Register and privacy policy

This is Salaojapiste Oy (business ID: 3429252-3) register and privacy policy in accordance with the EU's General Data Protection Regulation (GDPR).

Data Controller

Salaojapiste Oy

Auramontie 5

33880 LEMPÄÄLÄ

Contact person responsible for the register

Oskari Eskola

oskari.eskola@salaojapiste.fi

+35844 093 0012

Name of the register

Customer and marketing register

Legal basis and purpose of processing personal data

The legal basis for processing personal data under the EU General Data Protection Regulation is:

-Person's consent

-An agreement to which the data subject is a party

-Law

- Legitimate interest of the controller (e.g. customer relationship before the contract, employment relationship).

The purpose of processing personal data is to communicate with customers, maintain customer relationships and market. The data is not used for automated decision-making or profiling.

Data content of the register

The information stored in the register includes: the person's name, contact information (phone number, email address, address), website addresses, IP address of the network connection, usernames/profiles in social media services, billing information, other information related to the customer relationship and the services ordered. The IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of legitimate interest, among other things, to ensure data security and to collect statistical data on website visitors in cases where these may be personal data. Consent is requested separately for third-party cookies, if necessary.

Regular sources of information

The data stored in the register is obtained from the customer from messages sent via online forms, email, telephone, social media services, contracts, customer meetings and other situations in which the customer discloses their data. Contact information for companies and other organizations may also be collected from public sources, such as websites, directory services, and other companies.

Regular disclosure and transfer of data outside the EU or EEA

As a rule, the information is not disclosed to other parties. The information may be published to the extent agreed with the customer. The controller may also transfer data outside the EU or EEA. The data will not be transferred to the United States without the explicit consent of the data subjects.

Principles of register protection

Care is taken in the processing of the register, and the data processed in the information systems is appropriately protected. When register data is stored on internet servers, the physical and digital security of their equipment is appropriately ensured. The controller ensures that the stored data and access rights to servers and other information critical to the security of personal data are processed confidentially and only by those employees whose job description includes it.

Right of access and right to demand correction of information

Every person in the register has the right to check their data stored in the register and demand that incorrect information be corrected or incomplete information supplemented. If a person wishes to check their data or demand that it be corrected, the request must be sent in writing to the controller. If necessary, the controller may ask the requestor to prove his or her identity. The controller will respond to the customer within the time prescribed in the EU's General Data Protection Regulation (usually within one month).

Other rights related to the processing of personal data

A person in the register has the right to request that personal data concerning him or her be erased from the register ('right to be forgotten'). Similarly, data subjects have other rights under the EU's General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the requestor to prove his or her identity. The controller will respond to the customer within the time prescribed in the EU's General Data Protection Regulation (usually within one month).