Privacy notice

Updated: 6 November 2025

1. Data controller

Uhmu Oy
Business ID: 2893665-2
Sundsbergin Yritystie 9 A 15
02450 Sundsberg
Email: yhteys@uhmu.fi
Website: www.uhmu.fi

2. Contact person for data protection matters

For questions concerning data protection, please contact:

  • Email: yhteys@uhmu.fi
  • Postal address: Sundsbergin Yritystie 9 A 15, 02450 Sundsberg

3. Name of the register

Uhmu Oy client and contact register

4. Purposes and legal bases for processing personal data

We process personal data for the following purposes:

4.1 Provision of legal services

  • Purpose: Managing client relationships, providing legal services, representing and advising clients
  • Legal basis: Performance of a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR)

Special note: The professional rules for attorneys-at-law and attorney-client confidentiality are observed in legal practice

4.2 Client relationship management

  • Purpose: Maintaining client contacts, invoicing and contract management
  • Legal basis: Performance of a contract and compliance with legal obligations under accounting and tax legislation

4.3 Marketing and communications

  • Purpose: Newsletters, event invitations and information about services
  • Legal basis: Consent (Article 6(1)(a) GDPR) or legitimate interests in the context of an existing client relationship

4.4 Handling enquiries

  • Purpose: Handling enquiries submitted through the website
  • Legal basis: Legitimate interests in establishing a potential client relationship, or consent

5. Categories of personal data processed

We may process the following categories of personal data:

5.1 Basic information

  • Name
  • Date of birth
  • Contact details (address, telephone number and email address)
  • Business ID / personal identity code (where necessary)
  • Language and communication preferences

5.2 Information relating to the client relationship

  • Duration and history of the client relationship
  • Information relating to engagements
  • Client communications (emails, telephone calls and meetings)
  • Contract documents
  • Billing information

5.3 Legal documents and information relating to engagements

  • Litigation materials
  • Contracts and drafts
  • Opinions and advisory documents
  • Other documents relating to an engagement

5.4 Special categories of personal data

Due to the nature of legal services, we may also process special categories of personal data (sensitive data) under Article 9 GDPR where this is necessary to provide legal services. Such data may include:

  • Health data (for example, in matters concerning incapacity for work)
  • Data concerning criminal convictions
  • Trade union membership

Legal basis for processing special categories of personal data:

  • The establishment, exercise or defence of legal claims (Article 9(2)(f) GDPR)
  • Compliance with legal obligations (Article 9(2)(b) GDPR)
  • The data subject’s explicit consent (Article 9(2)(a) GDPR)

6. Data retention periods

We retain personal data for as long as necessary for the purposes for which it is processed:

6.1 Client information and engagement materials

  • Minimum period: 10 years after the end of the engagement (a recommendation under the professional rules for attorneys-at-law and proper professional conduct)
  • Accounting records: At least 6 years after the end of the financial year (Finnish Accounting Act)
  • Litigation materials: Retained for possible legal claims for at least 10 years

6.2 Marketing consents

  • Retained while the consent remains valid or until it is withdrawn
  • Reviewed and updated regularly

6.3 Enquiries

  • Handled enquiries are retained for 2 years if no client relationship is established

7. Regular disclosures and transfers of data

7.1 Disclosures of data

We do not disclose personal data to third parties without the client’s consent or a legal obligation to do so. Data may be disclosed in the following circumstances:

  • Requests from authorities: Where required by law (for example, court orders or police investigations)
  • Partners assisting with an engagement: For example, experts, translation services and foreign law firms (with the client’s consent)
  • Legal proceedings: Representing the client in court proceedings and matters before public authorities

7.2 Transfers of data outside the EU/EEA

As a rule, we do not transfer personal data outside the EU or EEA. If a transfer is necessary, for example for an international engagement, we ensure that:

  • There is an appropriate legal basis for the transfer (Articles 44–50 GDPR)
  • An adequate level of data protection is ensured (for example, by a European Commission adequacy decision or standard contractual clauses)
  • The client is informed of the transfer in advance

7.3 Service providers

We use trusted service providers for the following purposes:

  • IT and cloud services (servers and email)
  • Accounting and invoicing services
  • Website maintenance

All service providers are committed to complying with data protection law, and the necessary data processing agreements have been entered into with them.

