This is Kultahakku Oy's EU General Data Protection Regulation (GDPR) compliant register and privacy statement. Prepared on 04/24/2023.
Kultahakku Oy (Akmeelikoru)
Pahtajakuja 5 U
FI- 96460 Rovaniemi
Seppo Mölläri
akmeelikoru@gmail.com
Phone: +358 400 893781
Kultahakku Oy's customer register
The purpose of processing personal data is the sale of jewelry, contacting customers, and maintaining customer relationships. Data is not used for automated decision-making or profiling.
The information to be recorded in the register includes: person's name, company/organization, contact information (phone number, email address, address), website addresses, IP address of the internet connection, information about ordered services and their changes, billing information, and other information related to the customer relationship and ordered services.
IP addresses of website visitors and cookies necessary for service functionality are processed based on legitimate interest for purposes such as ensuring security and collecting statistics on website visitors in cases where they can be considered personal data. Consent for third-party cookies will be requested separately if necessary.
The data recorded in the register is obtained from the customer through, among others, messages sent via web forms, email, phone, social media services, contracts, customer meetings, and other situations where the customer provides their information.
Information is not regularly disclosed to third parties. Information may be published to the extent agreed upon with the customer.
In processing the register, care is taken and data processed by information systems is properly protected. When register data is stored on internet servers, the physical and digital security of their hardware is appropriately managed. The data controller ensures that stored data, as well as server access rights and other information critical to personal data security, are handled confidentially and only by employees whose job description includes such access.
Every individual registered has the right to inspect their data stored in the register and to demand the correction of any inaccurate data or the completion of any incomplete data. If an individual wishes to inspect the data stored about them or demand its rectification, the request must be sent in writing to the data controller. The data controller may, if necessary, request the person making the request to prove their identity. The data controller shall respond to the customer within the time limit stipulated by the EU General Data Protection Regulation (as a general rule, within one month).
An individual registered in the system has the right to request the deletion of their personal data from the system (the ”right to be forgotten”). Likewise, registered individuals have other rights under the EU's General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be sent in writing to the data controller. The data controller may, if necessary, request the person making the request to prove their identity. The data controller will respond to the customer within the time limit specified in the EU's General Data Protection Regulation (generally within one month).