PRIVACY POLICY

Statement on the processing of personal data — GDPR

Data Controller

Name of register and purpose of processing

Register: TechService H.Ö Oy Ab — Customers, business partners and collaborators

Purposes of processing:

  • Management of customer and business relationships
  • Fulfilling the company's statutory obligations

Categories of data subjects and personal data

  • Customers: Contact details (name, address, phone number, email), personal data, bank details
  • Business partners: Contact details
  • Collaborators: Contact details, bank details

Regular data sources

Personal data is primarily collected from the customers themselves in connection with the customer relationship.

Customer data is not transferred to third countries or international organisations.

Data retention periods

  • Customer data: Until the end of the customer relationship, deleted no later than 2 years after the end of the customer relationship
  • Accounting data: 10 years after the dissolution of the company

Technical and organisational security measures

Material containing personal data is kept in the company's locked premises and as files on the company's own server, and on the service provider's server for financial administration services.

Data stored as files is protected by firewall and passwords. Only persons whose duties require it have access to customer data.

Rights of the data subject

The data subject has the right to:

  • Access their own data
  • Request correction of inaccurate data
  • Request deletion of data
  • Restrict processing of data
  • Object to processing of data

Requests are answered by email:

Notification of data breaches

  • To the data subject: A notification is made to the data subject if the breach is likely to result in a high risk to their rights and freedoms.
  • To the supervisory authority: A notification is made to the supervisory authority within 72 hours of discovery, if the breach is likely to result in a risk to the rights and freedoms of natural persons.