are intended for adults. Content about early childhood education does not mean the site collects children’s data. Do not include children’s identity, health or other sensitive information in forms. If a separate service involves children or requires their data, appropriate information, authorisations and protections will be arranged beforehand.
10. Automated decisions and changes
The current system does not make automated decisions or profiles producing legal or similarly significant effects on individuals. Language selection is an interface preference only. This policy may change with new features or providers; material changes are communicated appropriately.
Official information sources: GDPR · Tietosuojavaltuutettu
