Privacy Policy

 

This is the Privacy Policy and Register Description of Softwave Ohjelmistot Oy, prepared in accordance with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR).

Drafted on 18 June 2018. Latest update on 31 January 2019 (updated contact person).

1. Data Controller
Softwave Ohjelmistot Oy,
Vaasantie 6C,
67100 Kokkola

Tel: 010 292 8810

markkinointi@softwave.fi
myynti@softwave.fi

2. Contact Person Responsible for the Register
Sami Hänninen
Email: sami.hanninen@softwave.fi
Tel: 010 292 8816

3. Name of the Register
Softwave Ohjelmistot Oy Marketing and Customer Register.

We process personal data of our customers, potential customers, and their representatives within this register.

4. Legal Basis and Purpose of Data Processing
The data is used for customer relationship management and communication. Additionally, it is used for marketing purposes.

The legal basis for processing is legitimate interest for marketing and the performance of a contract for customer relationship management.

The data is not used for automated decision-making or profiling.

5. Contents of the Register
The register contains the following information:
● Name of the person
● Position
● Company/organization
● Contact details (phone number, email address, postal address)
● Information on products and their updates
● Billing details
● Other details related to the customer relationship and subscribed services

6. Regular Sources of Information
The data stored in the register is obtained from customers via:
● Messages sent through web forms
● Email
● Telephone
● Contracts
● Customer meetings
● Other situations where the customer provides their information
● Data may also be collected from external sources, such as public websites of
organizations.

7. Regular Disclosures of Data and Transfers Outside the EU or EEA
Data is not regularly disclosed to third parties. Data may be published only if agreed with the customer.

Data is not transferred outside the EU or EEA by the data controller.

8. Principles of Register Protection
The processing of the register is conducted with care, and data processed with information systems is adequately protected. When data is stored on internet servers, both physical and digital security of the hardware is ensured appropriately.

The data controller ensures that stored data, server access rights, and other critical personal data security aspects are handled confidentially and only by employees whose job descriptions require it.

9. Right of Access and Right to Rectification
Every individual in the register has the right to inspect the personal data stored about them and to request correction of any inaccurate or incomplete data.

If an individual wishes to inspect their stored data or request corrections, they must send a written request to the data controller. The data controller may request the individual to verify their identity.

The data controller responds to the customer within the time frame specified in the EU General Data Protection Regulation (generally within one month).

10. Other Rights Related to Personal Data Processing
Individuals in the register have the right to request the deletion of their personal data (“right to be forgotten”). Similarly, registered individuals have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations.

Requests must be sent in writing to the data controller. The data controller may request the individual to verify their identity. The data controller responds to the customer within the time frame specified in the EU General Data Protection Regulation (generally within one month).

11. Changes to the Privacy Policy
We are committed to continuously improving our services and reserve the right to modify this privacy policy by notifying changes on this page.