Privacy Notice
Updated March 4, 2026
We process your personal data exclusively within the framework of the General Data Protection Regulation (GDPR) and other applicable legislation, and we respect your right to privacy.
The purpose of this Privacy Notice is to explain what personal data Keksi Agency Oy (“Keksi” or “We”) collects, for what purposes, and how it is processed. It also informs you of your rights related to the personal data we process.
1. Who is the Controller?
Keksi Agency Oy (2519402-4)
Mannerheimintie 142, 00270 Helsinki
Contact person for matters concerning the register:
CEO Jenni-Justiina Niemi
2. Whose personal data do we process?
This Privacy Notice applies to you if you belong to one of the following categories of data subjects:
a) a visitor to our website
b) our subscriber, representative or employee, our customer, or the representative or employee of a customer (“Customer or Subscriber”)
c) an individual registered in our model bank
d) an applicant for a collaboration role, employment, internship, assisting role or volunteering position (“Job Applicant”)
e) our partner or subcontractor, or their representative or employee (“Partner”)
f) a subscriber to our newsletter
g) a visitor to our social media accounts
Section 8 of this Privacy Notice describes, for each group, how we process your specific data.
3. How long do we retain personal data?
We process your personal data only for as long as it is necessary for our operations and for fulfilling our legal obligations.
Retention periods vary depending on the purpose of processing. You will find the retention periods relevant to your category in Section 8., under the description of your data subject group.
4. How have we protected your personal data?
Your personal data is processed confidentially and securely. We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, destruction or other unlawful processing.
Electronic personal data is protected using technical safeguards that are generally accepted and reasonable in our industry. Data is stored in databases protected by firewalls, passwords and other technical means. Databases and their backups are located in locked and monitored facilities, and only certain pre-designated persons have access to the data.
Physical records are stored securely in Keksi’s locked premises.
We have entered into appropriate data processing agreements with our service providers and require them to implement adequate measures to ensure the confidentiality and security of personal data.
5. Your rights regarding personal data
You have the right to access the personal data we hold about you. This request may be refused only on lawful grounds. Exercising this right is, as a rule, free of charge.
You have the right to request the rectification of inaccurate personal data concerning you. In certain situations, you also have the right to request the erasure of your data or the restriction of processing on grounds provided by law.
You have the right to object to processing activities concerning you when we process your personal data based on our legitimate interest. You may contact us at tietosuoja@keksiagency.fi
if you wish to object to the processing of your data.
If we process your personal data based on your consent, you have the right to withdraw your consent at any time by contacting us at tietosuoja@keksiagency.fi.
Where you have provided data yourself and it is processed based on your consent or an agreement, you generally have the right to receive such data in a machine-readable format and the right to transmit those data to another controller.
If you have any questions regarding the processing of your personal data, please contact us at tietosuoja@keksiagency.fi.
If you believe that we have not complied with applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority:
Office of the Data Protection Ombudsman
Lintulahdenkuja 4, 00530 Helsinki
Tel. +358 29 566 6700
6. Changes to this Privacy Notice
We may amend or update this Privacy Notice, for example due to changes in legislation, case law or our own practices. The most up-to-date version of this Privacy Notice is available on our website.
7. Contact regarding data protection
For all questions related to data protection, please contact us by email at: tietosuoja@keksiagency.fi.
8. How is your personal data processed?
Below we describe, for each group of data subjects, what personal data we process, for what purposes, on what legal basis, to whom we disclose data and how long we retain it.
a) Website visitor
What data do we collect about you?
Our website includes various forms, such as a contact form and a request for quotation form. If you use these forms, we may process the following personal data:
• First name, last name
• Subject of your message
• Email address
• Organisation
• Content of your request for quotation
• Information relating to newsletter subscription
Personal data that is mandatory for the use of the forms is marked with an asterisk. If you do not wish to provide this information, you cannot use the forms. You can, however, contact us by email or phone.
How do we collect your data?
We collect your personal data directly from you through the website forms.
Why do we process your data?
We process your personal data for the purpose you have specified when contacting us via the forms (for example, a contact request, request for quotation, newsletter subscription).
What is the legal basis for processing
The legal basis for processing is your consent. You have the right to withdraw your consent at any time by contacting us at tietosuoja@keksiagency.fi.
