Privacy statement – website

This privacy statement describes how the Municipality of Joroinen processes personal data in connection with the use of the www.joroinen.fi website (visitor statistics, cookies, web forms, content read-aloud, chat assistant and social media feed). This statement does not replace the municipality’s service-specific privacy statements, which can be found on the Privacy and Document Publicity page.

1. Data controller

Municipality of Joroinen (Business ID 0207112-8)
Lentoasemantie 130
79600 JOROINEN
Switchboard 017 578 440

Person responsible for register matters:
Administrative manager, Virva Leväinen

2. Contact person for register matters

Virva Leväinen, Administrative manager
virva.levainen@joroinen.fi

Other contact details:
Data Protection Officer
tietosuojavastaava@joroinen.fi

3. Name of the register

The Municipality of Joroinen’s website (www.joroinen.fi) usage and transaction data

4. Purpose of personal data processing

The municipality’s online communication and services: guidance and information, receiving enquiries and applications, website accessibility and usability, and maintaining the website’s information security and operational reliability. Public authority activities.

Key legislation:

  • EU General Data Protection Regulation (EU 2016/679)
  • Data Protection Act (1050/2018)
  • Act on the Openness of Government Activities (621/1999)
  • Act on the Provision of Digital Services (306/2019), incl. Section 6a (chat assistant)
  • Act on Electronic Communications Services (917/2014, Section 205: cookies)

Legal basis for processing (EU 2016/679, Article 6) by processing situation:

  • Task carried out in the public interest / exercise of public authority (6(1)(e)) and legal obligation (6(1)(c)): online services and communication, visitor statistics, accessibility, information security.
  • Consent (6(1)(a)): non-essential cookies, social media feed, use of chat assistant.

The processing of personal data does not involve automated decision-making or profiling that would have legal effects or similar significant effects on the user (EU 2016/679, Article 22). The chat assistant’s responses are also pre-approved by the municipality, and no decisions concerning the user are made in the chat.

5. Data content of the register

In connection with the use of the website, the following is processed:

  • Visitor statistics (Matomo): technical data on page loads, such as anonymised IP address (the last two bytes are removed before storage), browser and device type, referring page, pages viewed and time. Statistics are cookie-free (no cookies are set in the browser) and data is processed on the site’s own server in the EU – no external analytics service is used.
  • Cookie consent (CookieYes): user’s cookie choice. The cookies used are described in a separate cookie statement.
  • Web forms: information provided in the form, typically name, email address, phone number and message content. The data is transferred to the municipality’s email and saved in the site’s database. Akismet service (Automattic) is used for spam filtering of forms.
  • Chat assistant (Bulli): message written by the user, pseudonymous session identifier, timestamp, language used and technical processing data. Conversations do not store user identification data unless the user themselves writes it in their message. The chat assistant directs to answers pre-approved by the municipality; AI does not produce freely formulated responses (Act on the Provision of Digital Services 306/2019, Section 6a). An internal email alert may be sent to the municipality’s designated recipients regarding emergency or incident questions.
  • Content read-aloud (ReadSpeaker): text content of the page to be converted to speech and technical usage data (accessibility).
  • Social media feed (Instagram): displaying the feed may set third-party (Meta) cookies and transfer technical browser data; only with cookie consent.
  • Server logs and information security: technical log data (including IP address, timestamp, requested addresses) to ensure information security and prevent misuse.

Users are advised not to send sensitive information or personal identity codes in forms or chat unless it is essential for handling the matter and specifically requested.

6. Regular data sources

The data is primarily obtained from the user themselves (form, chat, cookie choice) and technically from traffic between the browser and the server (statistics, server logs).

7. Regular data disclosures

Personal data is not disclosed to external parties for marketing or commercial purposes. The following personal data processors process data on behalf of the municipality under data processing agreements:

ProcessorTaskLocation
Digitoimisto Digitaali OyWebsite implementation, maintenance and server hosting serviceFinland / EU
Anthropic PBC (Claude)Chat assistant AI model (selection of ready-made responses)United States
ReadSpeakerContent read-aloud (webReader, EU instance)EU
Automattic Inc. (Akismet)Spam filtering of formsUnited States
CookieYes LimitedCookie consent managementUnited Kingdom (EU adequacy decision)

In addition, the Instagram feed displayed on the site is a third-party (Meta Platforms) service. Meta does not act as a personal data processor for the municipality, but processes data related to displaying the feed as a data controller in its own right according to its own privacy practices.

8. Transfer of data outside the EU or EEA

Yes, in part. In the operation of the chat assistant, the user’s message is transferred for processing to the United States (Anthropic PBC): the AI model selects a pre-approved response from the municipality based on the message and does not use the data to train AI models. Standard Contractual Clauses (SCC) approved by the European Commission are used as a safeguard for the transfer, which are included in the data processing agreement.

In spam checking of forms, the form content may be transferred for checking to Automattic Inc. (Akismet) in the United States. Standard Contractual Clauses (SCC) approved by the European Commission are used as a safeguard for the transfer.

Displaying the Instagram feed may transfer technical browser data outside the EU/EEA area. For this data, Meta acts as its own data controller and is responsible for transfer safeguards according to its own practices (including EU–US Data Privacy Framework).

Visitor statistics and server logs are processed in the EU area; form data is processed in the EU area except for spam checking.

9. Register maintenance systems and protection principles

a) Paper material
No paper material.

b) Electronic material
Data is processed on a secure server. Connections are encrypted (HTTPS). Access to data is restricted according to job duties with a personal username and password (municipality and system provider). The site uses information security protection and regular backups.

Retention periods:

  • Form data: time required to process the matter, followed by archiving or deletion according to the records management plan.
  • Chat conversations: maximum 12 months, after which deletion or anonymisation.
  • Visitor statistics: raw data 24 months, after which automatic deletion (anonymous statistical summaries are retained).
  • Server logs: 12 months.

10. Right of access

Everyone has the right to check their own data. A person may submit a request for access to the Municipality of Joroinen by personal visit or with a document signed by hand or otherwise verified. Contact details are in section 2.

The right of access may only be denied in exceptional cases. If the right of access is denied, a written certificate of refusal is issued. The certificate states the reasons why the right of access has been denied. The data subject may refer the matter to the Data Protection Ombudsman for consideration at the address: Office of the Data Protection Ombudsman, P.O. Box 800, 00531 Helsinki.

No separate identification data is stored in chat conversations, so targeting an individual conversation to a user may require a session identifier or other identifying information provided by the user.

11. Rights related to personal data processing

Data subjects have other rights under the EU General Data Protection Regulation, such as the right to rectification and erasure of data, restriction and objection to processing under the conditions laid down in law, and the right to withdraw consent (for example, cookie settings) at any time. More information about rights related to the processing of personal data: https://tietosuoja.fi/tunne-oikeutesi

The data subject also has the right to lodge a complaint with the supervisory authority if they believe that the processing of personal data violates data protection legislation: Office of the Data Protection Ombudsman, P.O. Box 800, 00531 Helsinki, tietosuoja@om.fi, www.tietosuoja.fi.

Requests are made by personal visit or with a document signed by hand or otherwise verified.

The privacy statement was prepared on 28 July 2026.