OmaLeima
HomePrivacyTermsApp terms
ENSuomeksiContact us

Public information

Privacy notice

This privacy notice explains how OmaLeima processes personal data on the public website, in the mobile app, during pilot enquiries, and in student-event operations.

Last updatedAugust 1, 2026
Effective fromAugust 1, 2026
Version2026-08-01
Back to home
On this page
  • 1. Controller and responsibilities
  • 2. Personal data we process
  • 3. Purposes and legal bases
  • 4. Sources of data
  • 5. Recipients and service providers
  • 6. International transfers
  • 7. Retention
  • 8. Your rights and how to use them
  • 9. Account and data deletion
  • 10. Security checks and automated decisions
  • 11. Cookies, local storage, and Turnstile
  • 12. Mobile permissions and app data
  • 13. Children, event rules, and security
  • 14. Changes and contact

1. Controller and responsibilities

This notice describes the processing for which the OmaLeima service provider determines the purposes and means. It covers the public website, the mobile app, pilot communications, and platform security.

An event organiser, student club, venue, or business may be a separate controller for the event registration, attendance, participant communication, or reward fulfilment that it determines itself. Where OmaLeima processes data only on an organiser's documented instructions, the parties' roles and responsibilities are defined in the applicable agreement.

  • Controller / service provider: T:mi Aslan Dogan Marketing
  • Business ID: 3346878-5
  • Email: contact@omaleima.fi
  • Phone: 045 124 2459
  • Address: Sarvivälkkeentie 3 C 27, 90240 Oulu

2. Personal data we process

We collect only the information needed for the feature or communication you choose to use. Some fields are optional; refusing a device permission can limit the related feature without preventing other use of the service.

  • Public-site technical data: IP address, browser and request metadata, timestamps, security events, and error information.
  • Account and profile data: name, email address, authentication-provider identifier, role access, profile tags, organisation or club membership, and support history.
  • Event-operation data: event registrations, QR token metadata, token timestamps and identifiers, leima scans, scanner account and device identifiers, reward and leaderboard status, and event audit history.
  • Security and fraud data: IP and user-agent signals, replay or duplicate-scan indicators, scanner location proof when the feature is used and permission is granted, and review outcomes.
  • Device and permission data: push notification tokens, camera access for QR scanning, photos or videos when a user or organiser chooses to upload or save media, and local settings needed for the app.
  • Communication and business data: contact details, message content, attachments, organisation details, and pilot or partnership information that you provide.

3. Purposes and legal bases

The legal basis depends on the specific processing activity. The following summary is intended to make that distinction visible instead of treating all data processing as one purpose.

PurposeLegal basis
Operate the website, app, accounts, event participation, QR flows, rewards, support, and organiser tools.Performance of a contract or steps requested before entering a contract; where an organiser controls the event, its instructions or separate controller basis may also apply.
Protect accounts, prevent spam, QR replay, duplicate leimas, scanner misuse, reward abuse, and event-day fraud.Legitimate interest in securing the service and protecting users, organisers, businesses, and event integrity.
Answer contact, pilot, partnership, and business-application requests.Pre-contractual steps or legitimate interest in handling an initiated business conversation. The form checkbox is an acknowledgement of this handling, not marketing consent.
Send a push notification that you have enabled or requested.Performance of the service contract or your requested action; device notification permission is handled by the operating system.
Meet accounting, tax, legal, security, or claim-handling duties.Compliance with a legal obligation or legitimate interest in establishing, exercising, or defending legal claims.

4. Sources of data

We do not buy personal-data lists for the service and do not rely on hidden data sources. If a separate organiser or business controller provides data to OmaLeima, that party should give its own notice where required.

  • From you when you create or use an account, edit a profile, register for an event, show or scan a QR code, claim a reward, upload media, submit a support request, or contact us.
  • From organisers, clubs, approved businesses, venue staff, and scanner operators when they configure or operate an event.
  • From the browser, device, hosting layer, authentication layer, and security services when a request or event action is made.
  • From system-generated audit and status events required to verify a scan, reward, permission, or account action.

