[kcc_cookie_policy]
2. Contact person responsible for the register
Tapio Kauranen, tapio@kansleri.fi
3. Name of the register
Customer register of Kasvuasiaintoimisto Kansleri Oy.
4. Legal basis and purpose of processing personal data
The purpose of processing personal data is to communicate with customers, sales and marketing. The legal basis for processing personal data is the controller’s legitimate interest in communicating with customers, selling and marketing its services.
5. Content of the register
Information stored in the register may include:
the person’s name, position, company/organisation, contact details (phone number, email address, address), website addresses, IP address of the internet connection, usernames/profiles in social media services, information about ordered services and their changes, billing information, and other information related to the customer relationship and ordered services.
The register data is deleted when there is no longer any basis for retaining it.
6. Regular sources of information
The information stored in the register is obtained from the customer, for example, from messages sent via web forms, by email, by telephone, through social media services, from contracts, customer meetings and other situations in which the customer discloses their information.
7. Regular disclosures of data and transfer of data outside the EU or EEA
Data is not regularly disclosed to other parties. Data may be published to the extent that it has been agreed with the customer.
Data may also be transferred by the controller outside the EU or EEA (cloud services) to parties that have committed to complying with the GDPR in their operations.
8. Principles of Register Protection
The processing of the register is carried out with due care, and the data processed with the help of information systems is protected appropriately. When register data is stored on Internet servers, appropriate care is taken of the physical and digital data security of the hardware. The data controller ensures that the stored data, as well as server access rights and other information critical to the security of personal data, are handled confidentially and only by those employees whose job description includes it.
9. Right of Inspection and Right to Request Correction of Data
Every person registered in the register has the right to check the data stored about them in the register and to request the correction of any incorrect data or the completion of incomplete data. If a person wishes to check the data stored about them or request corrections to it, the request must be sent in writing to the data controller. The data controller may request the requester to prove their identity if necessary. The data controller responds to the customer within the time specified in the EU Data Protection Regulation (generally within one month).
10. Other Rights Related to the Processing of Personal Data
A person registered in the register has the right to request the deletion of personal data concerning them from the register (“right to be forgotten”). Likewise, data subjects have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be sent in writing to the data controller. The data controller may request the requester to prove their identity if necessary. The data controller responds to the customer within the time specified in the EU Data Protection Regulation (generally within one month).