Privacy notice

We at FCG Rakennettu Ympäristö Oy (hereinafter RaY) are committed to ensuring that all processing of personal data is carried out in accordance with data protection laws and their principles, as well as with the regulations and/or codes of conduct established by supervisory authorities and local legislation. We ensure secure, safe, ethical and transparent processing of all personal data and take measures to enable data subjects to exercise their rights.

1 Controller

FCG Rakennettu Ympäristö Oy (3485116-1)
Osmontie 34, 00610 Helsinki
010 409 2000

2 Contact person for matters concerning the register

Sami Vihelä
sami.vihela@fcg.fi

3 Data Protection Officer for matters concerning the register

tietosuojavastaava@fcg.fi

4 Name of the register

Master’s Thesis Research Register

5 Whose personal data do we collect?

The register contains data relating to the following groups of individuals:

  • Participants in the research survey

6 For what purpose do we use personal data and what is the legal basis for processing?

The purpose of processing personal data is to collect material for a master’s thesis on the topic “Removal of micropollutants from wastewater”. The thesis is prepared on commission from RaY.

Personal data are used to carry out the survey and study, to process feedback and to analyse responses. The register is used solely for research purposes.

The master’s thesis will be archived and published in Aalto University’s institutional repository. In addition, the thesis may be published through the Finnish Water Utilities Association’s publication channels and on RaY’s website. Direct identifiers, such as name and email address, will be removed from the published thesis.

The processing of personal data is based on the respondent’s consent.

7 What personal data do we process and how long do we retain them?

The register may contain the following data:

  • First and last name
  • Email address
  • Company
  • Any personal data provided in open-ended responses

No special categories of personal data or other particularly sensitive data are processed in the study.

Personal data will be deleted 3 months after the thesis has been published.

If a data subject withdraws consent, their data will be deleted.

With respect to an approved master’s thesis, withdrawal of consent will no longer have an effect, because an approved master’s thesis is an academic publication issued as part of freedom of academic expression (Articles 6 and 85 of the General Data Protection Regulation (EU) 2016/679 and Section 27 of the Data Protection Act of Finland (1050/2018)). Data can no longer be removed from an approved thesis.

8 Where do we obtain personal data?

Data are obtained from individuals who respond to the survey.

9 Who processes personal data and to whom may they be disclosed?

Personal data are processed only by RaY employees involved in conducting the survey and by the supervising professor at Aalto University, where necessary.

We may disclose your personal data as required by competent authorities, in a manner based on the applicable legislation in force at any given time. Such authorities include, for example, tax, police, enforcement and supervisory authorities.

10 Transfer of personal data outside the EU or EEA

In some cases, we may transfer personal data to organisations operating outside the EU and EEA, i.e. in so-called third countries. Such transfers may be carried out if one of the following conditions is met:

  • The European Commission has decided that the third country in question ensures an adequate level of data protection.
  • Other necessary safeguards have been implemented, for example by complying with the European Commission’s standard contractual clauses or by ensuring that the company processing the data has valid binding corporate rules.
  • Derogations apply to specific situations, for example where this is necessary for the performance of a contract, or you have given your consent to the transfer of the data in question.

11 How do we protect personal data?

The register typically does not generate paper materials. Should such materials be created, they will be destroyed in a secure manner in accordance with the controller’s data protection policy.

The controller ensures that information systems are protected by restricting access rights and by appropriate updates. Information systems are also protected by network technical measures (use of firewalls and positioning systems in different network segments). The survey is conducted using the Webropol system, and Microsoft Teams and Outlook are also used.

12 Rights related to the processing of personal data and additional information

The data subject has the right to request access to their personal data, as well as the right to request rectification or deletion of their personal data, or restriction of processing, or to object to processing. The data subject has the right to prohibit direct marketing targeted at them.

The data subject has the right to receive the personal data concerning them, which they have provided to the controller, in a commonly used and machine-readable format, and the right to transmit those data to another controller where the processing is based on the data subject’s consent.

Every data subject has the right to lodge a complaint with the competent supervisory authority, or with the supervisory authority of the EU Member State where the data subject has their residence or place of work, if the data subject considers that their personal data have not been processed in accordance with the applicable data protection legislation.

The data subject has the right to withdraw consent-based processing of personal data at any time.


The controller may ask the data subject to specify their request in writing and to verify the data subject’s identity before processing the request. The controller may refuse to comply with a request on grounds laid down in applicable law.

The data subject will be provided with the necessary information given in this privacy notice when personal data are collected from the data subject, or when personal data have not been obtained directly from the data subject.

Providing personal data is not a statutory requirement. The data subject is not obliged to provide personal data, and failure to provide such data will not result in consequences. The provision of personal data may be based on a contract or the conclusion of a contract and may thus be a prerequisite for purchasing the controller’s services.

If you wish to exercise your rights or obtain further information about the processing of your personal data, you may also contact the controller by sending an email to tietosuojavastaava@fcg.fi. We may, where necessary, ask the data subject to specify their request in writing, and the data subject’s identity may be verified before taking any further measures. We may refuse to disclose personal data on grounds defined in data protection legislation.

13 More information on data subject rights

The rights of the data subject are laid down in the European Union’s General Data Protection Regulation (EU 679/2016) and will be further specified in national legislation complementing it. The Office of the Data Protection Ombudsman publishes information on data subject rights and provides instructions on exercising those rights on its website https://tietosuoja.fi/.

14 Changes to the privacy notice

We are continuously developing our services and may update this privacy notice as necessary. Changes may also relate to amendments in legislation. If the changes made are material, we will announce them on our website and/or by contacting you in another appropriate manner.

We recommend that you review the contents of this privacy notice from time to time to acquaint yourself with any changes that may have been made.

Last updated 26/08/2026