Skip to content

Privacy Policy for the Processing of Personal Data

Last Updated August 31st, 2026

1. Data Controller

Name: Aerial Unlimited
Address: Sahurintie 8, 20320 Turku
Business ID: 3353014-7

2. Contact Person for Matters Concerning the Register

Name: Iiro Linden / aerialunlimited.ry@gmail.com
Address: Sahurintie 8, 20320 Turku / https://aerialunlimited.fi

3. Register Names

The association maintains two separate personal data registers:

1. Sign-up and billing register. Seasonal sign-ups, single-session sign-ups, membership applications, ticket reservations and contact messages collected through the forms on aerialunlimited.fi, together with the billing based on them.

2. Reservation system user register. User accounts, class reservations, event ticket purchases and prepaid card balances in the varaukset.aerialunlimited.fi service.

The controller, the legal bases and the data subject's rights are the same for both. Where they differ, the two are described separately below.

The registers contain personal data of the association's members and former members, as well as of people who use the association's services without being members — for example those buying event tickets.

Depending on the purpose, processing rests on one of the following bases:

The purposes of processing are:

5. Processed Personal Data

We process the following necessary personal data or categories of personal data for the purpose of use:

The reservation system user register additionally contains:

6. Regular Data Sources

The information stored in the registers comes mainly from the data subject: when signing up, when registering in the reservation system, and otherwise on their own initiative through the website's forms, email, phone, social media and other situations where the person provides their data. The provided information is only used for purposes agreed upon with the data subject, such as billing for a service they have purchased.

Information the data subject has provided is updated only when they update it. The reservation system additionally generates some data itself during use: reservation and purchase history, and information about account usage.

7. Retention of Personal Data

We keep personal data only as long as it is needed for the purposes described in this policy.

The registers are reviewed annually and data past its retention period is deleted. Deletion is performed manually, so data may persist for a short time after its retention period ends.

8. Disclosure of Personal Data to Third Parties

We do not sell or rent personal data of the data subject to third parties. We may disclose information to third parties in the following cases:

Personal data may be transferred forward when changing the register's service provider.

Information may be published to the extent agreed upon with the individual.

9. Service Providers and Transfers outside the EU or EEA

Sign-up and billing register. Website forms are relayed through AWS Lambda (Amazon Web Services, Stockholm data centre, EU). The data is stored in Google Workspace services (Gmail, Google Drive, Google Sheets), which may involve transfer to the United States. Google LLC participates in the EU–US Data Privacy Framework, which the European Commission found to provide an adequate level of protection in its decision of 10 July 2023.

Reservation system user register. The service runs entirely in Amazon Web Services' Stockholm region (eu-north-1). No data is transferred outside the EU or EEA. Event ticket payments are handled by Stripe, which acts as its own controller for the payment transaction under its own terms. The association neither receives nor stores card details.

10. Cookies and Browser Storage

aerialunlimited.fi stores no cookies and no other data in your browser. The site carries no visitor tracking and no analytics.

varaukset.aerialunlimited.fi stores sign-in tokens in your browser (valid for at most 30 days) and any unfinished ticket purchase, which is cleared when you close the browser tab. Nothing else is stored. The “About Cookies” link in the service footer opens a fuller description.

11. Data Protection Principles of the Register

Care is taken in the processing of the register, and the information processed with the help of data systems is properly protected. When register information is stored on Internet servers, the physical and digital security of their hardware is taken care of appropriately. The data controller ensures that the stored data, server access rights, and other data critical to the security of personal data are treated confidentially and only by persons whose job description includes it. All information stored in the various systems and devices is protected by passwords. Personal data is protected from external use, and the use of member data is monitored.

12. Checking and Modifying Personal Data

The data subject has the right to check what information concerning them is stored in the register. A request for inspection should be submitted primarily. A request for exercising the right can also be submitted in writing and signed to the address mentioned in the Data Controller's contact details of this privacy policy. The data subject has the right to request correction of incorrect information in writing and signed.

13. Deleting Own Data

The data subject has the right to request the data controller to delete their data from the register. The deletion of information in the membership register may affect the person's ability to participate in activities. A request for exercising the right can also be submitted in writing and signed to the address mentioned in the Data Controller's contact details of this privacy policy.

14. Changes

This privacy policy may be updated from time to time, for example, when there are changes in legislation.