Privacy Policy
We process your personal data only within the framework of the General Data Protection Regulation (“GDPR”) and other applicable legislation and respect your right to privacy.
The purpose of this privacy policy is to inform you what personal data Oy Bufo Ab (“Bufo” or “We”) collects, for what purpose and in what way it is processed, and to inform you about your rights regarding your personal data processed by us.
Who is the controller?
Oy Bufo Ab (y-tunnus 2095754-7)
info@bufo.fi
Työpajankatu 2a R 1d
00580 Helsinki
Whose personal data do we process?
This privacy policy applies to you if you belong to one of the following categories of data subjects.
- You are a visitor to our website,
- a guest at an event we organize, such as a premiere,
- you have applied to us as an employee, trainee or assistant/volunteer (hereinafter referred to as “Job Applicant”),
- you are our employee (“Employee”),
- you act as an Extra/volunteer in our production (“Extra”),
- you provide your services in our production through or as an employee of a subcontractor (“Subcontractor”),
- you are a representative or employee of our customer or other partner in cooperation (“Partner”).
In section 6 of this privacy statement, we describe how we process your personal data depending on which categories of data subjects you belong to.
Do we disclose your data to third parties and is it transferred outside the EU/EEA?
Your personal data is processed in our company by those persons who need to process it due to their duties. Your personal data may also be transferred to our subsidiary B-Plan Distribution Oy (“B-plan”), which processes your personal data only for the purposes specified in this privacy policy.
We use external service providers who, as part of their service, may process personal data on our behalf (e.g. cloud storage, financial management system, accounting firm) only for the purposes mentioned in this privacy statement. In these situations, we have contractually ensured that the service providers process your data only in accordance with applicable data protection regulations and this privacy statement.
Personal data may be stored by these service providers on servers outside the EU/EEA. If this is the case, we will ensure that your personal data is processed in accordance with the requirements of the GDPR and that there is a basis for transfer as defined in Chapter V of the GDPR, such as an adequacy decision issued by the European Commission (Art. 45 GDPR) or standard clauses approved by the European Commission (Art. 46 GDPR).
If you are a visitor to our website or a guest at an event organized by us, or a Job Applicant, we will not, as a rule, transfer your personal data to third parties other than possibly to the above-mentioned service providers or B-Plan.
If you are an Employee, Extra, Subcontractor or Partner, your data may be transferred, in addition to the above-mentioned service providers and B-Plan, to parties necessary for the production and marketing of the productions, such as other persons and companies involved in the productions, such as production co-producers, production service companies, production financiers, production distributors or our customers or other production-related contractors or other partners, as well as their representatives, employees, legal assistants and the like. Depending on your role in the production, your name and position in the production may be publicly disseminated in the production’s marketing materials in various media also outside the EU/EEA, and this information may also be transferred to the IMDB (International Movie Database), where it is publicly available. Your personal data is primarily processed within the EU/EEA, but in order to fulfil the purposes of processing personal data mentioned in this policy, personal data may be transferred to parties in productions or partners internationally, also outside the EU/EEA, for marketing and distribution of the production or for the management or registration of rights to which your personal data relates. If this is the case, we will ensure that your personal data is processed in accordance with the requirements of the GDPR and that there is a basis for transfer as defined in Chapter V of the GDPR, such as an adequacy decision issued by the European Commission (Art. 45 GDPR) or standard clauses approved by the European Commission (Art. 46 GDPR).
In addition, the personal data of an Employee, Extra, Subcontractor or Partner may, depending on your role in the production, be disclosed to the National Audiovisual Institute KAVI, which collects credits lists and daily shooting schedules of Finnish films and maintains the Finnish film database Elonet.
We regularly disclose the personal data of our Employees to the Social Insurance Institution of Finland, occupational health service providers, tax authorities, insurance companies, pension insurance companies and other parties in order to fulfil statutory obligations as employers.
In addition to the above-mentioned disclosures, we also disclose your personal data when we are required to do so by law.
How long do we keep your personal data?
We process your personal data only for as long as it is necessary for our operations and legal obligations.
The retention periods of personal data vary depending on the purposes of use, and you can find the retention periods that apply to you in section 6 of the privacy policy under the categories of data subjects you belong to.
How have we protected your personal data?
Your personal data will be treated confidentially and securely and we have taken the necessary technical and organizational measures to protect your personal data, including from unauthorized access or destruction.
Personal data in electronic form is protected by generally acceptable and reasonable technical means in the industry, such as firewalls and passwords/fingerprint identifiers. Access to personal data is restricted to certain persons only.
We also require our service providers to take appropriate measures to protect the confidentiality and security of personal data.
What are your rights regarding the processing of personal data?
You have the right of access to your personal data stored by Us. This request may be refused on grounds set out by law. The exercise of the right is generally free of charge.
You have the right to request the rectification of incorrect data concerning you. In addition, in certain situations, you have the right to request the erasure of data concerning you or to request restriction of processing on grounds set out by law.
You have the right to object to processing activities concerning you when we process personal data based on legitimate interest. You can contact us info@bufo.fi if you wish to object to the processing of your data.
If we process your data on the basis of your consent, you have the right to withdraw your consent at any time at info@bufo.fi .
To the extent that you have provided us with data yourself and they are processed on the basis of your consent or agreement, you have, as a rule, the right to receive such data in machine-readable format and the right to transfer this data to another controller.
If you have any questions regarding the processing of your personal data, please contact us at info@bufo.fi .
If you consider that we have not complied with applicable data protection regulations in our operations, you have the right to lodge a complaint with the competent supervisory authority.
