Privacy notice

Last updated 19 June 2026.

Register holder

Nettiteeri Oy (3331525-2)
rauhanmusiikki(ät)rauhanmusiikki.fi
Viereläntie 4 A, 90630 Oulu

Contact person in matters concerning the register

Juha-Pekka Teirikangas
rauhanmusiikki(ät)rauhanmusiikki.fi

Name of the register

Rauhanmusiikki customer and producer register

Purpose and legal basis of processing

Personal data is processed to manage the customer relationship and subscription, to provide the service, to fulfil rights and obligations, to develop the service and produce statistics, and to prevent misuse.

Legal bases for processing:
- Managing the account and subscription: performance of a contract (GDPR Art. 6(1)(b)).
- Accounting and retention of payment transactions: legal obligation (Art. 6(1)(c)).
- Service development, statistics and fraud prevention: the controller's legitimate interest (Art. 6(1)(f)).

Name, email address, password and the information needed for payment are required to enter into the contract; without them an account or subscription cannot be created.

Register information

Common
- Customer's or producer's name
- Email address
- Crypted password
- Language
- Country
- IP address
- Partial credit card number (e.g. 492057******1234)
- Credit card validity time
- Credit card issuer name
- Order details and history
- Gift card details: name, amount, code and dates
- Track-specific listening statistics
- PDF note purchases
- Google Play subscription details
- Playlists
- Sessions
- Date the information was created
- Date the information was modified

Producer
- Image
- Description
- Homepage address
- IBAN bank account number
- Payment reference number
- Producer payment details: sum, date and status
- Album details: name, images and description

Paytrail collects the IP address, payment method and payment date in connection with the payment transaction.

Register sources

User inputs the information when registering into the service. Order and usage details are collected when the user uses the service. Producer information is collected based on the contract from them or from their publications. Where a producer's personal data is collected from a source other than the producer themselves, the data subject is provided with the information required by GDPR Article 14 within a reasonable period, at the latest within one month.

Recipients, processors and disclosure of data

Personal data may be disclosed to a competent authority based on a lawful request, and in connection with a business acquisition.

The service uses the following recipients and processors of personal data:
- Payment intermediation: Paytrail Oyj (online payments) and Nets Oy / Netaxept (recurring card charges for the subscription).
- Email delivery: Mailgun (EU region).
- Google Play purchases: Google.

Processors handle personal data on behalf of the controller under a data processing agreement, not for their own purposes.

Some processors may process personal data outside the European Economic Area (EEA). In that case the transfer is based on the European Commission's Standard Contractual Clauses (SCC). Further information on the safeguards is available from the controller.

Data retention time

Data is stored in the service for as long as the customer relationship is in force or until the user deletes their account. The account can be deleted with a button in the profile view.

Logs are kept for a year, after which they are deleted automatically. Backups are stored for at most a month. Individual listening events are deleted after three years at the latest; until then they are used to produce recommendations and statistics. Payment transactions are kept for the period required by accounting law.

Data security

The register is located in a server secured by a firewall, passwords and other commonly accepted security measures and can only be accessed by people working for the registrar. Backups are secured with a password and a key code. Contracts and their digital copies are also protected: physical copies behind locked doors and digital copies protected by a password.

Data subject's rights

The data subject has the right to access their data, rectify inaccurate data, erase their data ("be forgotten"), restrict and object to processing, and to data portability. Where processing is based on consent, the data subject has the right to withdraw consent at any time. Requests are addressed to the controller and answered within the period required by law.

The data subject has the right to lodge a complaint with the supervisory authority. In Finland the supervisory authority is the Data Protection Ombudsman (tietosuoja.fi).

The service does not carry out decisions based solely on automated processing that significantly affect the data subject within the meaning of GDPR Article 22.

Use of cookies on the site

The site uses only strictly necessary first-party cookies, for example to enable login and maintain the session (including the session cookie, XSRF protection, cookie acceptance, listening history and browser-support check). The service does not use third-party analytics or tracking tools and does not profile users for advertising.