Skip to content

Privacy Notice

Updated March 2, 2026

We process your personal data exclusively within the framework of the General Data Protection Regulation (GDPR) and other applicable legislation, and we respect your right to privacy.

The purpose of this Privacy Notice is to explain what personal data Keksi Agency Oy (“Keksi” or “We”) collects, for what purposes, and how it is processed. It also informs you of your rights related to the personal data we process.

 

1. Who is the Controller?

Keksi Agency Oy (2519402-4)
Mannerheimintie 142, 00270 Helsinki

Contact person for matters concerning the register:
CEO Jenni-Justiina Niemi
tietosuoja@keksiagency.fi

 

2. Whose personal data do we process?

This Privacy Notice applies to you if you belong to one of the following categories of data subjects:

a) a visitor to our website

b) our subscriber, representative or employee, our customer, or the representative or employee of a customer (“Customer or Subscriber”)

c) an individual registered in our model bank

d) an applicant for a collaboration role, employment, internship, assisting role or volunteering position (“Job Applicant”)

e) our partner or subcontractor, or their representative or employee (“Partner”)

f) a subscriber to our newsletter

g) a visitor to our social media accounts

Section 8 of this Privacy Notice describes, for each group, how we process your specific data.

 

3. How long do we retain personal data?

We retain your personal data only for as long as is necessary for our operations and to fulfil legal obligations.

Retention periods vary depending on the purpose of processing. You will find the retention period relevant to your category in Section 6.

 

4. How have we protected your personal data?

Your personal data is processed confidentially and securely. We have implemented appropriate technical and organisational safeguards to protect your data, including preventing unauthorized access or destruction.

Electronic data is protected using industry-standard technical measures. Data is stored in databases protected by firewalls, passwords and other safeguards. Databases and backups are located in locked and monitored facilities with access granted only to authorized individuals.

Physical records are stored securely in Keksi’s locked premises.

We have entered into appropriate data processing agreements with our service providers and require them to implement suitable confidentiality and security measures.

 

5. Your rights regarding personal data

You have the right to access the data we hold about you. This request may be refused only on lawful grounds and is generally free of charge.

You have the right to request correction of inaccurate data. In certain cases, you also have the right to request deletion of your data or restriction of processing on grounds permitted by law.

You have the right to object to processing based on our legitimate interests. You may contact us at tietosuoja@keksiagency.fi if you wish to object.

If processing is based on your consent, you may withdraw that consent at any time by contacting tietosuoja@keksiagency.fi.

Where you have provided data yourself and the processing is based on your consent or an agreement, you generally have the right to receive your data in a machine-readable format and transfer it to another controller.

If you have questions regarding the processing of your personal data, please contact us at tietosuoja@keksiagency.fi.

If you believe we have not complied with applicable data protection laws, you have the right to lodge a complaint with:

Office of the Data Protection Ombudsman
Lintulahdenkuja 4, 00530 Helsinki
Tel. +358 29 566 6700
tietosuoja@om.fi

 

6. Changes to this Privacy Notice

We may update this Privacy Notice due to changes in legislation, case law or our internal practices. The most up-to-date version is available on our website.

 

7. Contact regarding data protection

For all matters related to data protection, please contact us at tietosuoja@keksiagency.fi.

 

8. How is your personal data processed?

 

a) Website visitor

 

What data do we collect?

• First name, last name

• Subject of your message

• Email address

• Organisation

• Quote request content

• Newsletter subscription information

Mandatory fields are marked with an asterisk. You can also contact us via email or phone.

 

How do we collect your data?

Directly through the form.

 

Why do we process your data?

To respond to the purpose specified in your contact (e.g., quote request, contact request, newsletter subscription).

 

Legal basis

Consent, which you may withdraw at any time by contacting tietosuoja@keksiagency.fi.

 

Disclosures

Not generally disclosed to third parties. External service providers (ICT, CRM) may process data according to this Notice. Transfers outside the EU/EEA follow appropriate safeguards.

