Register and Privacy Policy
This is the Company's register and privacy policy in accordance with the EU General Data Protection Regulation (GDPR). Created on 4/4/2024. Last modified on 5/6/2024.
1. Data Controller
Teollisuuskopla Oy, Rakentajantie 4, 91100 Ii, Finland
2. Contact person responsible for the register
Juho Onkalo, juho.onkalo@teollisuuskopla.com, mob. +358409687232
3. Name of the register
Employee register, online service user register, customer register
4. Legal basis and purpose of personal data processing
The legal basis for the processing of personal data under the EU General Data Protection Regulation isthe individual's consent is voluntary, specific, and/or informedthe legitimate interest of the data controller (e.g., customer relationship prior to a contract, employment relationship)
The purpose of processing personal data is to maintain contact with customers, manage customer relationships, marketing, etc.
Information is not used for automated decision-making or profiling.
5. Content of the Register
The information to be stored in the register includes: the person's name, position, company/organization, contact details (phone number, email address, address), website addresses, IP address of the internet connection, accounts/profiles on social media services, information about ordered services and their changes, billing information, and other information related to the customer relationship and ordered services.
If there are multiple registered groups (e.g., customer register and marketing register), list them along with their data content in broad terms.
The IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of legitimate interest, for example, to ensure data security and to collect statistical information about website visitors in cases where they can be considered personal data. Consent for third-party cookies is requested separately when necessary.
6. Regular data sources
The information to be stored in the register is obtained from the customer, for example, through messages sent via web forms, email, phone calls, social media services, contracts, customer meetings, and other situations where the customer provides their information.
Information about contacts at companies and other organizations can also be collected from public sources such as websites, directory services, and other companies.
7. Regular disclosures of data and transfer of data outside the EU or EEA
Information is not regularly disclosed to other parties. Information may be published to the extent that it has been agreed upon with the customer.
Data may also be transferred by the data controller outside the EU or EEA. Data will not be transferred to the United States without the explicit consent of the data subjects.
If you provide personal data to third parties, please specify any potential recipients or recipient groups (including data processors/subcontractors), the purposes of processing the personal data related to them, and the transfer basis if the data is transferred outside the EU.
8. Principles of Register Protection
Care is taken in the processing of the register, and the data processed using information systems is adequately protected. When register data is stored on Internet servers, appropriate measures are taken to ensure the physical and digital security of the hardware. The data controller ensures that stored data, as well as access rights to the servers and other information critical to the security of personal data, are handled confidentially and only by those employees whose job it is to do so.
9. Right of access and right to request correction of information
Every individual registered has the right to check the information stored about them in the register and to request the correction of any incorrect information or the completion of any incomplete information. If a person wishes to check the information stored about them or request a correction, the request must be sent in writing to the data controller. The data controller may ask the requester to verify their identity if necessary. The data controller will respond to the customer within the time frame specified in the EU General Data Protection Regulation (generally within one month)..
10. Other rights related to the processing of personal data
The person registered has the right to request the deletion of their personal data from the register ("right to be forgotten"). Likewise, data subjects have other rights under the EU General Data Protection Regulation, such as the restriction of processing personal data in certain situations. Requests must be sent in writing to the data controller. The data controller may request the requester to verify their identity if necessary. The data controller will respond to the customer within the time frame set by the EU data protection regulation (generally within one month).