This is the register and data protection statement of Kosken Autokeskus in accordance with the Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR), prepared on September 7, 2020.
1. Registry holder
Kosken Autokeskus
Koskentie 248
31500 Koski Tl
Finland
2. Contact Person responsible for the Registry
Minna Ojala
laskutus@koskenautokeskus.fi
3. Name of the Registry
Company customer register, marketing register, stakeholder register, online service user register.
4. Legal basis and purpose of the processing of Personal Data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is:
– consent of the person (documented, voluntary, identified, informed and unambiguous)
– a contract to which the data subject is a party
– the privilege of the controller (e.g. customer relationship).
The purpose of processing personal data is to communicate with customers, maintain a customer relationship, marketing, business development.
5. Content of the Registry
The information stored in the register includes: person’s name, position, company / organization, contact information (phone number, e-mail address, address), website addresses, network IP address, IDs / profiles in social media services, information about subscribed services and their changes, billing information, other information related to the customer relationship and the services ordered.
All data will be retained indefinitely or until requested to be deleted by the customer.
6. Sources of Information
The information stored in the register is obtained from the customer e.g. Messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information.
7. Transfer of Data outside the EU or the EEA
The information is not disclosed to third parties.
The information will not be transferred by the controller outside the EU or the EEA.
8. Registry Security Principles
The register shall be handled with care and the data processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it includes.
9. Right to inspect and request correction of Information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check the data stored about him or her or request a correction, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
10. Other rights related to the processing of Personal Data
A person in the register has the right to request the removal of his or her personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU’s general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).