Privacy policy

Privacy policy

This is an English translation of our Finnish privacy policy, provided for convenience. In the event of any discrepancy between the two versions, the Finnish version prevails.

  1. General

This privacy policy describes what personal data Puro Partners Oy (the ”Company”) collects, how that data is processed, for what purposes it is used and to whom it may be disclosed. The policy also sets out the obligations the Company follows when processing personal data. The Company pays particular attention to protecting data and, in all processing of personal data, complies with the EU General Data Protection Regulation (2016/679) (the ”GDPR”), other applicable data protection legislation and good data processing practice. This privacy policy applies to all services offered by the Company. In addition to the personal data of customers, it also applies to the processing of the personal data of prospective customers. The policy further applies to the processing of personal data belonging to representatives of the Company’s business customers, partners, service providers and subcontractors. Personal data means all information relating to a natural person (the ”data subject”) from which that person can be identified directly or indirectly, as defined in the GDPR. Information from which a data subject cannot be identified directly or indirectly is not personal data.

  1. Controller and contact person
  • Controller: Misa Pietilä Tmi
  • Business ID: 3564885-1
  • Email: info@purodigital.fi
  • Contact person: Misa Pietilä
  1. Purposes and legal basis for processing personal data
  • Personal data is processed for, among others, the following purposes:
  • Ordering the Company’s products and services, and their maintenance, development, quality assurance and related communications
  • Business planning and product development
  • Personalised customer service relating to the services, targeted customer communications and monitoring the use of the services
  • Marketing and the targeting of marketing to customers and prospective customers, ensuring the security of the services and preventing misuse
  • Invoicing
  • Job applications, recruitment or other comparable situations in which we need contact details
  • The legal basis for processing data subjects’ personal data is the contractual relationship between the Company and the data subject, arising from the ordering or provision of a product or service offered by the Company. Processing is also based on statutory obligations such as accounting obligations. Processing for the management of the customer relationship and for marketing is based on the Company’s legitimate interest. Electronic direct marketing and subscriptions to the Company’s newsletters are based on the data subject’s consent or on the Company’s legitimate interest. The data subject has the right to withdraw consent at any time (see the rights of the data subject below).
  1. Categories of personal data processed, data content and sources

The Company collects only such personal data about data subjects as is relevant and necessary for the purposes described in this privacy policy. The following data is processed about data subjects:

Providing the data referred to above is necessary in order to fulfil the obligations arising from the contract between the Company and the data subject and from legislation, and in order to provide the Company’s services. Providing the data referred to is voluntary.

Personal data is primarily collected from the data subjects themselves, for example when a quotation is prepared, when a contract is concluded or during the customer relationship. A data subject may also have provided information to the Company by, for example, subscribing to an electronic newsletter, through social media services or via the Company’s website.

The Company may use external service providers in its marketing, and those providers process data subjects’ contact details for marketing purposes. Personal data may also be collected from the organisation on whose behalf the data subject acts. In addition, where legislation permits, data may be collected and updated from registers maintained by third parties.

The Company’s subcontractors, contractors and partners provide the Company with data subjects’ personal data in situations required by legislation and contractual obligations.

The Company uses various services for website analytics, including Google Analytics, which make use of browser cookies and other identifiers. Further information can be found in the privacy policies of each service used.

  1. Retention of personal data

The Company retains personal data for as long as is necessary to fulfil the purposes defined in this privacy policy, unless legislation requires the data to be retained for longer (for example responsibilities and obligations relating to special legislation, accounting obligations or reporting obligations), or unless the Company needs the data to establish, exercise or defend a legal claim or to resolve a comparable dispute.

The retention period and the retention criteria vary by category of personal data, according to the purpose for which that particular category is used.

Personal data is processed for the duration of the customer and contractual relationship and for a necessary period after that relationship ends. Data concerning prospective customers is generally retained for one year.

In the case of organisations, the retention of a representative’s personal data is tied to how long that data subject acts as a representative of the organisation towards the Company.

When personal data is no longer needed as defined above, the data is deleted within a reasonable time.

  1. Parties processing and receiving personal data

Companies belonging to the same group as the Company may process personal data in accordance with data protection legislation.

