Book a free SEO check - Let's check your SEO together

Cookies

[kcc_cookie_policy]

Registry and privacy statement

This is the registry and privacy statement of Kasvuasiaintoimisto Kansleri Oy prepared in accordance with the Finnish Personal Data Act (sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Drafted 27.09.2020.

2. Contact person responsible for the register
Tapio Kauranen, tapio@kansleri.fi

3. Name of the register
Customer register of Kasvuasiaintoimisto Kansleri Oy.

4. Legal basis and purpose of processing personal data
The purpose of processing personal data is to communicate with customers, and to carry out sales and marketing. The legal basis for processing is the controller’s legitimate interest in contacting customers and promoting and selling its services.

5. Contents of the register
The register may contain the following information:

the person’s name, job title, company/organization, contact details (phone number, email address, postal address), website addresses, IP address of the web connection, social media account/profile identifiers, information about ordered services and any changes to them, billing information, and other information related to the customer relationship and ordered services.

Data in the register will be deleted when there is no longer a reason to retain it.

6. Regular sources of data
The information stored in the register is collected from the customer, for example from messages sent via website forms, email, phone calls, social media services, contracts, customer meetings and other situations where the customer provides their information.

7. Regular disclosures of data and transfers outside the EU/EEA
Data is not routinely disclosed to third parties. Information may be published where this has been agreed with the customer.

Data may also be transferred by the controller outside the EU or EEA (cloud services) to parties that have committed to comply with the GDPR in their operations.

8. Principles for protecting the register
The register is handled with care and information processed with information systems is protected appropriately. When register data is stored on Internet servers, appropriate measures are taken to ensure the physical and digital security of the hardware. The controller ensures that stored data, server access rights and other information critical to the security of personal data are treated confidentially and only by those employees whose duties require it.

9. Right of access and to request correction
Every person in the register has the right to check the information held about them and to request correction of any inaccurate data or completion of incomplete information. If a person wants to check the data held about them or request a correction, the request must be submitted in writing to the controller. The controller may, if necessary, ask the requester to prove their identity. The controller will respond to the customer within the time limits set by the EU General Data Protection Regulation (generally within one month).

10. Other rights related to the processing of personal data
A person listed in the register has the right to request deletion of their personal data from the register (“the right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to restrict processing in certain situations. Requests must be submitted in writing to the controller. The controller may, where necessary, ask the requester to prove their identity. The controller will respond to the data subject within the timeframes set by the EU GDPR (generally within one month).