Privacy policy

This is the Registry and Data Protection Statement under Corpenet Oy (3091364-4) Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Last modified 22.04.2020.

1. Registrar

Corpenet Oy 3091364-4, Nalkalankatu 12, 33200 Tampere, Finland.

2. Name of the register

Company customer register, marketing register, online service user register.

3. Legal basis and purpose of the processing of personal data

The legal basis for processing personal data under the EU General Data Protection Regulation is individual consent (documented, voluntary, individualized, informed, and unambiguous). An agreement to which the data subject is a party. The legitimate interest of the controller (customer relationship, employment relationship). The purpose of the processing of personal data is to communicate with customers, maintain customer relationships and marketing.

The data is not used for automated decision making or profiling.

4. Information content of the register

The information stored in the register includes a person’s name, position, company/organization, contact information (phone number, e-mail address, address), website addresses, network IP address, IDs/profiles in social media services, information about subscribed services and their changes, billing information and more customer relationship.

5. Regular sources of information

The information stored in the register is obtained from the customer, e.g., Messages sent via web forms, e-mail, telephone, social media services, contracts, customer meetings, and other situations in which the customer discloses their information.

6. Regular transfers of data and transfers of data outside the EU or the EEA

The information is not regularly disclosed to other parties. The information may be published to the extent agreed with the customer.

Data may also be transferred by the controller outside the EU or the EEA.

7. Registry Security Principles

We shall handle the register with due care, and we shall adequately protect the information processed by the information systems. When registry information is stored on Internet servers, their hardware’s physical and digital security is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it includes.

8. Right of inspection and right to request correction of information

Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check the data stored about him or request a correction, the person must send the request in writing to the data controller. If necessary, the controller may ask the applicant to prove their identity. The data controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).

9. Other rights related to the processing of personal data

A person in the register has the right to request the removal of their data (“right to be forgotten”). Data subjects also have other rights under the EU’s general data protection regulation, such as restrictions on the processing of personal data in certain situations. The person must send requests in writing to the controller. If necessary, the controller may ask the applicant to prove their identity. The data controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).