Register and Privacy Policy
This is the Polarfox Oy's register and privacy policy in accordance with the EU General Data Protection Regulation (GDPR). Created 1.2.2023 Last modified 27.2.2023.
1. The controller
Polarfox Oy
Paddock road 21
91100 Ii
2. Contact person responsible for the register
Minna Miettunen, minna.miettunen@polarfox.fi, +358405536248
3. Name of the register
Polarfox customer register
4. Legal basis and purpose of the processing of personal data
The legal basis for processing personal data under the EU General Data Protection Regulation is.
- the person's consent (documented, voluntary, individualised, informed and unambiguous)
- a contract to which the data subject is a party
- law (which)
- the exercise of a public function (on what basis), or
- legitimate interest of the controller (e.g. pre-contractual customer relationship, employment relationship, membership).
The purpose of processing personal data is to contact customers, maintain customer relations, marketing, etc.
The data will not be used for automated decision-making or profiling.
5. Data content of the register
The data stored in the register includes: name, position, company/organisation, contact information (phone number, e-mail address, address), website addresses, IP address of the network connection, billing information, other data related to the customer relationship and the services ordered.
The IP addresses of visitors to the website and the cookies necessary for the functioning of the service are processed for legitimate interests, such as ensuring data security and collecting statistics on visitors to the website in cases where they can be considered as personal data. Third party cookies are subject to separate consent where necessary.
6. Regular sources of information
The information stored in the register is obtained from the customer through, for example, messages sent via web forms, email, telephone, social media services, contracts, customer meetings and other situations where the customer discloses their information.
Information on contact persons of businesses and other organisations may also be collected from public sources such as websites, directory services and other businesses.
7. Regular disclosures and transfers of data outside the EU or EEA
Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer.
Data may also be transferred outside the EU or EEA by the controller. Data will not be transferred to the United States without the express consent of the data subjects.
If you disclose personal data to different parties, please indicate here the possible recipients or categories of recipients (including processors/sub-processors), the purposes of the processing of personal data in relation to them and the transfer criteria if the data are transferred outside the EU.
8. Principles of register protection
The register is processed with due care and the data processed by the information systems are adequately protected. Where the data are stored on Internet servers, the physical and digital security of their hardware shall be adequately ensured. The controller shall ensure that stored data, as well as access rights to servers and other information critical to the security of personal data, are treated confidentially and only by employees whose job description includes this.
9. Right of inspection and right to request correction of information
Every person in the register has the right to check the information stored in the register and to request that any inaccurate or incomplete information be corrected or completed. If a person wishes to check or request a correction of the data stored about him or her, the request must be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will reply to the customer within the time limit laid down in the EU General Data Protection Regulation (as a general rule, within one month).
10. Other rights relating to the processing of personal data
A person in the register has the right to request the erasure of personal data concerning him or her from the register ("right to be forgotten"). Data subjects also have other rights to Rights under the EU General Data Protection Regulation such as limiting the processing of personal data in certain situations. Requests should be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits set by the EU General Data Protection Regulation (as a general rule, within one month).
Cookies
To provide you with the best experience, we use technologies, such as cookies, to store and/or use device information. Accepting these technologies allows us to process information such as browsing behaviour or unique identifiers on this site. Giving or withdrawing consent may adversely affect certain features and functionality.