To whom is your data disclosed?
Personal data is generally not disclosed to third parties.
We use external service providers in the processing of personal data (such as ICT service providers and CRM providers), who may process your personal data only for the purposes described in this Privacy Notice.
Personal data may be transferred to the servers of these service providers located outside the EU/EEA. If personal data is transferred outside the EU/EEA, we ensure that the processing of personal data is appropriately protected and carried out in accordance with this Privacy Notice. Safeguards may include, for example, an adequacy decision by the European Commission or appropriate contractual clauses, such as the European Commission’s Standard Contractual Clauses, as well as other appropriate safeguards.
How long do we retain your data?
We retain personal data collected via the forms for as long as necessary to respond to your contact request, to prepare and conclude a potential agreement with a prospective customer/subscriber/partner, or to develop our customer service.
Cookies
Our website uses cookies and similar technologies if you give your consent to their use when visiting the site for the first time. You can find more information about cookies via the cookie settings link on our website, where you can also later modify your choices.
Embedded content
Our website contains embedded content from, for example, video services and social media services (LinkedIn, Instagram, Facebook, Vimeo). Even if you do not allow cookies related to embedded content, you can still view all other content on the site. The providers of embedded services may use cookies for their own analytics and targeted marketing.
b) Customers and Subscribers
What data may we collect about you?
-
Personal data (name, usernames, login details)
-
Contact details (postal address, email address, phone number)
-
Employer details (your employer’s contact details, order history)
-
Details of your orders, including photographs and videos, tracking information and order history
-
Purchase and payment information (billing details, payment history)
-
Complaints, feedback and other customer relationship-related contacts, communications and actions, including call recordings and your activities related to Keksi on social media platforms
-
Data on the use of other Keksi services, such as information on newsletter subscriptions
-
Direct marketing permissions and prohibitions
-
Marketing actions targeted at you and information on their use, including whether you have opened our newsletters
We need personal data collected in connection with orders to fulfil the orders. Furthermore, the processing of certain personal data, such as data relating to complaints and direct marketing permissions, is based on our legal obligations.
If you do not provide certain personal data, this may result in our not being able to fulfil your order or enter into an agreement with you for the sale of our products and services.
How do we collect your data?
We mainly collect your personal data directly from you when you provide information in your dealings with us. You may provide information, for example, when placing an order. We also collect personal data in connection with campaigns and customer service situations, and when you subscribe to our newsletter.
We additionally collect and update personal data from the Finnish Population Information System, from Suomen Asiakastieto Oy and from other companies or authorities that provide address, updating and similar services.
Why do we process your data?
We process your personal data to manage, maintain and develop the customer relationship. Your data is needed to deliver our services, including processing your orders, communicating with you, and sending order and delivery confirmations. We also use your data to handle complaints, errors and other service issues.
We process your data for customer communications, including messages related to orders and service updates. In addition, we use your data for Keksi’s direct marketing and other marketing activities, including electronic direct marketing, market and opinion research, and analysing the use of our services.
To provide relevant content, we may tailor and target our marketing by analysing and profiling data such as order history and service usage. We do not carry out automated decision-making when profiling.
We also process your data for the analysis, development and statistical monitoring of our services and other business operations.
In addition, we process personal data to prevent and investigate potential misuse or fraud.
What is the legal basis for processing?
The primary legal basis for processing your personal data is Keksi’s legitimate interest arising from the customer relationship. We process your data to provide our services, deliver orders, send marketing and other communications, and sell our products and services to the extent necessary for these purposes. We also process personal data for creating profiles for targeted marketing based on our legitimate interest.
We have assessed, as required by data protection legislation and supervisory authorities, that your interests, fundamental rights and freedoms do not override our legitimate interest to process your data as described in this Privacy Notice. You have the right to object to processing based on legitimate interest by contacting us at tietosuoja@keksiagency.fi.
In some cases, the legal basis for processing is your consent, for example when we send you electronic direct marketing. You may withdraw your consent at any time by contacting tietosuoja@keksiagency.fi. After withdrawal, we retain information on your marketing opt-out for as long as your data is otherwise processed.
For private customers, the legal basis may also be the performance of a contract.