 

Retention

Data is retained as long as necessary to respond, prepare or conclude agreements, or improve customer service.

 

Cookies

Our website uses cookies with your consent. You can adjust preferences in cookie settings.

 

Embedded content

Our site contains embedded content (e.g., Vimeo, LinkedIn, Instagram, Facebook). These services may use cookies for analytics and marketing.

 

b) Customers and Subscribers

 

Data collected:

• Personal data (name, usernames, login data)

• Contact information

• Employer and order history details

• Order content including photographs and videos

• Purchase and payment details

• Complaints, communication, call recordings, social media interactions

• Newsletter subscriptions

• Marketing permissions and prohibitions

• Information on marketing actions and newsletter openings

Data is needed to fulfil orders and meet legal obligations.

 

How collected:

Directly from you, customer service situations, campaigns and newsletter subscriptions. Also updated from official registers.

 

Why processed:

To manage and develop customer relationships, deliver services, handle complaints, communication, direct marketing, profiling (without automated decision-making), business analytics, statistics, and to prevent misuse.

 

Legal basis:

Legitimate interest, consent (for electronic marketing), contract performance (for private customers), and legal obligations.

 

Disclosures:

To third parties only when necessary to fulfil a contract. External service providers (ICT, email, Luuttu, Media Bank, cloud services, digital workspace, file transfer tools, CRM) may process data.

 

Retention:

Order and customer service data retained for 10 years from the year of last interaction.

Accounting data retained for 10 years from the end of the financial year.

 

c) Model bank registrants

 

Data collected:

• Name, address, city, phone, email

• Date of birth

• Guardian details (for minors)

• Clothing size

• Prior modelling experience

• Photos

• Possible details regarding filming location

• Tax card and bank account number (if selected)

• Notes made by Keksi staff

 

How collected:

Directly from you or a guardian.

 

Why processed:

To assess suitability for shoots, carry out shoots and pay compensation. Based on consent, contract performance (if selected), and legal obligations.

 

Disclosures:

To clients (first name, photo, clothing size, age, city) for assessment. To partners (full contact details) for shoots. External service providers may process data.

 

Retention:

Data deleted after 10 years of last activity or contact.

 

d) Job Applicant

 

Data collected:

• Name, address, phone number, email

• Position and employer details

• CV, education, experience, certificates, interview information

• Language skills

 

How collected:

Directly from you, from applications, interviews and provided referees.

 

Why processed:

To assess suitability in recruitment or open applications. Legal basis: legitimate interest and contract performance (if selected).

 

Disclosures:

Not generally disclosed. External service providers may process data.

 

Retention:

Data retained for 2 years if you are not selected.

 

e) Partner

 

Data collected:

• Contact details

• Role and company details

• Work history, education, portfolio

• Language skills

• Payment details (bank account, tax card)

• Travel-related information

 

Why processed:

To perform contractual tasks, pay compensation, handle internal communication, travel arrangements, and ensure work safety. Legal basis: contract and legal obligations; consent in some cases.

 

Disclosures:

To third parties only when necessary to fulfil contracts. External service providers may process data.

 

Retention:

Generally retained for 3 years after contract end, and longer if required by law.

 

f) Newsletter subscriber

 

Data collected:

• Name, email, organisation

 

Why processed:

To send newsletters for communication and marketing. Legal basis: consent (withdrawable anytime).

 

Disclosures:

Not generally disclosed. External service providers may process data.

 

Retention:

Retained as long as necessary (until unsubscribed or service discontinued).

 

g) Social media visitors

 

Data collected:

Comments, images or reactions posted on our accounts.

 

Why processed:

For communication and marketing. Legal basis: consent (given by posting) and legitimate interest.

 

Disclosures:

Content is stored on the social media platform. Keksi does not store or forward this content elsewhere. Platform-specific privacy policies apply.

 

Retention:

According to each platform's privacy policy.