Name of the service E-signature service (Oamk sign)
Data controller (liable organisation) Oulun Ammattikorkeakoulu Oy
Y-tunnus 2509747-8
PL 222, 90101 OULU
Contact information Ulla Virranniemi, , 0503610769
Data Protection Officer (DPO) Ulla Virranniemi,
The purposes of processing the personal data The Oulu University of Applied Sciences (Oamk) has several tasks, which require entering into agreements and decision-making. Such
processes require signing of contracts.

The processing of personal data is necessary to complete the tasks. Personal data processing is needed also in user assistance and the observing of the Oamk Sign system performance.

Some of the tasks that require signing, are based on legal obligations, for instance, the Universities of Applied Sciences Act and employer legislation. Also some tasks related to the public interest may require decisions and agreements that need to be signed.
Automated decision-making or profiling based on personal data Oamk will not use your personal data for any other purposes than mentioned above in the purposes of processing the personal data.
Personal data used in the service Oamk staff and students:
- Basic information: first name, last name, email address, organisation, title and phone number
- person ID number,
-registration information (username, password, some other unique identifier, if any)
- office address, IP address, user signature transaction information
- data concerning employment: position

The signatories outside oamk:
- name,
- email address,
- phone number,
- position
- IP address of the user’s computer, signature transaction information, registration information
(password and another unique identifier, if any)
- organisation details of the signatory: organisation name, business ID, organisation address
Data sources Some of the personal data is collected from you during your use of the Oamk Sign (e.g. IP address).

Oamk's students' and staff members basic information is collected from Oamk's user database (Active Directory).

The employee who adds the documents to be signed in the system, collects information about the contracting partners' signatories from the contracting partner and its signatories themselves. The employee may also collect personal data of its contracting partners’ signatories from publicly available sources.
Data processors (roles that can access the data) Those Oamk and University of Oulu staff members who prepare the signature requests, can see all the contact information in the system.

A document uploaded in the system is available for the employee who added the document, and the persons he/she has added to the request as
- persons for whom the signature request has been sent to,
- persons who are added to the request for information only, and
- those Oamk and University of Oulu employees who need to access the documents as a part of their duties.

ICT services' local administrators (who all are University of Oulu staff members) need the access to the contact information and the reports. They cannot access the documents.

The service provider (Sarake Oy) administrates the system technically and therefore they can access all the data in the system.
Transfers of personal data to other services (both inside OUAS and to other services inside the EU) At Oamk, the personal data in Oamk Sign can be processed by those employees (at Oamk or the University of Oulu) commissioned by or acting on behalf of the Oamk who need them in their tasks.

Personal data will be disclosed to Sarake Ltd. and its subcontractor Nebula Ltd. in order to implement
the Service for the university. Sarake Ltd. may outsource the processing of personal data to a third party only with the consent of Oamk. Personal data will not be disclosed to any third parties other than those listed above.
Data retention period (how long the data will be kept) Personal data will be retained in accordance with the Oamk's archive compilation plan indefinitely. The retention times are based on the Archives Act (831/1994) and other legislation.
International data transfers outside the EU or the EEA Personal data is not transferred outside the European Union or the European Economic Area.
Individual rights
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to object
  • Right to data portability
Basis for processing personal data
  • Legal obligation
  • Public task
  • Legitimate interests