Privacy Policy
This is the Floor Factory Helsinki Oy register and privacy policy in accordance with the EU General Data Protection Regulation (GDPR). Last modified on 13.10.2024.
1. Controller
Floor Factory Helsinki, Pikimetsäntie 11A35, 01800 Klaukkala
2. Contact person responsible for the register
Jann Valjus, jann.valjus@floorfactory.fi, 040 7166850
3. Name of the register
Floor Factory Helsinki customer and marketing register, floorfactory.fi newsletter subscriber register, floorfactory.fi web service user register
4. Legal basis and purpose of the processing of personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is
– the consent of the individual (documented, freely given, specific, informed and unambiguous)
– a contract to which the data subject is a party
– a legal obligation; or
– a legitimate interest of the controller (e.g. pre-contractual relationship, customer relationship, employment relationship).
The purpose of processing personal data is to contact customers, provide customer service, process data relating to offers, orders and deliveries, invoicing and marketing.
5. Data content of the register
The data stored in the register includes: company/organisation, name, position, contact information (phone number, email address, address), website addresses, IP address of the network connection, social media accounts/profiles, information on ordered services and changes thereto, billing information, other information related to the customer relationship and ordered services. The IP addresses of visitors to the website and cookies necessary for the functioning of the service are processed for legitimate interests, such as ensuring security and collecting statistics on visitors to the website in cases where they can be considered as personal data. Third party cookies are subject to separate consent where necessary.
6. Regular data sources
The data stored in the register is obtained from the customer through, for example, messages sent via web forms, e-mail, telephone, social media services, contracts, customer meetings and other situations where the customer provides his/her data. Information from contact persons of companies and other organisations may also be collected from public sources such as websites, directory services and other companies.
7. Regular disclosures and transfers of data outside the EU or EEA
The data may be disclosed to producers of goods or services or to subcontractors who may be customers of the data subject or who need the data for customer service, order or delivery management. Data will not be disclosed to other parties as a matter of course. Data may be published to the extent agreed with the customer. Data will not be transferred by the controller outside the EU, EEA or the USA without the express consent of the data subjects.
8. Principles for the protection of the register
The register is processed with due care and the data processed by the computer systems are adequately protected. Where the data are stored on Internet servers, the hardware of the servers
the physical and digital security of the equipment used to store the data. The controller shall ensure that the data stored, as well as access rights to the servers and other personal data
critical to the security of personal data are handled confidentially and only by employees whose job description includes such handling.
9. Right of access and rectification
Every person in the register has the right to check the information stored in the register and to request that any inaccurate or incomplete information be corrected or completed. If a person wishes to check or request a correction of the data stored about him or her, the request must be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will reply to the customer within the time limit laid down in the EU General Data Protection Regulation (as a general rule, within one month).
10. Other rights relating to the processing of personal data
A data subject in the register has the right to request the erasure of personal data concerning him or her from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of the processing of personal data in certain circumstances. Requests should be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits set by the EU GDPR (as a general rule, within one month).