Register & Privacy Policy

PRIVACY STATEMENT FOR KOME OY’S CUSTOMER REGISTER (Contact Form / Job Application Form Details)

1 Data Controller The controller of the register is HAAPAJÄRVEN KOME OY (Business ID 0568745-4)

The contact person for register matters is: Seppo Saarnio
KOME OY Address: Komenkatu 1, 85800 HAAPAJÄRVI, FINLAND Phone: +358 400 947 777 Email: info (at) kome.fi

 

2 Name of the Register The name of the register is the Customer Register of HAAPAJÄRVEN KOME OY.

 

3 Purpose of Processing Personal Data Personal data is processed for purposes related to managing, administering, and developing customer relationships, offering and delivering services, as well as service development and invoicing. Personal data is also processed for purposes required to handle potential complaints and other claims.

In addition, personal data is processed in customer communication, such as information and news distribution, and marketing, as part of which personal data is also processed for direct marketing and electronic direct marketing purposes.

The customer has the right to prohibit direct marketing targeted at them.

The controller processes data itself and utilizes subcontractors acting on behalf and for the account of the controller in processing personal data.

 

4 Legal Bases for Processing The legal bases for processing personal data are the following grounds pursuant to the EU General Data Protection Regulation (hereinafter also “GDPR”): – the data subject has given consent to the processing of their personal data for one or more specific purposes (GDPR Art. 6(1)(a)); – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (GDPR Art. 6(1)(b)); – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party (GDPR Art. 6(1)(f)).

The aforementioned legitimate interest of the controller is based on a relevant and appropriate relationship between the data subject and the controller resulting from the data subject being a customer of the controller, and when processing occurs for purposes the data subject could reasonably expect at the time of personal data collection and in the context of an appropriate relationship.

 

5 Data Content of the Register (Categories of Personal Data Processed) The register contains, as a rule, the following personal data for all registered individuals: basic personal and contact information: [first name, last name, address, phone number, email address, education, work history]; information related to the individual’s company or other organization and the individual’s position or job title in said company or organization; the individual’s direct marketing consents and prohibitions.

 

6 Regular Sources of Data Personal data is collected from the individual submitting the forms themselves.

Personal data is also collected and updated within the limits of applicable law from publicly available sources relevant to the execution of the customer relationship between the controller and the data subject, through which the controller fulfills its obligations related to maintaining customer relationships.

 

7 Retention Period of Personal Data Data collected in the register is retained only for as long as and to the extent necessary in relation to the original or compatible purposes for which the personal data was collected.

The need for retaining personal data is evaluated [every three years]; and in any case, data regarding a data subject is erased from the register [3 years] after the customer relationship between the data subject and the controller has ended, and all obligations and actions related to the customer relationship have been completed. For example, accounting records are retained for six years from the end of the financial year.

The controller evaluates the necessity of retaining data regularly in accordance with its internal codes of practice. Furthermore, the controller takes all reasonable steps to ensure that personal data that is inaccurate, incorrect, or outdated relative to the processing purposes is erased or rectified without delay.

 

8 Recipients of Personal Data (Recipient Categories) and Regular Disclosures of Data Personal data is not disclosed to third parties.

 

9 Transfer of Data Outside the EU or EEA Personal data contained in the register is not transferred outside the EU or EEA.

 

10 Principles of Register Protection Materials containing personal data are stored in locked premises accessible only by designated persons authorized by virtue of their duties.

The database containing personal data is hosted on a server stored in a locked facility accessible only by designated persons authorized by virtue of their duties. The server is protected with an appropriate firewall and technical protection measures.

Databases and systems are accessible only with individually granted user credentials and passwords. The controller has limited access rights and authorizations to IT systems and other storage platforms so that data can only be viewed and processed by personnel necessary for its lawful processing. In addition, database and system operations are logged in the controller’s IT system log files.

Employees and other personnel of the controller are bound by confidentiality obligations to keep secret all information obtained in connection with personal data processing.

 

11 Rights of the Data Subject

The data subject has the following rights under the EU General Data Protection Regulation:

  • the right to obtain confirmation from the controller as to whether or not personal data concerning them is being processed, and where that is the case, access to the personal data and the following information: (i) the purposes of the processing; (ii) the categories of personal data concerned; (iii) the recipients or categories of recipients to whom the personal data has been or will be disclosed; (iv) where possible, the envisaged period for which the personal data will be stored, or if not possible, the criteria used to determine that period; (v) the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; (vi) the right to lodge a complaint with a supervisory authority; (vii) where the personal data is not collected from the data subject, any available information as to their source (GDPR Art. 15). These basic details (i)–(vii) are provided to the data subject via a form;
  • the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal (GDPR Art. 7); the right to obtain from the controller without undue delay the rectification of inaccurate or incorrect personal data concerning the data subject, as well as the right to have incomplete personal data completed, including by providing a supplementary statement taking into account the purposes of processing (GDPR Art. 16);
  • the right to obtain from the controller the erasure of personal data concerning the data subject without undue delay, provided that (i) the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed; (ii) the data subject withdraws consent on which the processing is based, and there is no other legal ground for the processing; (iii) the data subject objects to the processing on grounds relating to their particular situation and there are no overriding legitimate grounds for the processing, or the data subject objects to processing for direct marketing purposes; (iv) the personal data has been unlawfully processed; or (v) the personal data has to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject (GDPR Art. 17);
  • the right to obtain from the controller restriction of processing where (i) the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data; (ii) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of its use instead; (iii) the controller no longer needs the personal data for the purposes of the processing, but it is required by the data subject for the establishment, exercise, or defense of legal claims; or (iv) the data subject has objected to processing on grounds relating to their particular situation pending the verification whether the legitimate grounds of the controller override those of the data subject (GDPR Art. 18);
  • the right to receive personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format, and the right to transmit that data to another controller without hindrance from the controller to which the personal data was provided, where processing is based on consent within the meaning of the regulation and processing is carried out by automated means (GDPR Art. 20); the right to lodge a complaint with a supervisory authority if the data subject considers that the processing of personal data relating to them infringes the EU General Data Protection Regulation (GDPR Art. 77). Requests regarding the exercise of data subject rights should be directed to the controller’s contact person mentioned in section 1.
X