- Forsiden
- Privacy Policy
Privacy Policy
A record of processing activities under Article 30 of Regulation (EU) 2016/679 of the European Parliament and of the Council
1. Controller:
Finnfoam Oy
Satamakatu 5, FI-24100 Salo, Finland
Business ID: 0689386-6
2. Representative of the controller in register-related matters:
Elisa Lindqvist
Finnfoam Oy
Satamakatu 5, FI-24100 Salo, Finland
elisa.lindqvist@finnfoam.fi
3. Name of the register:
Finnfoam Oy's customer, prospect, and marketing register
4. Purposes of the processing of personal data:
The processing of personal data is based on the company’s legitimate interest which is based on a customer relationship or another relevant association. Personal data is used for
- Management, administration, maintenance, and development of the existing and potential customer relationships of Finnfoam Oy
- Targeting of communications and marketing
- Production, provision, and development of services
- Communication and marketing related to services and events.
- Management of training and courses
- Design and development of business operations.
- Market research and collection and reporting of customer feedback and customer satisfaction data.
5. Data Contents of the Register
Within the register, we process the following data provided by the data subject:
- Name information
- Address information
- Telephone number
- Email address
- Organization
- Position within the organization
- Field
In addition, the register may contain other notes pertaining to the data subject and their possible customer relationship and other information required for the administration of the customer relationship, such as information on direct marketing permissions and prohibitions, participation in previous or future events, food allergies (information provided voluntarily by the data subject when registering for a training event), or information pertaining to the data subject's purchases and delivery and invoicing. The register may also contain information collected using cookies pertaining to the data subject’s visits to and use of the controller's website.
6. Regular sources of data
We primarily receive data directly from the data subjects themselves or through the cookies used on the controller's website. In addition, personal data may be collected and updated for the purposes described in this privacy policy from publicly available sources and based on information received from authorities or other third parties within the limits of applicable legislation. Such updating of information will be carried out manually or using automated means.
7. Regular disclosure of data:
Personal data may be disclosed and transferred for the purpose of processing personal data to the service providers of the controller and its subsidiaries and the subsidiaries of the controller. The processors of personal data mentioned above do not have the right to process personal data other than on behalf of the controller.
8. Transfer of data outside EU or EEA
Finnfoam Oy may also outsource the processing of personal data to outside companies who may also be located outside of the European Union and the European Economic Area, such as in the United States. These companies may process personal data in order to provide IT services, for example. In such cases, sufficient data security and proper processing of registers is ensured by the EU-U.S. Privacy Shield framework, or by way of agreement using the standard contractual clauses adopted by the European Commission.
9. Data protection principles
Access to data stored and processed using data processing systems is provided to a limited number of designated personnel. Use of the data requires logging in to the data processing system with a personal user ID and password. The data processing systems are protected with appropriate virus control software and firewalls.
Physical documents containing personal data are protected against unauthorized access and unlawful processing (such as destruction, alteration, and disclosure). Each processor only has access to the personal data they require in the course of their tasks.
10. Storage of data
We store personal data for as long as the customer relationship exists or as long as required by law.
The personal data of data subjects who have permitted marketing is stored in the marketing register until the data subject withdraws the marketing permission. In this case, the basic information of the data subject in question and the information pertaining to the marketing prohibition will however be stored in the register.
Sensitive personal data (food allergies) pertaining to data subjects who participate in training events will be deleted after the participation.
We will regularly review the need to store information taking the applicable legislation into account. Furthermore, we will take reasonable measures used to ensure that no personal data pertaining to the data subjects that is inconsistent, expired or erroneous with regard to the purposes of the processing is stored in the register. We will rectify or delete any such data immediately.
11. Rights of the data subject
The data subject has the right to object to the use of their personal data for electronic direct marketing by using the cancellation or prevention link included in a newsletter or another electronic message, or by contacting the representative of the controller mentioned in section 2 in writing.
The data subject has the right to review the data pertaining to them that is stored within the register and, where necessary, demand the controller to rectify or supplement the data pertaining to them in the register. The data subject is personally responsible for the accuracy of the data they provide. The data subject must notify the controller if changes occur in the data they have provided. The controller may also rectify incorrect information on its own initiative having been informed of incorrect information.
As a data subject, under the data protection regulation you have the right to object to or request the controller to restrict the processing of personal data pertaining to you, and to lodge a complaint regarding the processing of personal data with the supervisory authority, and to request the controller to delete personal data pertaining to you or transmit the data to another system. All requests by data subjects must be sent in writing to the representative of the controller mentioned in section 2.
12. Changes to the privacy policy
If we revise this privacy policy, the revisions will be shown in the policy with the date of revision included. If the revisions are significant, we may also provide information about them in other ways, such as through email or by including a notification of the matter on our website. We recommend that you visit our website regularly and take note of possible changes in the privacy policy.
Revised: 5/25/2018