Privacy policy
Privacy policy in accordance with Section 10 of the Personal Data Act (523/99)
Data controller
Turun Uunisepät Oy Rydöntie 32 20360 Turku
Entity responsible for maintaining the register
Turun Uunisepät Oy Rydöntie 32 20360 Turku uunisepat@uunisepat.fi
Name of the register
Uunisepät Customer Register
Purpose of processing personal data
The purpose of processing personal data is to manage and maintain the customer relationship between the company and the customer, communicate with customers, and conduct marketing. The data in the register is used for the company’s own direct marketing unless the customer has opted out of direct marketing.
Description of the group of data subjects
The register may contain personal data concerning the company’s customers.
Description of data relating to data subjects
The register may contain the following information:
Customer information
- First and last name
- Company/customer name and contact information, such as
- Mailing address
- Telephone number
- Mobile phone number
- Email address
Customer number
- Information on offers received by the customer
- Information on orders placed by the customer
Regular sources of information
Contact and customer information contained in the register is obtained from notifications made by the customer to the controller when the customer relationship is established and during its course. Contact and customer information may also be collected through various marketing campaigns. A marketing opt-out is recorded based on a separate notification from the customer.
Regular disclosures of information
Information is reported or disclosed to third parties only due to a statutory reporting obligation, such as at the customer’s own request or at the statutory request of an authority.
Transfer of information outside the EU or the European Economic Area
Information is not transferred or disclosed outside the EU or the European Economic Area.
Principles for protecting the register
The controller’s information system and files are protected using technical safeguards normally used in business operations. Access to the register requires a personal user ID and password, which are granted only to personnel of the controller or a service provider acting on behalf of the company whose position and duties involve such access and the processing of personal data. Employees who process customer register information are bound by a duty of confidentiality.
Right of access of the data subject
The data subject has the right to review information concerning them stored in the register and to receive copies of it. The request for access must be made in writing and addressed to the party responsible for register matters (see the section Entity responsible for maintaining the register).
Correction of information
The party maintaining the register rectifies, erases, or supplements personal data in the register that is incorrect, unnecessary, incomplete, or outdated in relation to the purpose of processing, either on its own initiative or at the request of the data subject. To correct information, the data subject must contact the controller’s party responsible for register matters in writing (see the section Entity responsible for maintaining the register).