Privacy Policy and Data Protection Statement

This is KX-Treeshears Oy’s Privacy Policy and Data Protection Statement in accordance with the Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on June 6, 2020. Last updated on March 29, 2023.

1. Data Controller

KX-Treeshears Oy, Yrittäjänkatu 3, 44150 Äänekoski
kx-treeshears.com
[email protected]

2. Contact Person Responsible for the Registry

Kimmo Tossavainen
[email protected]
+358 409 662 067

3. Name of the Registry

Company Customer Database

4. Legal Basis and Purpose of Processing Personal Data

Under the EU General Data Protection Regulation, the legal basis for processing personal data is the individual’s consent (documented, voluntary, specific, informed, and unambiguous).

The purpose of processing personal data isto communicate with customers, conduct marketing, and maintain customer relationships.

The data will not be used for automated decision-making or profiling.

5. Data Content of the Registry

The information to be stored in the registry includes:

  • a person’s name
  • company/organization
  • contact information (phone number, email address)

6. Standard Sources of Information

The information stored in the registry is obtained from the customer through, for example, messages sent via web forms, email, telephone, social media services, contracts, customer meetings, and other situations in which the customer provides their information.

7. Routine Disclosure of Data and Transfer of Data Outside the EU or the EEA

Information is not routinely disclosed to third parties. Information may be disclosed to the extent agreed upon with the customer.

8. Principles of Data Protection

The register is handled with due care, and data processed using information systems is appropriately protected. When registry data is stored on Internet servers, the physical and digital security of the hardware is ensured as appropriate. The data controller ensures that stored data, as well as server access rights and other information critical to the security of personal data, is handled confidentially and only by those employees whose job description includes such duties.

9. Right of Access and Right to Request Correction of Information

Every person listed in the registry has the right to review their information stored in the registry and to request that any incorrect information be corrected or that any incomplete information be supplemented. If a person wishes to review the information stored about them or request that it be corrected, the request must send it to the data controller via email. If necessary, the data controller may ask the person making the request to verify their identity. The data controller will respond to the customer within the timeframe specified in the EU General Data Protection Regulation (generally within one month).

10. Other Rights Related to the Processing of Personal Data

A person listed in the registry has the right to request that their personal data be removed from the registry (“the right to be forgotten”). Data subjects also have other Rights under the EU General Data Protection Regulation, such as the restriction of the processing of personal data in certain situations. Requests must be send it to the data controller via email. If necessary, the data controller may ask the person making the request to verify their identity. The data controller will respond to the customer within the timeframe specified in the EU General Data Protection Regulation (generally within one month).