Privacy Policy
Privacy Policy of Kontiotuote Oy's Registry Statement +
1. Register
Kontiotuote Oy
Raunuantie 224
93100 Pudasjärvi
info@kontio.fi
2. Person responsible for the register
The contact person is Timo Mustonen, Kontiotuote Oy, and Crasman Oy is responsible for the technical implementation.
3. The name of the registry
Kontio web service
4. Purpose of the register
The personal data collected will be used for market research carried out by Kontiotuote Oy and to send advertising and marketing materials. The data will be collected and used in accordance with Chapter 4, Section 19 of the Personal Data Act.
5. Data contained in the register
The following personal data may be included in the register: first name, last name, e-mail address, phone number. This data is collected on the Kontio web pages using a separate email form.
6. Principles of registry protection
The data in the website user registry is stored in the Registrar’s system as an IT record that is protected by the operating system’s security software. A username and password are required to access the system. The system is also protected by firewalls and other technical means. The data contained in the registry stored in the system is accessible to and only authorized for use by certain pre-determined employees of the Registrar. The information contained in the register is located in locked and guarded premises.
Privacy Policy of Kontiotuote Oy's Marketing Register +
1. Register
Name: Kontiotuote Oy
Address: Ranuantie 224, 93100 Pudasjärvi
Telephone number: +358 20 770 7400
Email address: info@kontio.fi
2. Contact person for matters related to the register
Name: Timo Mustonen
Telephone number: +358 40 617 6669
Email address: timo.mustonen@kontio.fi
3. Name of the register
Kontiotuote Oy’s marketing register
4. Purpose and basis for processing personal data
Personal data is processed for the needs of the company’s advertising, marketing and sales in order to acquire new customers with the consent of the registered.
5. Processed personal data and their storing times
- Customer’s name and contact information
- For a business customer the name and contact information for a contact person
Customer data is stored for 5 years. If an offer is made to the customer, customer data will be stored for 10 years.
6. Regular sources of data
The persons to be registered themselves (data collected e.g. at fairs and from brochure orders).
7. Regular transfer of data to third parties
No regular transfer of data to third parties.
8. Transfer of data outside of the EU or EEA
The data may be transferred outside the EU/EEA area for the purpose of maintaining the ERP system and the registrar has in force proper provisions regarding the transfer of personal data required by the data protection regulation, the purpose of which provisions is to ensure the implementation of privacy policy.
9. Principles according to which the register has been secured
- The manual material is stored in locked rooms and in separately locked storing cabinets and drawers, to which only those persons have access, whose work tasks require processing the material. The rooms have passage control. The data is processed as confidential and statutory obligations of confidentiality are upheld.
- The electronic material is stored centrally in servers protected by a firewall. Access to the data and personal information is protected with a user name and password, and access can be limited according to processing need. The data is processed as confidential and statutory obligations of confidentiality are upheld.
- At least the same level of security principles is required from the personal data processors, and additionally, the implementation of instructions and security requirements given separately with a processing contract.
10. Right of inspection
Everyone has a right to receive information about what data is stored about him in a register. In order to give the data, it is required that a request is presented in writing, and if necessary, sufficient information is presented to ensure the identity of the person making the request. The request must be presented to the contact person of the registrar mentioned in point 2 above. The inspection request is free once per calendar year and otherwise a reasonable compensation can be charged for the request (50 €+vat).
11. Right to demand correction of data
The registered has a right to demand that incorrect data about him is corrected. The registrar can also on his own initiative correct data which he discovers is incorrect. The correction request must be made in writing, and if necessary, sufficient information is presented to ensure the identity of the person making the demand. The correction request must be presented to the contact person of the registrar mentioned in point 2 above.
12. Right to demand removal of data
The registered has a right to demand that data about him is removed. The request must be made in writing, and if necessary, sufficient information is presented to ensure the identity of the person making the demand. The removal request must be presented to the contact person of the registrar mentioned in point 2 above.
Privacy Policy of Kontiotuote Oy's Customer Register +
1. Register
Name: Kontiotuote Oy
Address: Ranuantie 224, 93100 Pudasjärvi
Telephone number: +358 20 770 7400
Email address: info@kontio.fi
2. Contact person for matters related to the register
Name: Timo Mustonen
Telephone number: +358 40 617 6669
Email address: timo.mustonen@kontio.fi
3. Name of the register
Kontiotuote Oy’s customer register
4. Purpose and basis for processing personal data
Personal data is processed according to law for fulfilling customer contracts, commissions and orders and for customer communication needs.
The basis of the processing is the customer relationship existing at any time based on contracts, orders or commissions.
5. Processed personal data and their storing times
- Customer’s name and contact information (business ID or personal identification number)
- For a business customer the name and contact information for a contact person
- Instructions regarding invoicing
The customer data is stored on a permanent basis. The contact person can be changed or removed.
6. Regular sources of data
Public registers, the persons to be registered themselves.
7. Regular transfer of data to third parties
No regular transfer of data to third parties.
8. Transfer of data outside of the EU or EEA
The data is transferred outside the EU/EEA area for implementing financial management and the registrar has in force proper provisions regarding the transfer of personal data required by the data protection regulation, the purpose of which provisions is to ensure the implementation of privacy policy.
9. Principles according to which the register has been secured
- The manual material is stored in locked rooms and in separately locked storing cabinets and drawers, to which only those persons have access, whose work tasks require processing the material. The rooms have passage control. The data is processed as confidential and statutory obligations of confidentiality are upheld.
- The electronic material is stored centrally in servers protected by a firewall. Access to the data and personal information is protected with a user name and password, and access can be limited according to processing need. The data is processed as confidential and statutory obligations of confidentiality are upheld.
- At least the same level of security principles is required from the personal data processors, and additionally, the implementation of instructions and security requirements given separately with a processing contract.
10. Right of inspection
Everyone has a right to receive information about what data is stored about him in a register. In order to give the data, it is required that a request is presented in writing, and if necessary, sufficient information is presented to ensure the identity of the person making the request. The request must be presented to the contact person of the registrar mentioned in point 2 above. The inspection request is free once per calendar year and otherwise a reasonable compensation can be charged for the request (50 €+vat).
11. Right to demand correction of data
The registered has a right to demand that incorrect data about him is corrected. The registrar can also on his own initiative correct data which he discovers is incorrect. The correction request must be made in writing, and if necessary, sufficient information is presented to ensure the identity of the person making the demand. The correction request must be presented to the contact person of the registrar mentioned in point 2 above.
12. Right to demand removal of data
The registered has a right to demand that data about him is removed. The removal can be limited by statutory or technical reasons to retain the data. The request must be made in writing, and if necessary, sufficient information is presented to ensure the identity of the person making the demand. The request must be presented to the contact person of the registrar mentioned in point 2 above.