Privacy policy

1. The controller

Fiid Oy (3274878-5)
Neitsytpolku 2B
00140 HELSINKIcontact (at) fiid.fi

2. Contact person for the register

Fiid Oy
contact (at) fiid.fi

3. Name of the register

Fiid Oy's customer and marketing register

4. Legal basis and purpose of processing personal data

The legal basis for the processing of personal data under the EU General Data Protection Regulation is

- the consent of the individual (documented, voluntary, individual, informed and unambiguous)
- a contract to which the data subject is a party
- a legitimate interest of the controller (customer relationship, employment relationship, membership).

The purpose of processing personal data is to maintain customer relations, customer relationship management and marketing.

5. Data content of the register

The information stored in the register includes: name, title, company/organisation, contact details (telephone number, e-mail address), website addresses, information on ordered services and changes thereto, billing information and any other information related to the customer relationship. The data is processed only to the extent necessary for your dealings with Fiid Oy.

6. Regular sources of information

The data stored in the register is obtained from the customer, for example, through messages sent via web forms, e-mail, telephone, contracts, customer meetings and other situations where the customer provides his/her data.

7. Regular disclosures and transfers of data outside the EU or EEA

No data will be disclosed to other parties. Data may be published to the extent agreed with the customer. Data may also be transferred outside the EU or EEA by the controller.

8. Principles for the protection of the register

The register is processed with due care and the data processed by the information systems are adequately protected. Where the data are stored on Internet servers, the physical and digital security of the hardware is adequately ensured. The controller shall ensure that stored data, as well as access rights to servers and other information critical to the security of personal data, are treated confidentially and only by employees whose job description includes this. The register is protected by appropriate user IDs and passwords.Employees handling customer register data are bound by confidentiality obligations. Information is disclosed or released to third parties only in response to a legal obligation to disclose, such as at the customer's own request or at the request of a public authority under the law.

9. Right of inspection and right to request correction of information

Every person in the register has the right to check the data recorded in the register and to request the correction of any inaccurate data or the completion of incomplete data. If a person wishes to check or request the rectification of data stored about him or her, the request must be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will reply to the customer within the time limit laid down in the EU General Data Protection Regulation (as a general rule, within one month).

10. Other rights relating to the processing of personal data

A data subject in the register has the right to request the erasure of personal data concerning him or her from the register ("right to be forgotten"). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of the processing of personal data in certain circumstances. Requests should be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits set by the EU GDPR (as a general rule, within one month).