We also process personal data to comply with legal obligations, such as accounting requirements or disclosures required by law to competent authorities.
To whom is your data disclosed?
Your personal data may be disclosed to third parties only where this is necessary for the performance of tasks in accordance with the contract between us, for example in connection with arranging shooting schedules related to an order or in other similar situations.
We also use external service providers in the processing of personal data (such as ICT service providers, email systems, the Luuttu project management tool, Media Bank, cloud services, digital workspaces, file transfer tools and CRM systems), who may process your personal data solely for the purposes described in this Privacy Notice. Personal data may also be transferred to servers located outside the EU/EEA in connection with these service providers. If personal data is transferred outside the EU/EEA, we ensure that the processing is adequately protected and carried out in accordance with this Privacy Notice. Safeguards may include, for example, an adequacy decision issued by the European Commission or appropriate contractual clauses, such as the European Commission’s Standard Contractual Clauses, as well as other appropriate safeguards.
How long do we retain your data?
We retain order-related data and data collected in connection with customer service for ten (10) years from the end of the calendar year during which you last interacted with us, placed an order or contacted our customer service.
We retain all personal data necessary for compliance with our accounting obligations for ten (10) years from the end of the financial year during which the data was collected.
c) Model bank registrants
What data may we collect about you?
• Name, address, city, phone, email
• Date of birth
• Guardian details (for minors)
• Clothing size
• Previous modelling experience
• Photos
• Possible details regarding locations or other objects
• Tax card and bank account number (if you are selected for a shoot)
• Notes made by Keksi staff related to the shoots
Personal data that is mandatory for the use of the model bank is marked with an asterisk.
How do we collect your data?
We collect your personal data directly from you through the model bank, or from your guardian if the model is a minor.
Why do we process your data?
We process your data in order to assess your suitability for photo or video shoots organized by Keksi or by Keksi’s customers, as well as to organize the shoots and pay compensation if you are selected.
The processing is based on your consent, which you provide when registering in the model bank and submitting your personal data. Processing may also be based on the performance of a contract if you are selected for a shoot.
In addition, we may process personal data based on a legal obligation, for example in relation to our accounting obligations.
To whom is your data disclosed?
Your personal data (first name, photograph, clothing size, age and place of residence) may be disclosed to our customers for the purpose of evaluating whether you will be selected for a shoot.
Your personal data (full name, email address, phone number, age, clothing size and place of residence) may also be disclosed to our partners, such as stylists and make-up artists, in order to organise and carry out the shoot.
We also use external service providers in the processing of personal data (such as ICT service providers, the model bank system, email systems, cloud services and CRM systems), who may process your personal data solely for the purposes described in this Privacy Notice.
Personal data may also be transferred to servers located outside the EU/EEA in connection with these service providers. If personal data is transferred outside the EU/EEA, we ensure that the processing is adequately protected and carried out in accordance with this Privacy Notice. Safeguards may include, for example, an adequacy decision issued by the European Commission or appropriate contractual clauses, such as the European Commission’s Standard Contractual Clauses, as well as other appropriate safeguards.
How long do we retain your data?
Model bank data is deleted when ten (10) years have passed since you last contacted us or were active in the model bank.
d) Job Applicant
What data may we collect about you?
-
Name, address, phone number, email address
-
Your position in a company and the company’s contact details
-
Work history, education and other information you provide in your CV, references, job application or job interview
-
Language skills
You may decide yourself what personal data you provide to us in connection with the recruitment process or when submitting an open application. If you do not provide certain requested personal data, it may affect our ability to evaluate your suitability for the position.
How do we collect your data?
We collect your personal data directly from you through forms on our website, through job applications and during job interviews. We may also collect data from references you have provided.
Why do we process your data and what is the legal basis?
We process your data in connection with a recruitment process or when you submit an open application in order to evaluate your suitability for the position.
The processing is based on our legitimate interest in processing data during the recruitment process or when evaluating an open application. When processing personal data based on legitimate interest, we always take your right to privacy into account.
You have the right to object to processing based on legitimate interest by contacting us at tietosuoja@keksiagency.fi.
Processing may also be based on the performance of a contract if you are selected for the position, for the purpose of taking steps prior to entering into a contract at the request of the data subject.
