Register and Privacy Statement

Register and Privacy Statement

This is Oy Duroy Ab's register and privacy statement in accordance with the Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on 1.12.2020

1. Controller

Oy Duroy Ab, Business ID 3171224-6
Bulevardi 5
FIN-00120 Helsinki, Finland

2. Contact Person for Register Matters

Mika Marjakangas, mika.marjakangas@duroy.fi

3. Name of the Register

1) Company Customer Register 2) Marketing Register 3) Stakeholder Register 4) Web Service User Register 5) Employee Register

4. Legal Basis and Purpose of Personal Data Processing

The legal basis for processing personal data in accordance with the EU General Data Protection Regulation is - the person's consent (documented, voluntary, specific, informed, and unambiguous) - a contract in which the data subject is a party - the controller's legitimate interest (e.g., customer relationship, employment relationship, membership). The purpose of processing personal data is to communicate with customers, maintain customer relationships, marketing, etc. The data is not used for automated decision-making or profiling.

5. Data Content of the Register

Data stored in the register includes: person's name, position, company/organization, contact information (phone number, email address, address), website addresses, IP address of the connection, identifiers/profiles on social media services, information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services.

6. Regular Data Sources

Data stored in the register is obtained from the customer via messages sent through web forms, by email, phone, social media services, contracts, customer meetings, and other situations where the customer provides their information.

7. Regular Disclosures and Transfers of Data Outside the EU or EEA

Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer.

8. Principles of Register Protection

Care is taken when processing the register, and data processed via information systems is appropriately protected. When stored on internet servers, the physical and digital security of the hardware is adequately ensured. The controller ensures that stored data, server access rights, and other information critical to the security of personal data are handled confidentially and only by employees whose job description includes this task.

9. Right of Access and Right to Request Correction

Every person in the register has the right to check their stored data and to request the correction of any incorrect or incomplete data. If a person wants to check their stored data or request a correction, the request must be sent in writing to the controller. The controller may ask the requester to prove their identity if necessary. The controller responds to the customer within the time frame stipulated by the EU Data Protection Regulation.

10. Other Rights Related to the Processing of Personal Data

Persons in the register have the right to request the deletion of their personal data from the register ("right to be forgotten"). Likewise, data subjects have other rights under the EU General Data Protection Regulation, such as restricting the processing of personal data in certain situations. Requests must be sent in writing to the controller. The controller may ask the requester to prove their identity if necessary. The controller responds to the customer within the time frame stipulated by the EU Data Protection Regulation.

Gift card