PRIVACY POLICY
HSolutions Oy's customer register privacy policy
1 Data controller
The controller of the register is HSolutions Oy (business ID 2786982-2)
The contact person for registry matters is: Henrik Lähdeniemi, Managing Director
HSolutions Oy
Address: Sörnäistenkatu 2 B, 00580 Helsinki
Phone: 050 566 1810
Email: henrik.lahdeniemi@hsolutions.fi
2 Name of the register
The name of the register is HSolutions Oy's customer register.
3 Purpose of processing personal data
Personal data is processed for purposes related to the management, administration and development of the customer relationship, the provision and delivery of services, and the development and billing of services. Personal data is also processed for the purposes of dealing with possible complaints and other claims.
In addition, personal data is processed for customer communications, such as information and news purposes and marketing, which also includes processing of personal data for direct marketing and electronic direct marketing purposes.
The customer has the right to opt-out of direct marketing directed at him/her.
The controller processes the data itself and uses subcontractors acting for and on behalf of the controller to process personal data.
4 Legal grounds for processing
The legal grounds for processing personal data are as follows, in accordance with the EU General Data Protection Regulation (also referred to as "GDPR"):
The legitimate interest of the controller referred to above is based on a relevant and proper relationship between the data subject and the controller, resulting from the fact that the data subject is a customer of the controller, and where the processing is carried out for purposes which the data subject could reasonably have expected at the time of collection of the personal data and in the context of the relevant relationship.
5 Data content of the register (categories of personal data processed)
The register contains the following personal data in principle for all data subjects:
6 Regular sources of information
Personal data is collected from the data subject himself/herself.
Personal data are also collected and updated, within the limits of applicable law, from publicly available sources related to the performance of the customer relationship between the controller and the data subject and through which the controller carries out its obligations in relation to the maintenance of the customer relationship.
7 Retention period of personal data
Data collected in the register will be kept only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal data were collected.
The need to retain personal data will be assessed every ten years and in any event, data relating to a data subject will be erased from the register after twenty years, once the data subject's customer relationship with the controller has ended and the obligations and measures relating to the customer relationship have been completed. For example, accounting records are kept for five years after the end of the accounting year.
The controller regularly assesses the need for data retention in accordance with its internal code of conduct. In addition, the controller shall take all reasonable steps to ensure that personal data which are inaccurate, inaccurate or out of date, having regard to the purposes of the processing, are erased or rectified without undue delay.
8 Recipients (categories of recipients) and regular transfers of personal data
Personal data will not be disclosed to third parties.
9 Transfer of data outside the EU or EEA
The personal data contained in the register will not be transferred outside the EU or EEA.
10 Principles of register protection
Personal data files are kept in locked premises, accessible only to designated persons authorised by their functions.
The database containing personal data is stored on a server in a locked room accessible only to designated persons authorised by their functions. The server is protected by an appropriate firewall and technical protection.
Access to databases and systems is only possible with a personal username and password, which must be issued separately. The controller has limited access rights and authorisations to information systems and other storage platforms so that only persons necessary for their lawful processing have access to and can process the data. In addition, access events to the databases and systems are recorded in the log files of the controller's IT system.
The employees and other persons of the controller are bound by the obligation of confidentiality and to keep confidential the information they receive in connection with the processing of personal data.
11 Rights of the data subject
The data subject has the following rights under the EU General Data Protection Regulation:
Requests concerning the exercise of the rights of the data subject shall be addressed to the contact person of the controller mentioned in point 1.
12 Network analytics
The services below collect anonymised information about visits to the website without any personal data.
-Google Analytics, WordPress, Elementor, Hubspot
13 Targeted marketing
Based on your visit to the website, we may carry out targeted advertising on the following services
- Facebook, Instagram, Google, Hubspot