5. Recipients and service providers

We use carefully limited service providers to host the website, authenticate users, store and process event data, deliver push notifications, and protect forms from abuse. A provider may be our processor or a separate controller for its own legally required processing; the role depends on the service and contract.

Provider or categoryRole and purpose
Vercel and hosting infrastructureWebsite delivery, server execution, request handling, and operational logs.
SupabaseAuthentication, database, storage, and backend service infrastructure for accounts and event operations.
Cloudflare TurnstileBot and abuse protection for public forms and authentication-related flows. Turnstile receives the challenge response and security signals needed to assess whether a request is likely automated.
Expo push service and operating-system providersDelivery of push notifications that are enabled for the app. Apple and Google may process data under their own platform terms when their services are used.
Email and communication providersReceiving, routing, and replying to contact, support, and pilot messages.
Advisers, auditors, authorities, or dispute bodiesOnly when needed for legal compliance, security, accounting, claims, or a formal dispute.
Further information
  • Cloudflare Turnstile Privacy Addendum
  • Office of the Data Protection Ombudsman: individual rights

6. International transfers

Some providers may process data outside Finland or outside the European Economic Area. Before using such a provider for personal data, we use the transfer mechanism required by the GDPR, such as an adequacy decision or standard contractual clauses, together with supplementary safeguards where needed.

Provider locations, subprocessors, and safeguards can change. You may contact us to ask which safeguards apply to a particular transfer or request the relevant information in an accessible form.

7. Retention

We keep information for the shortest period that supports the stated purpose. Exact provider log periods can also depend on the provider's current service configuration and contract.

Data categoryRetention criterion
Public-site security, rate-limit, and error logsA limited operational period needed to investigate abuse, maintain availability, and resolve incidents; then deletion or anonymisation when no longer needed.
Contact, support, pilot, and business-application messagesUntil the request or onboarding discussion is resolved and for any necessary legal, accounting, or claim-handling record period.
Account, event, leima, reward, and leaderboard recordsWhile the account or event service is active and for the limited period needed to resolve event disputes, support claims, prevent fraud, or meet a legal duty.
QR, scanner, fraud-review, and audit recordsThrough the relevant event and review window, then deletion, aggregation, or de-identification unless a legal or security reason requires longer retention.
Push notification tokensUntil you disable notifications, remove the device, the token becomes invalid, or the account is deleted, subject to necessary security records.

8. Your rights and how to use them

Send a request to contact@omaleima.fi or use the in-app support flow. We normally respond within one month; where a request is complex, the period may be extended as permitted by the GDPR and we will explain why. We may ask for proportionate identity verification before disclosing or deleting data.

  • Access and a copy of your personal data.
  • Correction of inaccurate or incomplete data.
  • Erasure where the GDPR conditions are met.
  • Restriction of processing in the situations provided by law.
  • Objection to processing based on legitimate interest, including a request to stop that processing unless we have overriding lawful grounds.
  • Data portability where the right applies.
  • Withdrawal of consent where processing is based on consent. Withdrawal does not affect processing already carried out lawfully.
  • A complaint to the Finnish Data Protection Ombudsman.

9. Account and data deletion

This public page is the public web resource for OmaLeima account deletion and associated data deletion requests. App-store account deletion links must point to this resource or the equivalent English page.

  • In the app, open Profile or Settings, choose Support, and select the account and data-deletion request template.
  • On the web, send an account deletion or data deletion request to contact@omaleima.fi. Include the email address used for OmaLeima.
  • Deleting an account removes or anonymises data that no longer has a lawful retention reason. We may retain a limited record for legal duties, security, fraud prevention, accounting, or defence of claims.
  • Event organisers or businesses may need to handle data for which they are separate controllers; we may forward or clarify the request where appropriate.

