Register and Privacy Statement

This is SIIV Oy's registration and data protection statement in accordance with the EU General Data Protection Regulation (GDPR). Prepared on 1 August 2022. Latest change 15.11.2022.

  1. Registrar

    Siiv Oy
    Day path 10
    04410 Järvenpää
    Social security number 3290834-7
    www.siiv.fi

  2. The contact person responsible for the register

    Lasse Oz, [email protected], 045 7838 444 3

  3. Register name

    The company's customer register, marketing register, stakeholder register, online service user register, employee/subcontractor register

  4. Legal basis and purpose of personal data processing

    According to the EU General Data Protection Regulation, the legal basis for processing personal data is one of the following

    • consent of the person (documented, voluntary, individualised, informed and unambiguous)
    • an agreement to which the data subject is a party
    • the law (for employees) or
    • legitimate interest of the controller (customer relationship).

    The purpose of personal data processing is communication with customers, maintenance of customer relations, statutory obligations and company needs, storage of employees' and subcontractors' data, and marketing.

  5. Data content of the register

    The information to be recorded in the register is:

    For employees, customers and subcontractors, the person's name, company/organisation, contact information (phone number, e-mail address, address), allergies to animals, IP address of the network connection, credentials/profiles in social media services, information about ordered services and their changes, billing information, other customer relations and ordered information related to services.

    Marketing uses the information mentioned above by customers and potential customers, as well as approval to receive marketing messages

    The data will be stored indefinitely unless the customer/potential customer requests their deletion. Employee/subcontractor information is stored for the period prescribed by law.

    IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to take care of information security and for the collection of statistical data of website visitors in those cases when they can be considered as personal data. If necessary, consent is requested separately for third-party cookies.

  6. Regular sources of information

    The information to be saved in the register is obtained from the customer, e.g. From messages sent via web forms, by email, by phone, via social media services, contracts, customer meetings and other situations where the customer gives out their information.

    Information about contact persons of companies and other organisations can also be collected from public sources such as websites, directory services and other companies.

  7. Regular transfers of data and transfer of data outside the EU or EEA

    Information is not regularly disclosed to other parties. Information can be published to the extent agreed with the customer.

    Data can also be transferred by the controller outside the EU or EEA.

    The data can be used in different systems located outside the EU and EEA (e.g. CRM, direct mail services, etc.), but the data will not be released for use by third parties.

  8. Principles of registry protection

    Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.

  9. Right of inspection and right to demand correction of information

    Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

  10. Other rights related to the processing of personal data

    A person in the register has the right to request the removal of personal data about him from the register ('the right to be forgotten'). Those registered also have other rights according to the EU's General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month)