REGISTRY AND PRIVACY STATEMENT
The registrar of the register is MM Experience Oy (business ID number 3136967-9)
The contact person for registry matters is: Marco Pohjola
2 REGISTER'S NAME
The name of the register is HelsinkiBoats contact and customer register.
3 PURPOSE OF PERSONAL DATA PROCESSING
Personal data is processed for purposes related to managing, managing and developing customer relationships, providing and delivering services, and developing and invoicing services. Personal data is also processed for the purposes required to settle possible complaints and other claims.
In addition, personal data is processed in communications aimed at customers, such as for information and news purposes, as well as in marketing, as part of which personal data is also processed for purposes related to direct marketing and electronic direct marketing.
The customer has the right to refuse direct marketing aimed at him.
The controller processes the data himself and uses subcontractors acting on behalf and on behalf of the controller in the processing of personal data.
4 LEGAL BASIS OF PROCESSING
The legal bases for the processing of personal data are the following bases according to the EU General Data Protection Regulation (hereinafter also "GDPR"):
- the data subject has given his consent to the processing of her personal data for one or more specific purposes (GDPR 6 art. 1.a);
- the processing is necessary for the implementation of an agreement to which the data subject is a party, or for the implementation of pre-contractual measures at the request of the data subject (GDPR 6 art. 1.b);
- the processing is necessary to fulfill the legitimate interests of the controller or a third party (GDPR 6 art. 1.f).
The aforementioned legitimate interest of the data controller is based on a relevant and appropriate relationship between the data subject and the data controller, which is a consequence of the fact that the data subject is a customer or partner of the data controller, and when the processing takes place for purposes that the data subject could reasonably have expected at the time of the collection of personal data and in connection with the relevant relationship.
5 DATA CONTENT OF THE REGISTER (PERSONAL DATA GROUPS TO BE PROCESSED)
The register basically contains the following personal information about all registered persons:
- the person's basic information and contact information: [first name, last name, address, phone number, e-mail address];
- information related to the person's company or other organization and the person's position or job title. in a company or organization;
- the person's direct marketing permits and prohibitions.
6 REGULAR INFORMATION SOURCES
Personal data is collected from the registered person himself.
Personal data is also collected and updated within the limits of the applicable legislation from generally available sources, which are related to the implementation of the customer relationship between the controller and the registered person and with which the controller fulfills its obligations related to maintaining customer relationships.
7 PERSONAL DATA STORAGE PERIOD
The information collected in the register is kept only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal information was collected.
The need to retain personal data is assessed annually, and in any case, information about the registered person is removed from the register at the request of the registered person. Accounting documents are kept for five years after the end of the accounting period.
The controller evaluates the necessity of storing data regularly in accordance with its internal code of conduct. In addition, the controller takes all possible reasonable measures to ensure that personal data that is inaccurate, incorrect or outdated in relation to the purposes of the processing is deleted or corrected without delay.
8 RECIPIENTS OF PERSONAL DATA (GROUPS OF RECIPIENTS) AND REGULAR TRANSFER OF DATA
Personal data will not be disclosed to external parties
9 DATA TRANSFER OUTSIDE THE EU OR EEA
Personal data included in the register will not be transferred outside the EU or EEA.
10 REGISTRY PROTECTION PRINCIPLES
Materials containing personal data are stored in locked rooms, to which only designated and authorized persons have access due to their duties.
The database containing personal data is on a server, which is kept in a locked state, to which only designated and authorized persons have access due to their duties. The server is protected by an appropriate firewall and technical protection.
Access to databases and systems is only possible with separately issued personal user IDs and passwords. The registrar has limited access rights and authorizations to information systems and other storage platforms in such a way that the data can be viewed and processed only by the persons necessary for their legal processing. In addition, the usage events of databases and systems are registered in the log data of the controller's IT system.
The employees and other persons of the registrar are committed to observe the obligation of confidentiality and to keep secret the information they receive in connection with the processing of personal data.
11 RIGHTS OF THE REGISTRANT
Rekisteröidyllä on seuraavat EU:n yleisen tietosuoja-asetuksen mukaiset oikeudet:
- the right to receive confirmation from the data controller that the personal data concerning him or her is being processed or that it is not being processed, and if this personal data is being processed, the right to have access to the personal data and the following information: (i) the purposes of the processing; (ii) the groups of personal data in question; (iii) recipients or groups of recipients to whom personal data has been disclosed or is intended to be disclosed; (iv) if possible, the planned retention period of personal data or, if it is not possible, this period
- the right to withdraw consent at any time without affecting the legality of the processing carried out on the basis of consent before its withdrawal (GDPR art. 7);
- the right to demand that the data controller correct inaccurate and incorrect personal data concerning the data subject without undue delay, and the right to have incomplete personal data supplemented, for example by submitting an additional explanation taking into account the purposes for which the data were processed (GDPR art. 16);
- the right to have the data controller delete the personal data concerning the data subject without undue delay, provided that (i) the personal data is no longer needed for the purposes for which it was collected or for which it was otherwise processed; (ii) the data subject withdraws the consent on which the processing was based, and there is no other legal basis for the processing; (iii) the data subject objects to the processing on grounds related to his personal special situation and is not subject to the processing
- the right to have the data controller limit the processing if (i) the data subject disputes the accuracy of the personal data, in which case processing is limited to a period during which the data controller can verify their accuracy; (ii) the processing is illegal and the data subject opposes the deletion of personal data and instead demands the restriction of their use; (iii) the controller no longer needs the personal data in question for the purposes of the processing, but the data subject does
- the right to receive the personal data concerning himself, which the data subject has provided to the data controller, in a structured, commonly used and machine-readable format, and the right to transfer the data in question to another data controller without the hindrance of the data controller to whom the personal data has been delivered, if the processing is based on the consent referred to in the regulation and the processing is carried out automatically (GDPR 20 art.);
- the right to file a complaint with the supervisory authority if the data subject considers that the processing of personal data concerning him violates the EU General Data Protection Regulation (GDPR art. 77).
Requests regarding the exercise of the data subject's rights are addressed to the controller's contact person mentioned in point 1.
12 NETWORK ANALYTICS
The services below collect anonymized information about website visits without personal information.
13 TARGETED MARKETING
Based on the visit to the website, we may do targeted advertising in the following services
Facebook, Instagram, Mailchimp