Register and privacy policy
PRIVACY STATEMENT OF THE CUSTOMER REGISTER OF TUOVILA GUMMI OY
This is Tuovilan Gummi Oy’s registration and data protection statement in accordance with the EU General Data Protection Regulation (GDPR). Prepared on 29/04/2022. Latest change 29.04.2022.
- Registrar
Tuovilan Gummi Oy (0763211-5), Inarijärventie 281, 99800 Ivalo.
laskutus@tuovilangummi.com, 040 664 6747
- Contact person
Maria Kauppila, mariakauppila@tuovilangummi.com, 040 664 6747
- Registry name
Customer and marketing register of Tuovilan Gummi Oy.
- Legal basis and purpose of personal data processing
According to the EU’s General Data Protection Regulation, the legal basis for processing personal data is the person’s consent (documented, voluntary, individualized, informed and unambiguous).
Personal data is processed for purposes related to managing, managing and developing customer relationships, providing and delivering services, and developing and invoicing services. Personal data is also processed for the purposes required to settle possible complaints and other claims.
In addition, personal data is processed in communications aimed at customers, such as for information and news purposes, as well as in marketing, as part of which personal data is also processed for purposes related to direct marketing and electronic direct marketing. The customer has the right to refuse direct marketing aimed at him.
The information is not used for automated decision-making or profiling.
- Data content of the register
The register basically contains the following personal information about all registered persons: the person’s basic information and contact information: first name, last name, telephone number, e-mail address, information related to the person’s company or other organization and the person’s position or job title. in a company or organization, a person’s direct marketing permits and prohibitions.
IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to take care of information security and for the collection of statistical data of website visitors in those cases when they can be considered as personal data. If necessary, consent is requested separately for third-party cookies.
The information collected in the register is kept only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal information was collected.
The need to retain personal data is evaluated every five years, and in any case, the data concerning the registered person is deleted from the register five years after the customer relationship of the registered person with the controller has ended, and the obligations and measures related to the customer relationship have been completed. For example, accounting documents are kept for five years after the end of the accounting period.
The controller evaluates the necessity of storing data regularly in accordance with its internal code of conduct. In addition, the controller takes all possible reasonable measures to ensure that personal data that is inaccurate, incorrect or outdated in relation to the purposes of the processing is deleted or corrected without delay.
- Regular sources of information
The information to be saved in the register is obtained from the customer, e.g. From messages sent via web forms, by e-mail, by phone, via social media services, contracts, customer meetings and other situations where the customer gives out their information.
Information about contact persons of companies and other organizations can also be collected from public sources such as websites, directory services and other companies.
- Regular transfers of information
Information is not disclosed to external parties. The personal data included in the register will not be transferred outside the EU or EEA either.
- Principles of registry protection
Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.
- The right of inspection and the right to demand correction of information
Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be made by email to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).
- Other rights related to the processing of personal data
A person in the register has the right to request the removal of personal data about him from the register (”right to be forgotten”). Those registered also have other rights according to the EU’s General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests should be sent by e-mail to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).