Register and Privacy Policy
This is the register and privacy policy of Säräpirtti Oy in accordance with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR).
Prepared on 25 May 2018 and updated on 7 May 2024.
Data Controller
Säräpirtti Oy
Rantatie 1
54710 Lemi
Finland
Contact Person Responsible for the Register
Elias Ruosteinen
elias.ruosteinen@sarapirtti.fi
+358 5 414 6470
Name of the Register
Customer Register
Legal Basis and Purpose of Processing Personal Data
The legal basis for processing personal data in accordance with the EU General Data Protection Regulation is based on:
- processing orders and invoicing
- managing customer relationships and marketing
Contents of the Register
The register may contain the following information: name, address, phone number, company name, email address, and password.
Regular Sources of Data
Personal data is obtained from customers through, among other things, messages sent via website forms, the online store, email, telephone, social media services, and contracts.
We use cookies to improve the usability of our website. We use Google Analytics to track visitor traffic. The data collected by Google Analytics is anonymous and cannot be used to identify individual users.
Regular Disclosure of Data and Transfer of Data Outside the EU or EEA
Personal data is not disclosed to third parties. The data is stored on a server that is accessible only to persons responsible for maintaining the register. The data is protected by usernames and passwords.
Principles of Register Protection
Care is taken in processing the register, and data processed using information systems is appropriately protected. When register data is stored on an internet server, the physical and digital security of the hardware is properly ensured. The data controller ensures that stored data, server access rights, and other information critical to personal data security are handled confidentially and only by employees whose job responsibilities require it.
Right of Access and Right to Rectification
Each person registered has the right to inspect their personal data stored in the register and to request the correction of any inaccurate data or completion of incomplete data. Requests for inspection or correction must be submitted in writing to the data controller. If necessary, the data controller may request proof of identity. The data controller will respond within the time limits set by the GDPR (generally within one month).
Other Rights Related to the Processing of Personal Data
Registered individuals have the right to request the deletion of their personal data from the register (“the right to be forgotten”). Registered individuals also have other rights under the EU General Data Protection Regulation, such as the right to restrict processing in certain situations. Requests must be submitted in writing to the data controller. The data controller may request proof of identity if necessary and will respond within the time limits set by the GDPR (generally within one month).