In accordance with this privacy policy, the Company may outsource the processing of personal data to service providers or subcontractors. The Company ensures through adequate contractual obligations that personal data is processed appropriately. Personal data may be disclosed to authorities in situations required and permitted by legislation.

The Company does not disclose data subjects’ personal data for direct marketing purposes.

If the Company is party to a merger, a business transfer or another corporate arrangement, it may be required to disclose data subjects’ personal data to third parties.

Disclosure of data to a third party generally takes place via electronic data transfer connections, but data may also be disclosed by other means such as by telephone or by letter.

  1. Transfer of personal data outside the European Union or the European Economic Area

Data is not transferred outside the European Union or the European Economic Area.

Should data be transferred outside the European Union or the European Economic Area, the Company will ensure an adequate level of protection for personal data, among other things by agreeing on matters relating to the processing of personal data in the manner required by data protection legislation, such as by using the standard contractual clauses approved by the European Commission.

  1. Principles of personal data protection and security of processing

The Company processes personal data in a manner intended to ensure, in all situations, the appropriate security and protection of personal data, including protection against unauthorised processing and against accidental loss, destruction or damage.

Appropriate technical and organisational safeguards are used in the processing of personal data to secure this, including the use of firewalls, encryption technologies and secure equipment facilities, appropriate access control and access management, and the instruction of personnel.

Contracts and other documents retained as originals are kept in locked facilities to which access is limited to authorised parties only. Paper printouts are destroyed securely.

All parties processing personal data are bound by a duty of confidentiality regarding matters relating to the processing of data subjects’ personal data, on the basis of the Employment Contracts Act and the confidentiality terms of contracts.

In accordance with this privacy policy, the Company may outsource the processing of personal data to service providers, in which case the Company ensures through adequate contractual obligations that personal data is processed appropriately and lawfully.

  1. Rights of data subjects

Data subjects have the rights guaranteed by data protection legislation.

A data subject has the right to obtain confirmation as to whether their personal data is being processed. A data subject has the right to inspect and see the data concerning them and, on request, the right to receive that data in writing or in electronic form.

A data subject has the right to require the correction of incorrect or inaccurate data. In addition, a data subject has the right under applicable data protection legislation to require the deletion of their data. The Company also deletes, corrects and completes, on its own initiative, personal data it identifies as incorrect, unnecessary, incomplete or outdated in relation to the purpose of the processing.

Under applicable data protection legislation, a data subject has the right to require the transfer of their data to another controller.

In addition, subject to the conditions set out in data protection legislation, a data subject has the right to request the restriction of processing of personal data. Furthermore, in a situation where personal data suspected of being incorrect cannot be corrected or deleted, or where there is uncertainty about a deletion request, the Company will restrict access to the data.

A data subject has the right to object to the use of their data for certain types of processing. A data subject has the right to prohibit the disclosure and processing of their data for direct marketing purposes.

Requests concerning data subjects’ rights are made in person, in writing or electronically, and are addressed to the contact person named in this privacy policy. Identity is verified before any data is provided. An inspection request is answered within a reasonable time and, where possible, within one month of the request being made and identity being verified.

If a data subject’s request cannot be granted, the refusal will be communicated to the data subject in writing. The Company may refuse a request, such as a request for deletion, on the basis of a statutory obligation or a statutory right of the Company, such as an obligation or claim relating to the services.

Consent to electronic direct marketing may be withdrawn, or a prohibition on direct marketing given, by contacting the Company’s contact persons. In addition, a data subject may leave the Company’s mailing list at any time by clicking the ”Unsubscribe” link in an email.

  1. Right to lodge a complaint with a supervisory authority

A data subject has the right to lodge a complaint with the data protection authority if the data subject considers that their personal data has been processed contrary to applicable legislation.

Office of the Data Protection Ombudsman

Visiting address: Ratapihantie 9, 6th floor, 00520 Helsinki, Finland

Postal address: P.O. Box 800, 00521 Helsinki, Finland

Email: tietosuoja@om.fi

Switchboard: +358 29 56 66700

  1. Changes to this privacy policy

The Company develops its services continuously and may therefore need to amend and update this privacy policy. Changes may also arise from changes in legislation. We recommend reviewing the content of this privacy policy regularly. Changes are announced on the Company’s website and, in the case of material changes, to data subjects by email.