Register and Privacy Statement

This is a register and privacy statement in accordance with the EU General Data Protection Regulation (GDPR). Created on 16.10.2024. Last modified on 16.10.2024.

1.Data controller

Juho Wickström
Visakoivuntie 1, Hartola
Phone number: 045 135 0826

2. Contact person responsible for the register

Juho Wickström
Visakoivuntie 1, Hartola
Phone number: 045 135 0826
Sähköposti: vuokraus@wisaranta.fi

3. Register name

Asiakasrekisteri

4. Legal Basis and Purpose of Processing Personal Data

The legal basis for processing personal data in accordance with the EU General Data Protection Regulation (GDPR) is:

  • The individual’s consent (documented, voluntary, specific, informed, and unambiguous)
  • A contract in which the data subject is a party
  • Law (e.g., accounting law)
  • The legitimate interest of the data controller (e.g., customer relationship prior to a contract)

The purpose of processing personal data is to communicate with customers, maintain customer relationships, and conduct marketing. The data is not used for automated decision-making or profiling.

5. Contents of the register

The data stored in the register includes:

  • Person’s name
  • Address details
  • Email address
  • Phone number
  • Information about subscribed services and their changes
  • Billing information

6. Regular sources of information

The data stored in the register is obtained from the customer through messages sent via web forms, email, phone, social media services, contracts, customer meetings, and other situations where the customer provides their information. Information about contact persons of companies and other organizations can also be collected from public sources such as websites, directory services, and other companies.

7. Regular disclosures of data and transfer of data outside the EU or EEA

Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer. Data may also be transferred by the controller outside the EU or EEA. Data is not transferred to the United States without the explicit consent of the data subjects.

8. Principles of register protection

Care is taken in handling the register, and data processed with information systems is properly protected. When register data is stored on Internet servers, appropriate measures are taken to ensure the physical and digital security of the hardware. The controller ensures that stored data, server access rights, and other critical personal data are handled confidentially and only by employees whose job descriptions include such tasks.

9. Right of access and right to request correction of data

Every person in the register has the right to check their stored data and request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check their stored data or request a correction, the request must be sent in writing to the controller. The controller may ask the requester to prove their identity if necessary. The controller will respond to the customer within the time frame specified in the EU Data Protection Regulation (generally within one month).

10. Other rights related to the processing of personal data

A person in the register has the right to request the deletion of their personal data from the register (“right to be forgotten”). Registered individuals also have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be sent in writing to the controller. The controller may ask the requester to prove their identity if necessary. The controller will respond to the customer within the time frame specified in the EU Data Protection Regulation (generally within one month).