REGISTER AND PRIVACY STATEMENT

This is the Register and Privacy Statement in accordance with the Company Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on 27.1.2020. Last modified 27.1.2020.

1 Registrar

The registrar of the register is;

Guldhoven (business ID 3113281-5)

The contact person for registration matters is: Charlotta Lindgren, owner

www.guldhoven.com

Address: Tavastinkatu 4, 06400 PORVOO

Phone: 050 4588214

Email: kht.guldhoven@gmail.com

 

2 Name of the registry

The name of the register is Guldhoven's customer register.

 

3 Purpose of processing personal data

Personal data is processed for purposes related to the management and administration of the customer relationship, the provision and delivery of services, and the development and invoicing of services. Personal data is also processed for the purposes required to clarify possible complaints and other claims.

In addition, personal data is processed in communications to customers, such as for information and news purposes, and in marketing, as part of which personal data are also processed for purposes related to direct marketing and electronic direct marketing.

 

The customer has the right to prohibit direct marketing directed at him.

 

4 Information content of the register

The register collects basic information about the registrants that he has provided in the online store, by e-mail or by telephone, such as:

- name

- address

- telephone

- email

The data collected in the register shall be kept only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal data were collected.

 

5 Regular sources of information

The information stored in the register is obtained from the customer e.g. Messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information.

 

6 Regular transfers of data and transfers of data outside the EU or the EEA

The data controller processes the data himself. We do not disclose information to third parties. Personal data contained in the register will not be transferred outside the EU or the EEA.

 

7 Registry security principles

The register shall be handled with due care and the data processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it includes.

8 Right of inspection and right to request correction of information

Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check or request the correction of data stored about him or her, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).

 

9 Other rights related to the processing of personal data

A person in the register has the right to request the removal of his or her personal data from the register ("the right to be forgotten"). Data subjects also have other rights under the EU's general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).