10. Security checks and automated decisions

OmaLeima uses automatic security checks to validate QR and scanner requests and may reject a request that appears to be expired, replayed, duplicated, unauthorised, or unsafe. These checks protect event integrity; they are not intended to decide a person's legal status or make a solely automated decision with legal or similarly significant effects.

Security or fraud signals can lead to a manual review of an event action. If an automated security restriction has affected your use, contact support with the event and account details so the decision can be checked where appropriate.

11. Cookies, local storage, and Turnstile

The public website currently uses necessary first-party cookies and similar local storage for secure sessions, dashboard authentication, language preference, form protection, and remembering your cookie choice. Optional analytics and marketing cookies are not currently loaded.

StoragePurpose
omaleima_cookie_consentStores the website cookie preference and its consent-version marker for up to the configured preference period.
sb-<project-ref>-auth-token and chunksSupabase authentication session storage. The exact name can include the project reference and may be split into cookie chunks; token values are not listed here.
omaleima_dashboard_csrfRequired browser protection for dashboard and login form requests.
Browser local storage and mobile device storageLanguage and interface preferences, privacy acknowledgement, secure session support, QR and support state, and other feature-required local state.
Cloudflare Turnstile challenge signalsSecurity signals used to distinguish legitimate form or auth requests from automated abuse. Turnstile is not used for OmaLeima marketing or behavioural advertising.

12. Mobile permissions and app data

Operating-system permission prompts explain the relevant permission at the time it is requested. You can change permissions in device settings; disabling one may disable the related feature.

  • Camera access is requested for QR scanning and is not required for reading this notice or using unrelated app areas.
  • Photo and video access is used only when the relevant media feature is chosen, such as uploading or saving approved event content.
  • Precise location may be requested for scanner location proof in an event-security flow. It is not a general background location feature.
  • Push tokens are used only for enabled notifications and can become invalid when the device or account changes.
  • The app does not use marketing cookies or cross-app advertising tracking.

13. Children, event rules, and security

OmaLeima is designed for student events and is not directed at children. We do not knowingly collect children's personal data without an applicable legal basis and any required guardian or other lawful authorisation. Organisers and venues remain responsible for their own age, access, alcohol, safety, and participant rules.

We use access controls, server-side authorisation, validation, rate limits, audit trails, encryption in transit, and provider security controls proportionate to the risk. No online service can promise absolute security. Suspected security incidents or privacy concerns should be sent to the contact address above without including unnecessary sensitive information.

14. Changes and contact

We may update this notice when the service, providers, processing purposes, or legal requirements change. The version and effective date at the top of this page show which text is current. Material changes will be presented through the website, app, or another appropriate channel where required.

Questions, rights requests, and privacy concerns can be sent to contact@omaleima.fi.

At a glance

The important parts, at a glance

  • This notice covers the public website, mobile app, and event operations.
  • Security data such as QR metadata and scanner location proof is used to protect event integrity.
  • Optional analytics and marketing cookies are not currently loaded.
  • Account and data-deletion requests can be started in the app or by email.

OmaLeima

The digital stamp pass and checkpoint infrastructure for Finnish student events. Built to streamline appro nights and overall rewards on the phone.

Download on theApp StoreGET IT ONGoogle Play
Instagram
Quick Links
HomeGuides & BlogBecome a PartnerContact Us
Contact Details
Company InfoT:mi Aslan Dogan Marketing
contact@omaleima.fi045 124 2459
Sarvivälkkeentie 3 C 27, 90240 Oulu
Business ID: 3346878-5
Legal
Privacy noticeTerms of useApp terms

© 2026 OmaLeima. All rights reserved.

OmaLeima

Cookie and privacy choices

We use essential cookies for security, authentication, language and form protection. Optional analytics or marketing cookies are not currently loaded.

Privacy noticeTerms of use