Privacy statement – website

This privacy statement describes how the Municipality of Joroinen processes personal data in connection with the use of the www.joroinen.fi website (visitor statistics, cookies, online forms, text-to-speech, the chat assistant and the social media feed). This statement does not replace the municipality’s service-specific privacy statements, which can be found on the Data protection and document publicity page.

1. Controller

Municipality of Joroinen (Business ID 0207112-8)
Lentoasemantie 130
FI-79600 JOROINEN
Switchboard +358 17 578 440

Person responsible for register matters:
Virva Leväinen, Administrative Manager

2. Contact person for matters concerning the register

Virva Leväinen, Administrative Manager
virva.levainen@joroinen.fi

Other contact details:
Data Protection Officer
tietosuojavastaava@joroinen.fi

3. Name of the register

Use and transaction data of the Municipality of Joroinen website (www.joroinen.fi)

4. Purpose of processing personal data

The municipality’s online communication and services: advice and information, receiving contacts and applications, the accessibility and usability of the website, and maintaining the site’s information security and reliability. Public authority activities.

Key legislation:

  • EU General Data Protection Regulation (EU 2016/679)
  • Data Protection Act (1050/2018)
  • Act on the Openness of Government Activities (621/1999)
  • Act on the Provision of Digital Services (306/2019), including Section 6 a (chat assistant)
  • Act on Electronic Communications Services (917/2014, Section 205: cookies)

Legal basis for processing (EU 2016/679, Article 6) by processing situation:

  • Task carried out in the public interest / exercise of official authority (6(1)(e)) and legal obligation (6(1)(c)): online services and communication, visitor statistics, accessibility, information security.
  • Consent (6(1)(a)): non-essential cookies, the social media feed, use of the chat assistant.

The processing of personal data does not involve automated decision-making or profiling that would produce legal effects concerning the user or similarly significantly affect them (EU 2016/679, Article 22). The chat assistant’s answers are also pre-approved by the municipality, and no decisions concerning the user are made in the chat.

5. Data content of the register

The following data are processed in connection with the use of the website:

  • Visitor statistics (Matomo): technical data on page loads, such as an anonymised IP address (the last two bytes are removed before storage), browser and device type, referring page, pages viewed and the time of the visit. The statistics are cookie-free (no cookies are set in the browser) and the data are processed on the site’s own server within the EU — no external analytics service is used.
  • Cookie consent (CookieYes): the user’s cookie choice. The cookies used are described in a separate cookie statement.
  • Online forms: the information provided on the form, typically name, email address, telephone number and the content of the message. The data are forwarded to the municipality’s email and stored in the website database. The Akismet service (Automattic) is used for spam filtering of forms.
  • Chat assistant (Bulli): the message written by the user, a pseudonymous session identifier, a timestamp, the language used and technical processing data. No identifying information about the user is stored in the conversations unless the user writes it in their message. The chat assistant directs users to answers pre-approved by the municipality; the artificial intelligence does not produce freely formulated answers (Act on the Provision of Digital Services 306/2019, Section 6 a). An internal email alert may be sent to designated recipients at the municipality about an emergency or disruption-related question.
  • Text-to-speech (ReadSpeaker): the text content of the page to be converted into speech and technical usage data (accessibility).
  • Social media feed (Instagram): displaying the feed may set third-party (Meta) cookies and transmit technical browser data; only with cookie consent.
  • Server logs and information security: technical log data (including IP address, timestamp, requested addresses) to ensure information security and prevent misuse.

Users are advised not to send sensitive data or a personal identity code via a form or in the chat unless it is necessary for handling the matter and has been specifically requested.

6. Regular sources of data

The data are obtained primarily from the users themselves (form, chat, cookie choice) and technically from the traffic between the browser and the server (statistics, server logs).

7. Regular disclosures of data

Personal data are not disclosed to outside parties for marketing or commercial purposes. The following processors handle data on behalf of the municipality under data processing agreements:

ProcessorTaskLocation
Digitoimisto Digitaali OyWebsite implementation, maintenance and hostingFinland / EU
Anthropic PBC (Claude)Chat assistant’s AI model (selection of a ready-made answer)United States
ReadSpeakerText-to-speech (webReader, EU instance)EU
Automattic Inc. (Akismet)Spam filtering of formsUnited States
CookieYes LimitedCookie consent managementUnited Kingdom (EU adequacy decision)

In addition, the Instagram feed displayed on the site is a third-party service (Meta Platforms). Meta does not act as a processor of personal data for the municipality but processes the data related to displaying the feed as an independent controller in accordance with its own privacy practices.

8. Transfer of data outside the EU or the EEA

Yes, in part. In the operation of the chat assistant, the user’s message is transferred to the United States for processing (Anthropic PBC): based on the message, the AI model selects an answer pre-approved by the municipality and does not use the data to train AI models. The transfer is safeguarded by the Standard Contractual Clauses (SCC) approved by the European Commission, which are included in the data processing agreement.

In the spam check of forms, the content of the form may be transferred to Automattic Inc. (Akismet) in the United States for checking. The transfer is safeguarded by the Standard Contractual Clauses (SCC) approved by the European Commission.

Displaying the Instagram feed may transfer technical browser data outside the EU/EEA. With regard to these data, Meta acts as an independent controller and is responsible for the safeguards for the transfers in accordance with its own practices (including the EU–US Data Privacy Framework).

Visitor statistics and server logs are processed within the EU; form data are processed within the EU with the exception of the spam check.

9. Systems maintaining the register and principles of protection

a) Paper material
No paper material.

b) Electronic material
The data are processed on a protected server. Connections are encrypted (HTTPS). Access to the data is restricted according to job duties with a personal user ID and password (the municipality and the system supplier). The website uses security protection and regular backups.

Retention periods:

  • Form data: for the time required to handle the matter, after which archiving or deletion in accordance with the information management plan.
  • Chat conversations: no more than 12 months, after which deletion or anonymisation.
  • Visitor statistics: raw data 24 months, after which automatic deletion (anonymous statistical summaries are retained).
  • Server logs: 12 months.

10. Right of access

Everyone has the right to check their own data. A person may address a request for access to the Municipality of Joroinen in person or by a document signed by hand or otherwise verified. The contact details are given in section 2.

The right of access may be denied only in exceptional cases. If the right of access is denied, a written certificate of refusal will be issued. The certificate states the reasons why the right of access was denied. The data subject may refer the matter to the Data Protection Ombudsman at the address: Office of the Data Protection Ombudsman, P.O. Box 800, FI-00531 Helsinki.

No separate identifying information is stored in chat conversations, so linking an individual conversation to a user may require the session identifier provided by the user or other identifying information.

11. Rights related to the processing of personal data

Data subjects have the other rights provided in the EU General Data Protection Regulation, such as the right to rectification and erasure of data, to restriction of and objection to processing under the conditions laid down by law, and the right to withdraw consent (for example the cookie settings) at any time. More information on the rights related to the processing of personal data: https://tietosuoja.fi/en/know-your-rights

The data subject also has the right to lodge a complaint with the supervisory authority if they consider that data protection legislation is being infringed in the processing of personal data: Office of the Data Protection Ombudsman, P.O. Box 800, FI-00531 Helsinki, tietosuoja@om.fi, www.tietosuoja.fi.

Requests are made in person or by a document signed by hand or otherwise verified.

This privacy statement was drawn up on 28 July 2026.