8. Sources of data

Personal data is collected mainly:

  • Directly from the data subject (the client or a contact person)
  • From public registers (for example, the Finnish Trade Register and Population Information System)
  • From documents and materials provided by the client
  • From public authorities to the extent permitted by law
  • From third parties with the client’s consent

9. Rights of the data subject

You have the following rights in relation to the processing of your personal data:

Right of access

Article 15 GDPR

You have the right to obtain confirmation as to whether your personal data is being processed and to access the personal data held about you.

Right to rectification

Article 16 GDPR

You have the right to require inaccurate or incomplete personal data to be corrected or completed.

Right to erasure

Article 17 GDPR

You may request the erasure of your personal data in certain circumstances, unless there is a legal obligation to retain it.

Right to restriction of processing

Article 18 GDPR

You may request restriction of the processing of your personal data in certain circumstances, for example where you contest its accuracy.

Right to data portability

Article 20 GDPR

You have the right to receive the personal data you have provided in a machine-readable format and transmit it to another controller.

Right to object

Article 21 GDPR

You have the right to object to the processing of your personal data where the processing is based on legitimate interests or carried out for direct marketing purposes.

9.1 Limitations on the right to erasure

We cannot erase data where its retention is necessary:

  • To comply with a legal obligation (for example, an accounting obligation)
  • For the establishment, exercise or defence of legal claims
  • To comply with attorney-client confidentiality and professional rules

9.2 Right to withdraw consent

If processing is based on your consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

9.3 Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with the Data Protection Ombudsman if you believe that the processing of your personal data infringes data protection law.

Office of the Data Protection Ombudsman

Visiting address: Lintulahdenkuja 4, 00530 Helsinki
Postal address: PO Box 800, 00521 Helsinki
Email: tietosuoja@om.fi
Switchboard: +358 29 566 6700
Website: www.tietosuoja.fi

9.4 Exercising your rights

You can exercise your rights by contacting contact@uhmu.fi. We will respond to your request within one month at the latest. Where necessary, we will ask you to verify your identity before processing the request.

10. Data security

We take appropriate care to protect personal data against unauthorised access, alteration, disclosure and destruction. The safeguards we use include:

10.1 Technical safeguards

  • Firewalls and anti-virus protection
  • Encrypted data connections (SSL/TLS)
  • Regular secure backups
  • Management and restriction of access rights
  • Strong password policies and two-factor authentication
  • Encryption of devices and files

10.2 Organisational safeguards

  • Data protection training for personnel
  • Data protection instructions and policies
  • Data processing agreements with service providers
  • Regular security audits and risk assessments
  • Data breach response plan

10.3 Physical security

  • Locked premises
  • Access control
  • Secure storage and disposal of documents
  • Secure archive facilities

11. Cookies and website tracking

11.1 Use of cookies

Cookies may be used on our website, www.uhmu.fi, to improve its functionality and enhance the user experience.

Strictly necessary cookies:

  • Enable the website’s core functions
  • Do not require consent

Analytics cookies:

  • Collect information about use of the website (for example, Google Analytics)
  • Help improve the website’s functionality
  • Require consent

Marketing cookies:

  • Are used to target advertising
  • Require consent

You can manage cookies through your browser settings. Blocking cookies may affect the website’s functionality.

Read more: Our cookie policy

12. Automated decision-making and profiling

We do not use automated decision-making or profiling in the processing of personal data where it would produce legal effects concerning a data subject.

13. Changes to this privacy notice

We may update this privacy notice as necessary. We will announce material changes on our website or notify our clients directly by email. We recommend reviewing this privacy notice regularly.

This privacy notice was last updated: 6 November 2025

14. Contact details

If you have any questions about this privacy notice or the processing of your personal data, please contact:

Uhmu Oy
Sundsbergin Yritystie 9 A 15
02450 Sundsberg
Email: yhteys@uhmu.fi
Business ID: 2893665-2

Summary: your rights

You can:

  • Request access to your personal data
  • Have inaccurate personal data rectified
  • Request erasure of your personal data
  • Restrict the processing of your personal data
  • Object to the processing of your personal data
  • Transfer your personal data to another service provider
  • Withdraw your consent
  • Lodge a complaint with the Data Protection Ombudsman

This privacy notice has been prepared in accordance with the EU General Data Protection Regulation (GDPR 2016/679) and the Finnish Data Protection Act (1050/2018).

Request a free initial assessment

Tell me briefly about your business’s situation, what you need to achieve and any deadline. Niko Mäenpää usually replies the same business day.

Contacting me does not commit you to using my services. We agree the scope and fees before any work begins.

How I handle personal data