To whom is your data disclosed?
As a rule, we do not disclose your personal data to third parties.
We also use external service providers in the processing of personal data (such as ICT service providers, email systems, cloud services and CRM systems), who may process your personal data solely for the purposes described in this Privacy Notice.
Personal data may also be transferred to servers located outside the EU/EEA. If personal data is transferred outside the EU/EEA, we ensure that the processing is adequately protected in accordance with this Privacy Notice.
How long do we retain your data?
Data retained for 2 years if you are not selected.
e) Partner
What data may we collect about you?
- Name, address, phone number, email address
- Your position in the company and the company’s contact details
- Work history, education, work samples/portfolio and other information you provide in your CV, references or interviews
- Language skills
- Bank account number, tax card and other information required for payment of compensation
- Information necessary for travel arrangements
How do we collect your data?
We primarily collect the above personal data directly from you or from a representative of your company.
Why do we process your data and what is the legal basis?
We process your data to the extent necessary to perform tasks in accordance with the agreement between us and to enable payment of compensation, internal communication, travel arrangements, and the implementation of occupational health and safety.
The legal basis for processing is the performance of a contract and compliance with legal obligations.
In some cases, processing may also be based on your consent. In such cases, you may withdraw your consent at any time by contacting tietosuoja@keksiagency.fi.
To whom is your data disclosed?
Your personal data may be disclosed to third parties only where necessary for performing tasks under the agreement between us, for example as part of offers, when arranging schedules or in similar situations.
We also use external service providers in the processing of personal data (such as ICT service providers, email systems, the Luuttu project management tool, Media Bank, cloud services, digital workspaces, file transfer tools and CRM systems), who may process your personal data solely for the purposes described in this Privacy Notice.
Personal data may also be transferred to servers located outside the EU/EEA in connection with these service providers. If personal data is transferred outside the EU/EEA, we ensure that the processing is adequately protected in accordance with this Privacy Notice.
How long do we retain your data?
Personal data is generally retained for three (3) years after the end of the contractual relationship and thereafter to the extent required by applicable legislation, regulations or the management of contractual rights.
f) Newsletter subscriber
What data do we collect about you?
- Name
- Email address
- Organisation
How do we collect your data?
We collect the above personal data directly from you.
Why do we process your data and what is the legal basis?
We process the data in order to send our newsletter for communication and marketing purposes.
The legal basis for processing is your consent, which you provide when subscribing to the newsletter. You may withdraw or update your consent at any time via the unsubscribe link included in the newsletter.
To whom is your data disclosed?
Personal data is generally not disclosed to third parties.
We also use external service providers in the processing of personal data (such as ICT service providers and CRM systems), who may process your personal data solely for the purposes described in this Privacy Notice.
Personal data may also be transferred to servers located outside the EU/EEA. If personal data is transferred outside the EU/EEA, we ensure that the processing is adequately protected in accordance with this Privacy Notice.
How long do we retain your data?
Personal data is retained for as long as necessary to send the newsletter (until the subscription is cancelled or the newsletter service ceases to exist).
g) Visitors to Keksi’s Social Media Accounts
What data do we collect about you?
If you interact with our social media accounts (Instagram, Facebook, LinkedIn, YouTube, Vimeo), we may process comments, images or reactions you provide on our accounts or posts.
Why do we process your data and what is the legal basis?
We process your data in connection with Keksi’s communication and marketing activities.
The legal basis for processing is your consent when you provide the above information on social media platforms. You may withdraw your consent at any time by deleting your reaction or comment.
Processing may also be based on Keksi’s legitimate interest in marketing and communicating about its activities and services.
To whom is your data disclosed?
All comments published and private messages sent on social media platforms are automatically stored on the respective platform.
Keksi does not store comments or private messages received via its social media channels on other platforms and does not disclose them further.
Links to social media services are available on our website. If you click a link, you will be redirected to the respective service, which has its own policies regarding cookies and privacy.
More information about cookies used on our website (including those related to social media platforms and embedded content) can be found via the cookie settings link on our website. We request your consent to the use of cookies when you first visit the site, and you may later modify your choices in the cookie settings.
How long do we retain your data?
The categories of personal data and retention periods can be found in the privacy policies of the respective social media service providers.