Privacy statement
REGISTRY AND DATA PROTECTION POLICY
This is Company RA Tarvikke's register and privacy policy in accordance with (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on 10.04.2020 Last modified on 19 .04.2020 .
1. Data Controller
RA Accessories Rajakatu 17 24260 Salo
info@ra-tarvike.com
2. Contact person responsible for the register
A Romppainen info@ra-tarvike.com 0417125332
3. Name of the register
The company's customer register, marketing register, stakeholder register, online service user register, member register, employee register, etc.
4. Legal basis and purpose of processing personal data
The legal basis for processing personal data under the EU General Data Protection Regulation is
- the person's consent (documented, voluntary, individualized, informed and unambiguous)
- a contract to which the data subject is a party
- law (which)
- performing a public task (on what basis), or
- the legitimate interest of the controller (e.g. customer relationship, employment relationship, membership).
The purpose of processing personal data is contact with customers, customer relationship maintenance, marketing, etc.
The data is not used for automated decision-making or profiling.
5. Data content of the register
The information stored in the register includes: person's name, position, company/organization, contact information (phone number, email address, address), website addresses, IP address of the network connection, IDs/profiles in social media services, information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services.
Please also state the retention period of the data here, if possible. Also state if, for example, the data will be anonymized after a certain period of time.
6. Regular sources of information
The information stored in the register is obtained from the customer, for example, through messages sent via web forms, email, telephone, social media services, contracts, customer meetings and other situations in which the customer provides their information.
7. Regular data transfers and data transfers outside the EU or EEA
The information is not routinely disclosed to other parties. Information may be published to the extent agreed upon with the customer.
Data may also be transferred by the controller outside the EU or EEA.
If you disclose personal data to different parties, please indicate the potential recipients or recipient groups here.
8. Principles of register protection
The register is handled with care and the data processed by the information systems are protected appropriately. When the register data is stored on Internet servers, the physical and digital security of their equipment is appropriately ensured. The controller ensures that the stored data, as well as the access rights to the servers and other information critical to the security of personal data, are handled confidentially and only by employees whose job description requires it.
9. Right to inspect and right to request correction of information
Every person in the register has the right to check their data stored in the register and to demand correction of any incorrect data or completion of incomplete data. If a person wishes to check the data stored about them or to demand correction of them, the request must be send in writing to the controller. The controller may, if necessary, ask the requester to prove their identity. The controller will respond to the customer within the time period specified in the EU Data Protection Regulation (generally within one month).
10. Other rights related to the processing of personal data
The person in the register has the right to request that personal data concerning him or her be deleted from the register ("right to be forgotten"). Data subjects also have other rights Rights under the EU General Data Protection Regulation, such as the restriction of processing of personal data in certain situations. Requests must send in writing to the controller. The controller may, if necessary, ask the requester to prove their identity. The controller will respond to the customer within the time period specified in the EU Data Protection Regulation (generally within one month).