Register and Privacy Policy

Register and Privacy Policy


This is the Company's Privacy and Data Protection Statement in accordance with the EU General Data Protection Regulation (GDPR). Last modified 29.11.2023

Piones
Teuroontie 1 D 8, 40520 Jyväskylä, Finland


2. Contact person responsible for the register
Päivi Boualem

Teuroontie 1 D 8, 40520 Jyväskylä

info@piones.fi


3. Name of the register
The company's customer and marketing register.



4. Legal basis and purpose of processing personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is
- the consent of the individual (documented, voluntary, individual, informed and unambiguous)
- a contract to which the data subject is a party
- law (which)
- the performance of a public task (based on what), or
- a legitimate interest of the controller (e.g. customer relationship before a contract, employment relationship, membership).

The purpose of processing personal data is to contact customers, maintain a customer relationship, marketing, etc.

The data will not be used for automated decision-making or profiling.


5.
The data stored in the register includes: name, position, company/organisation, contact information (phone number, e-mail address, address), website addresses, IP address of the network connection, social media accounts/profiles, information on ordered services and changes thereto, billing information, other information related to the customer relationship and ordered services.

If there are several categories of data subjects (e.g. customer register and marketing register), list them and their data content in outline.

Please also indicate here the data retention period, if applicable. Please also indicate if, for example, the data will be anonymised after a certain period of time.

The IP addresses of visitors to the website and cookies necessary for the functioning of the service are processed for legitimate interests, including for security purposes and for the collection of statistical data on visitors to the website where they can be considered as personal data. Third party cookies are subject to separate consent where necessary.

6. Regular data sources
The data stored in the register is obtained from the customer through, for example, messages sent via web forms, e-mail, telephone, social media services, contracts, customer meetings and other situations where the customer provides his/her data.

Information from contact persons of companies and other organisations may also be collected from public sources such as websites, directory services and other companies.


7. Regular disclosures and transfers of data outside the EU or EEA
There is no regular disclosure of data to other parties. Data may be published to the extent agreed with the customer.

Data may also be transferred outside the EU or EEA by the controller. Data will not be transferred to the United States without the express consent of the data subjects.

If you transfer personal data to different parties, please indicate here the possible recipients or categories of recipients (including processors/sub-processors), the purposes of the processing of personal data in relation to them and the transfer criteria if the data are transferred outside the EU.



8. Principles for the protection of the register
The register will be processed with due care and the data processed by the IT systems will be adequately protected. Where the data are stored on Internet servers, the physical and digital security of their hardware is adequately ensured. The controller shall ensure that stored data, as well as access rights to servers and other information critical to the security of personal data, are treated confidentially and only by employees whose job description includes this.



9. Right of access and rectification
Any person in the register has the right to check the data recorded in the register and to request the correction of any inaccurate data or the completion of incomplete data. If a person wishes to check or request the rectification of data stored about him or her, the request must be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will reply to the customer within the time limit laid down in the EU General Data Protection Regulation (as a general rule, within one month).


10. Other rights relating to the processing of personal data
A data subject in the register has the right to request the erasure of personal data concerning him or her from the register ("right to be forgotten"). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of the processing of personal data in certain circumstances. Requests should be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller is responsible for providing the customer with the information required by the EU Data Protection Regulation.