Registry and Privacy Statement
Registry and Privacy Statement
This is the register and data protection statement in accordance with Nordesans Oy's Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on 30.09.2020 Last modified on 30.09.2020
1. The controller
Freedom 20 A 13,
business ID: 3167750-8
2. Name of the register
Nordesans Oy's customer register
3. Legal basis and purpose of the processing of personal data
We collect personal information for customer relationship management purposes. The legal basis for the processing of personal data is the agreement between us and the legal obligations arising from it. The provision of personal data is a precondition for the conclusion of a contract. In other words, you cannot order goods from our online store if you do not provide your personal information.
We also collect personal information for marketing purposes. The legal basis for the processing of personal data is consent.
4. Information content of the register
The information stored in the register includes: person's name, company / organization, contact information (phone number, email address, address), website addresses, network IP address, location information (for service localization: currencies, delivery methods), Google or Facebook login email, and certificate , Product reviews, marketing message authorizations, and information related to customer relationships and subscribed services.
We will retain the information for the time necessary to enable us to fulfill the uses set forth in this leaflet. We will delete the personal information of a customer account that we have determined to be inactive no later than five years after the end of the activity. Some information may be retained longer if required to do so by law.
5. Regular sources of information
The information stored in the register is obtained from the customer e.g. Messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information.
6. Regular transfers of data and transfers of data outside the EU or the EEA
The information is not regularly disclosed to other parties. The information may be published to the extent agreed with the customer.
7. Registry Security Principles
The register shall be handled with due care and the data processed by the information systems shall be adequately protected. When registry data is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it belongs to.
8. Right of inspection and right to request correction of information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check or correct the data stored about him or her, the request must be sent by e-mail to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
9. Other rights related to the processing of personal data
You have the following rights:
The right to inspect personal data about you, the right to rectify data, the right to restrict processing (for example, you can refuse marketing), the right to object to processing, the right to withdraw consent (for example, you can withdraw your consent to marketing), the right to complain to the supervisory authority
Please note that you only have the "right to be forgotten" if we have no legal obligation to continue processing your personal information.
Likewise, registrants have others Rights under the EU General Data Protection Regulation such as restricting the processing of personal data in certain situations. Requests should be emailed to the registrar. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
A cookie is a small text file that is stored on a user's device by an Internet browser. Cookies are set on the user's terminal only with the site the user invites. Only the server that sent the cookie can later read and use the cookie. Cookies or other technologies do not damage the user's terminal or files, and cannot be used to access programs or spread malware. The user cannot be identified by cookies alone.
The uses of cookies are to enhance analytics, marketing and communication. Cookies are divided into subgroups: functional cookies, product development and business reporting, advertising reporting and advertising targeting.
There are some third-party tools or plug-ins that are required for the service to function. Examples of such tools include embedding of social media or video services on sites, or social media sharing and liking capabilities. In addition, such third-party plug-ins may collect information about users of online services, for example, to recommend content or track traffic.
If you wish, you can prevent your browser from using cookies, delete stored cookies or request notification of new cookies from your browser. Instructions on how to delete cookies can be found at: https://www.aboutcookies.org/ Blocking or deleting cookies may interfere with some of the functions of our website.
You can read more about cookies and Finnish cookie requirements on FICORA's website https://www.kyberturvallisuuskeskus.fi/fi/toimintamme/saantely-ja-valvonta/luottamuksellinen-viestinta
We reserve the right to update our cookie policies, for example, due to service developments or mandatory legislation.