XENONIT CUSTOMER REGISTER PRIVACY STATEMENT
1 Registrar
The registrar of the register is XENONIT Oy (business ID 3245833-1)
The contact person for registry matters is Juha Kilpinen
XENONIT Oy
Address: Köynnöskuja 8, 01360 Vantaa, Finland
Phone: 040 2453067
Email: xenonit@xenonit.fi
2 Name of the registry
The name of the register is the XENONIT customer register.
3 Purpose of the processing of personal data
Personal data is processed for purposes related to the management, administration and development of the customer relationship, the provision and delivery of services, and the development and invoicing of services. Personal data is also processed for the purposes required to clarify possible complaints and other claims.
In addition, personal data are processed in communications to customers, such as for information and news purposes and in marketing, as part of which personal data are also processed for purposes related to direct marketing and electronic direct marketing.
The customer has the right to prohibit direct marketing directed at him.
The data controller processes the data itself and utilizes subcontractors acting on behalf and for the account of the data controller in the processing of personal data.
4 Legal bases of the proceedings
The legal bases for the processing of personal data are the following in accordance with the General EU Data Protection Regulation (hereinafter also the “GDPR”):
The data subject's legitimate interest referred to above is based on a relevant and appropriate relationship between the data subject and the data controller as a result of the data subject's processing and processing for purposes which the data subject could reasonably have expected at the time and in the appropriate relationship.
5 Data content of the register (categories of personal data to be processed)
The register contains, in principle, the following personal data on all registered persons:
6 Regular sources of information
Personal information is collected from the registered person himself.
Personal data shall also be collected and updated, within the limits of the applicable law, from publicly available sources related to the implementation of the customer relationship between the controller and the data subject and through which the controller fulfills its customer relationship responsibilities.
7 Retention period of personal data
The data collected in the register shall be kept only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal data were collected.
The need to retain personal data shall be assessed every five years and in any case the data of the data subject shall be deleted from the register five years after the end of that data subject's customer relationship with the controller and the end of the customer relationship obligations and measures. For example, accounting documents are kept for six years from the end of the financial year.
The controller shall regularly assess the need for data retention in accordance with its internal code of conduct. In addition, the controller shall take all reasonable steps to ensure that personal data which are inaccurate, incorrect or out of date for the purposes of processing are deleted or rectified without delay.
8 Recipients (groups of recipients) of personal data and regular disclosures of data
Personal data will not be disclosed to third parties.
9 Data transfer outside the EU or the EEA
Personal data contained in the register will not be transferred outside the EU or the EEA.
10 Registry security principles
Materials containing personal data shall be kept in locked premises to which only designated and authorized persons have access.
The database containing personal data is on a server, which is stored in a locked state, which can only be accessed by designated and authorized persons. The server is protected by an appropriate firewall and technical protection.
Access to databases and systems is only possible with separately issued personal usernames and passwords. The controller has limited the access rights and authorizations to information systems and other storage media so that the data can be viewed and processed only by persons who are necessary for their lawful processing. In addition, database and system access transactions are recorded in the log data of the registrar's IT system.
The controller's employees and other persons have undertaken to observe professional secrecy and to keep confidential the information they receive in connection with the processing of personal data.
11 Rights of the data subject
The data subject has the following rights under the EU General Data Protection Regulation:
Requests for the exercise of the data subject's rights shall be addressed to the controller's contact person referred to in paragraph 1.