The competent supervisory authority in matters related to the processing of customers’ personal data is the Office of the Data Protection Ombudsman, Lintulahdenkuja 4, 00530 Helsinki, tel. 029 566 6700, tietosuoja@om.fi.
How is your personal data processed?
- Visitor to our website
Our website only uses cookies that are necessary for technical operation. We do not collect any information about you when you visit our website.
Our website contains embedded content from, for example, video services and social media services (Vimeo, Youtube, Facebook). Without allowing embedded cookies, you can see all content on the site. Embedded services may use cookies for their own analytics and targeted marketing.
- Guest at an event we organize
What information can we collect about you?
First name, last name, position in the company, email address, phone number.
How do we collect your data?
We collect your personal data either directly from you or your personal data may have been collected from public sources, such as the website of the company you represent.
Why do we process your data and what is the legal basis for the processing?
We process your data in order to invite you to an event organized by us.
The processing is based on our legitimate interest to communicate and market events and to develop our professional network to develop and promote our business. When processing your data on the basis of legitimate interest, we always take into account your right to privacy in relation to our aforementioned legitimate interest.
You have the right to object to processing activities concerning you when we process personal data based on legitimate interest. You can contact us info@bufo.fi if you wish to object to the processing of your data.
To whom is your data disclosed?
See point 3 above.
How long do we keep the data?
Your personal data will be inactivated after two years has passed from your last contact with us. This means that we only store your personal data. Your data will be deleted within 1 year of the passivation of the personal data if you have not contacted us after the passivation.
- Job Applicant
What information can we collect about you?
- name, address, telephone number, email address,
- Your position in the company and company contact information,
- work history, educational background, possible showreel, and other hobbies, etc. information you provide in your CV, certificates of employment or job interview,
- age and date of birth,
- language skills.
if you are also applying for a performing role
- information related to your appearance (screen age, height, etc.),
- show reel provided by you,
- test shooting material (still photos and video),
- Other information you provide.
You can decide for yourself what personal data you disclose to us in connection with the recruitment process or when submitting an open application. If you do not provide some of the personal data we have requested, it may affect whether we are able to adequately assess your suitability for the position.
How do we collect your data?
We collect your personal data mainly directly from you through job applications and job interviews.
We may also collect your data from references you have provided.
Why do we process your data and what is the legal basis for the processing?
We process your data during the recruitment process or when you send us an open job application so that we can assess your suitability for the position you are applying for.
Our processing is based on our legitimate interest to process data during the recruitment process or when evaluating your open application. When processing your data on the basis of legitimate interest, we always take into account your right to privacy in relation to our aforementioned legitimate interest.
You have the right to object to processing activities concerning you when we process your personal data on the basis of legitimate interest. You can contact us info@bufo.fi if you wish to object to the processing of your data.
In addition, our processing may be based on the performance of a contract, if you are selected for the task, in order to take pre-contractual measures at the request of the data subject.
To whom is your data disclosed?
See section 3 of this privacy statement.
How long do we keep the data?
We will store your personal data for one (1) year after the end of the recruitment process or the submission of an open application, if you are not selected for the position.
If you are selected for the position, see the data retention periods specified in section d) below.
- Employee, extra, subcontractor
What information can we collect about you?
- first name, last name, date of birth, age, social security number, telephone number, email address, postal address,
- your position in the company and contact details of the company,
- work history, educational background and other hobbies, etc. information you provide in your CV, certificates of employment or job interview,
- language skills,
- information necessary for personnel management and access control,
- your bank account number, tax card and other information related to the payment of wages or rewards,
- information necessary for travel arrangements,
- system and application usage data,
Also related to casting
- information related to your appearance (screen age, length, etc.),
- show reel provided by you,
- test shooting material (still photos and video).
How do we collect your data?
As a rule, we collect the above-mentioned personal data directly from you or your potential agent/representative.
If you act as an Extra, we may also have collected your data through a third party, for example through a sports club.
If you are a subcontractor, we may have received the information from a representative of the subcontractor.
Why do we process your data and what is the legal basis for the processing?
We process your data to the extent necessary for the carrying out of tasks based on an employment contract or other contract, for the implementation of human resources administration and salary payment, for internal communications of the company, for travel arrangements, and for the implementation of occupational health and safety.
The legal basis for processing is the performance of an employment contract or other contract and compliance with legal obligations.
In some limited respects, the legal basis for processing may also be your consent. In this case, you have the right to withdraw your consent at any time by sending us an email at info@bufo.fi.
To whom is your data disclosed?
See section 3 of this privacy statement.
How long do we keep the data?
As a rule, personal data is stored for the duration of the employment or contractual relationship and after their termination to the extent required of us by applicable legislation and other regulations or for as long as required by the management of rights based on contracts.
- Partner
What information can we collect about you?
- first name, last name, date of birth, telephone number, email address,
- your position in the company and contact details of the company.
How do we collect your data?
As a rule, we collect the above-mentioned personal data from the company you represent or from yourself.
Why do we process your data and what is the legal basis for the processing?
We process your data to the extent that, taking into account your task, it is necessary for the production of the productions and, for example, for negotiating production-related contracts and managing rights related to contracts.
The legal basis for processing is the performance of a contract and compliance with legal obligations.
To whom is your data disclosed?
See section 3 of this privacy statement.
How long do we keep the data?
As a rule, personal data is stored for the duration of the contractual relationship and after the termination of the contractual relationship for as long as required by the management of rights based on contracts, applicable legislation or other regulations.
- Changes to the Privacy Policy
We may change or update this privacy policy, for example, when regulations, case law or our own practices change. The up-to-date privacy policy can be found on our website.
- Who can you contact about data protection issues?
For all questions regarding data protection, please contact us by e-mail at info@bufo.fi .