Updated 3.8.2026
Privacy Policy
Ventell
Date of issue: 3.8.2026
This is a translation of the Finnish original. In the event of any discrepancy between the language versions, the Finnish text shall prevail. The Finnish version is available at ventell.eu/tietosuoja.
This privacy policy covers two separate registers: the website contact register (sections 1–12) and the patient register (section 13). Different retention periods and different disclosure practices apply to each register.
Sections 1–12 describe how we process personal data collected through the contact and quote request form on the ventell.eu website.
1. Data controller
Katerina Ventell
Business ID (Y-tunnus): 2494677-3
Email: Katerina.Ventell@gmail.com
Phone: +358 44 984 5281
Register matters are handled by the data controller personally.
2. Name of the register
Website contact and quote request register.
3. Purpose of processing personal data
Personal data is processed for the following purposes:
- responding to quote requests and enquiries
- planning and providing the service according to the client's needs
- communicating with the client while the matter is being handled
Personal data is not used for marketing, profiling or automated decision-making.
4. Legal basis for processing
Processing is based on the data subject's consent (EU General Data Protection Regulation, Article 6(1)(a)).
Consent is given when submitting the form, by means of a separate checkbox. Consent may be withdrawn at any time by contacting the data controller.
5. Personal data processed
The following data is collected through the form:
Required information
- company
- contact person's name
- email address
Optional information
- phone number
- number of people
- whether the request concerns an event or a regular service
- preferred timing
- location
- additional information (free text field)
In addition, the form delivery service may process the sender's IP address for spam prevention purposes (section 7).
We do not collect health data or other data belonging to special categories of personal data through the web form. Data subjects are asked not to write information concerning their state of health in the free text fields.
6. Regular sources of data
Data is obtained solely from the data subject through the website form. Data is not collected from any other sources.
7. Recipients and processors of data
Personal data is not sold or disclosed for marketing purposes. The following service providers process the data:
Web3Forms — form delivery service
Receives the form data and forwards it by email to the data
controller. The service's servers are located in the United States (Amazon Web Services).
Form submissions are retained on the service's free tier for 30 days, after which they
are deleted automatically.
Privacy policy: web3forms.com/privacy
Spam prevention
Web3Forms may forward the sender's IP address and email address to spam filtering services (CleanTalk, Akismet) in order to prevent misuse.
Google (Gmail) — email reception
Form data is received by email. The email service provider processes messages as part of providing the service.
Transfers outside the EU and EEA
This section applies only to data collected through the web form. Patient register data is not disclosed outside the EU or EEA (section 13.5).
Some of the service providers listed above process data in the United States. Such transfers are based on the standard contractual clauses approved by the European Commission or on the EU–U.S. Data Privacy Framework.
8. Retention period
Data received through the form is retained for 12 months from the date of contact, after which it is deleted.
If the enquiry leads to a client relationship, the data is retained for the duration of that relationship and, after it ends, for as long as required by law.
In the Web3Forms service, form submissions are deleted automatically after 30 days on the service's free tier.
9. Principles of register protection
This section concerns the website contact register. The protection of the patient register is described in section 13.6.
- Data is transmitted from the form over an encrypted connection (HTTPS).
- Data is stored in an email account protected by a password and two-factor authentication.
- Access to the data is limited to the data controller alone.
- No manual or paper-based material is created.
10. Rights of the data subject
The data subject has the right to:
- access their data — to check what data has been stored about them
- rectify incorrect or incomplete data
- erase their data («the right to be forgotten»)
- restrict processing
- object to processing
- data portability — to transfer data from one system to another
- withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Requests should be addressed to the data controller at the address given in section 1: Katerina.Ventell@gmail.com. Requests are responded to within one month.
Right to lodge a complaint
The data subject has the right to lodge a complaint with the supervisory authority if they consider that the processing of personal data infringes data protection legislation.
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Lintulahdenkuja 4, 00530 Helsinki
P.O. Box 800, 00531 Helsinki
Phone: 029 566 6700
tietosuoja.fi
11. Cookies
The website does not use cookies or visitor tracking. The site has no advertisements and no third-party tracking tools.
12. Changes to this privacy policy
This privacy policy may be updated as services or legislation change. The current version is always available at ventell.eu/en/privacy.
13. Patient register
13.1 Name of the register
Patient register.
13.2 Purpose of processing personal data
The register has been established for the purpose of providing health care services. The processing of patient data is a prerequisite for the data controller to be able to offer health care services to the client.
The processing of personal data is based on the need to comply with the data controller's statutory obligations. In addition, processing is based on consent where the purpose is communication with clients and the maintenance of the client relationship.
Data is not used for automated decision-making or profiling.
13.3 Content of the register
The data stored in the register includes: the person's name, personal identity code (henkilötunnus), contact details (phone number, email address, address), underlying medical conditions, and the reason for seeking treatment.
13.4 Regular sources of data
The data stored in the register is obtained from the client themselves, e.g. through a preliminary information form, by email, by telephone, at client appointments and in other situations in which the client provides their data.
13.5 Disclosures and transfers outside the EU
Patient register data is not disclosed outside the EU or EEA by the data controller.
The data controller processes personal data personally, but where necessary uses an information technology service provider as an assistant. The data controller endeavours to use the best and most reliable partners and is responsible for the conduct of the service providers it selects when personal data is processed.
13.6 Principles of register protection
Care is exercised in the processing of the register, and data processed by means of information systems is protected appropriately. Where register data is stored on internet servers, the physical and digital security of the equipment is duly ensured.
The data controller ensures that stored data, server access rights and other data critical to the security of personal data are handled confidentially and only by the data controller.
13.7 Retention period
The general statutory retention period for patient records is 12 years from the death of the patient or, if there is no information on this, 120 years from the patient's birth, or 12 years from the end of treatment.
The rights of the data subject are described in section 10. They also apply to patient register data.
← Back to the home page