Privacy Policy

Privacy Policy

Updated on 1 March 2022

1. Data Controller
Jokiväri Oy, Alasintie 1, 80130 Joensuu, Finland

2. Contact Person for Matters Concerning the Register
Maiju Asikainen, maiju.asikainen@jokivari.fi, +358 50 371 1730

3. Name of the Register
Jokiväri Oy Customer and Marketing Register

4. Purpose of Processing Personal Data
The register is used to manage existing customer relationships and communications related to quotations, orders and forms submitted through the website. With the customer’s consent, the information may also be used for direct marketing. Individuals who provide their information for the register have a customer relationship with the data controller.

5. Data Contained in the Register
The register contains information provided by the customer in connection with an order or enquiry, including the customer’s first name, surname, postal address, telephone number and email address. This information is necessary for processing, invoicing and delivering orders, as well as responding to submitted forms. The register also contains information about the customer’s order history, order processing and customer feedback.

Google Analytics collects the visitor’s IP address, language, browser name and screen resolution.

6. Regular Sources of Information
The information stored in the register is provided by the customer when ordering services, registering as a customer or completing a request for quotation or feedback form.

7. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected or as required by an agreement or applicable law. Retention periods may vary depending on the purpose and circumstances. Retention periods may also be based on legislation, such as the Finnish Accounting Act. Where necessary, we aim to keep personal data up to date, and information that is no longer required will be deleted.

8. Regular Disclosure of Information
The information in the register is used solely for managing the data controller’s customer relationships and is not disclosed to third parties. Information may be published to the extent separately agreed with the customer.

9. Transfer of Data Outside the EU or EEA
The data controller does not transfer information contained in the customer register outside the European Union or the European Economic Area.

10. Principles of Register Protection
The data controller’s website uses a secure HTTPS connection. All information contained in the register is stored on a secure server and backed up on another server. The security of the servers is kept up to date. Access to the information is restricted to selected key personnel and requires logging in to the system with a username and password.

11. Cookies
A cookie is a small text file stored on the user’s device by an internet browser. Cookies are used, for example, to retain user information when the user moves from one page of an online service to another. The purpose of cookies on this website is to make browsing and using the service easier and faster by storing information and the session identifier in the user’s browser.

12. Right of Access and Right to Request Correction of Information
Every person included in the register has the right to access the personal data stored about them and to request the correction of inaccurate information, the completion of incomplete information or the deletion of information. Requests to access or correct personal data must be submitted in writing to the data controller. The data controller will respond within the period specified in the EU General Data Protection Regulation. The right of access is free of charge once per year.

13. Other Rights Relating to the Processing of Personal Data
Every person included in the register has the right to request the deletion of personal data concerning them from the register, also known as the “right to be forgotten”. Data subjects also have other rights under the EU General Data Protection Regulation, including the right to restrict the processing of personal data in certain circumstances. Requests must be submitted in writing to the data controller. Where necessary, the data controller may ask the person making the request to verify their identity. The data controller will respond within the period specified in the EU General Data Protection Regulation, generally within one month.