Privacy Policy and Register Description in accordance with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR)

Prepared on 28 March 2019
Updated on 17 February 2021

1. Data Controller

Ole.Fit Kamppi (Silveman Oy) ( 3455427-1)

2. Contact Person Responsible for the Register

Samuli Silvennoinen
0401234567
kamppi@ole.fit

3. Name of the Register

Ole.Fit Kamppi (Silveman Oy) Customer and Marketing Register, CCTV Recording Register

4. Legal Basis and Purpose of Processing Personal Data

The legal basis for processing personal data under the EU General Data Protection Regulation is:

the voluntary, documented consent of the data subject

a contract to which the data subject is a party, or

the legitimate interest of the data controller (customer relationship, employment relationship, membership).

The purpose of processing personal data is to maintain customer relationships, communicate with customers, and carry out marketing activities. The purpose of CCTV surveillance is to protect property, prevent misuse and crime, assist in the investigation of criminal offences, and ensure and improve the safety of staff, customers, and visitors.

5. Contents of the Register

The register may contain the following information: the person's name, position, company/organization, contact details (telephone number, email address, postal address), company website addresses, information about ordered services, billing information, and other information related to the customer relationship and ordered services. The information is retained in the register for the duration of the customer relationship and for one year after it has ended.

The register also contains video recordings captured by surveillance cameras.

6. Regular Sources of Information

The information stored in the register is obtained from the customer through messages sent via website forms, email, telephone, social media services, agreements, customer meetings, and other situations in which the customer provides their personal information.

7. Regular Disclosure of Information and Transfer of Data Outside the EU or EEA

We share your personal data with the following parties:

In cases involving suspected criminal activity, information may be disclosed to the relevant authorities.

For marketing-related assignments, information may be shared with partners who analyze, print, or distribute marketing materials.

Personal data may also be transferred by the data controller outside the EU or EEA.

If we disclose your personal data to our partners, they act as data processors under a cooperation agreement. Through this agreement, we require our partners to comply with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Our partners are not permitted to use the information in the register for any purpose other than the assignment agreed upon with Fit Sastamala.

8. Principles of Register Protection

The register is handled with due care, and all electronically processed data is appropriately protected. Information is stored in locked facilities, and electronic register data is protected by passwords known only to authorized personnel. When register data is stored on Internet servers, the physical and digital security of the hardware is ensured appropriately. Fit Sastamala ensures that stored data, server access rights, and other information critical to the security of personal data are handled confidentially and only by employees whose duties require such access. Employees who process customer register data are bound by confidentiality.

9. Right of Access and Right to Request Correction of Information

Every person included in the register has the right to inspect the personal data stored about them and to request the correction of any inaccurate information or the completion of incomplete information. If a person wishes to inspect the information stored about them or request corrections, the request must be submitted in writing to the data controller. The data controller may, if necessary, require the requester to verify their identity. The data controller will respond within the time period specified by the EU General Data Protection Regulation (generally within one month).

10. Other Rights Related to the Processing of Personal Data

Every person included in the register has the right to request the deletion of their personal data from the register. Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be submitted in writing to the data controller. The data controller may, if necessary, require the requester to verify their identity. The data controller will respond within the time period specified by the EU General Data Protection Regulation (generally within one month).