Privacy policy

Tämä on EU:n yleisen tietosuoja-asetuksen (GDPR) mukainen rekisteri- ja tietosuojaseloste. Laadittu 21.10.2024. Viimeisin muutos 21.10.2024.

1.Data controller

Hietaranta Housing
Sammaltie 5, 94700 Kemi
Business ID: 1059692-8
Phone: 040 068 3213

2 Contact person responsible for the register

Jarmo Parkkinen
040 068 3213
info@kemiapartments.fi

3. Register name

Asiakasrekisteri

4. Legal basis and purpose of processing personal data

The legal basis for processing personal data in accordance with the EU General Data Protection Regulation (GDPR) is:

  • The individual’s consent (documented, voluntary, specific, informed, and unambiguous)
  • A contract to which the data subject is a party
  • Law (e.g., accounting law)
  • The legitimate interest of the data controller (e.g., customer relationship before a contract)

The purpose of processing personal data is to communicate with customers, maintain customer relationships, and for marketing. Data is not used for automated decision-making or profiling.

5. Data content of the register

The information stored in the register includes:

  • Name
  • Address details
  • Email address
  • Phone number
  • Information about ordered services and their changes
  • Billing information

6. Regular sources of information

The information stored in the register is obtained from the customer through messages sent via web forms, email, phone, social media services, contracts, customer meetings, and other situations where the customer provides their information. Information about contact persons of companies and other organizations can also be collected from public sources such as websites, directory services, and other companies.

7. Regular disclosures of data and transfer of data outside the EU or EEA

Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer. Data may also be transferred by the data controller outside the EU or EEA. Data will not be transferred to the United States without the explicit consent of the data subjects.

8. Principles of register protection

Care is taken in handling the register, and data processed with information systems is appropriately protected. When register data is stored on Internet servers, the physical and digital security of the hardware is properly ensured. The data controller ensures that stored data, server access rights, and other critical personal data are handled confidentially and only by employees whose job description includes it.

9. Right of inspection and right to request correction of information

Every person in the register has the right to check their stored data and request the correction of any incorrect information or the completion of incomplete information. If a person wants to check their stored data or request a correction, the request must be sent in writing to the data controller. The data controller may ask the requester to prove their identity if necessary. The data controller will respond to the customer within the time specified in the EU Data Protection Regulation (usually within a month).

10. Other rights related to the processing of personal data

A person in the register has the right to request the deletion of their personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of personal data processing in certain situations. Requests must be sent in writing to the data controller. The data controller may ask the requester to prove their identity if necessary. The data controller will respond to the customer within the time specified in the EU Data Protection Regulation (usually within a month).