Register and Privacy Statement

This is Kultahakku Oy's EU General Data Protection Regulation (GDPR) compliant register and privacy statement. Prepared on 04/24/2023.

 

1. Data controller

Kultahakku Oy (Akmeelikoru)
Pahtajakuja 5 U
FI- 96460 Rovaniemi

akmeelikoru@gmail.com

 

2. Contact person responsible for the register

Seppo Mölläri
akmeelikoru@gmail.com
Phone: +358 400 893781

 

3. Register name

Kultahakku Oy's customer register

 

4. Legal Basis and Purpose of Personal Data Processing

The purpose of processing personal data is the sale of jewelry, contacting customers, and maintaining customer relationships. Data is not used for automated decision-making or profiling.

 

5. Register's Data Content

The information to be recorded in the register includes: person's name, company/organization, contact information (phone number, email address, address), website addresses, IP address of the internet connection, information about ordered services and their changes, billing information, and other information related to the customer relationship and ordered services.

IP addresses of website visitors and cookies necessary for service functionality are processed based on legitimate interest for purposes such as ensuring security and collecting statistics on website visitors in cases where they can be considered personal data. Consent for third-party cookies will be requested separately if necessary.

 

6. Regular information sources

The data recorded in the register is obtained from the customer through, among others, messages sent via web forms, email, phone, social media services, contracts, customer meetings, and other situations where the customer provides their information.

 

7. Regular disclosures and transfers of data outside the EU or EEA

Information is not regularly disclosed to third parties. Information may be published to the extent agreed upon with the customer.

 

8. Principles of Record Protection

In processing the register, care is taken and data processed by information systems is properly protected. When register data is stored on internet servers, the physical and digital security of their hardware is appropriately managed. The data controller ensures that stored data, as well as server access rights and other information critical to personal data security, are handled confidentially and only by employees whose job description includes such access.

 

9. Right of inspection and right to request correction of data

Every individual registered has the right to inspect their data stored in the register and to demand the correction of any inaccurate data or the completion of any incomplete data. If an individual wishes to inspect the data stored about them or demand its rectification, the request must be sent in writing to the data controller. The data controller may, if necessary, request the person making the request to prove their identity. The data controller shall respond to the customer within the time limit stipulated by the EU General Data Protection Regulation (as a general rule, within one month).

 

10. Other data protection rights

An individual registered in the system has the right to request the deletion of their personal data from the system (the ”right to be forgotten”). Likewise, registered individuals have other rights under the EU's General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations. Requests must be sent in writing to the data controller. The data controller may, if necessary, request the person making the request to prove their identity. The data controller will respond to the customer within the time limit specified in the EU's General Data Protection Regulation (generally within one month).