KM PARTS OY (KM-PARTS.FI) CUSTOMER REGISTER PRIVACY STATEMENT
1 Personal data controller
Controller of the register is KM Parts Oy (business-ID 2324675-9 )
Contact information in matters related to personal data files: Kari Manninen
KM Parts Oy
Address: Puusepäntie 65, 62420 Kortesjärvi
Phone: 0505992111
E-mail: info@km-parts.fi
2 Name of the registry
The name of the registry is KM Parts Oy customer register.
3 Purpose of use of personal data
Personal data is processed for purposes related to managing, administration and developing customer relationships, providing and delivering services and developing and invoicing services. Personal data is also processed for the purposes required to settle possible complaints and other claims..
In addition, personal data is processed in communications aimed at customers, such as for information and news purposes, as well as in marketing, as part of which personal data is also processed for purposes related to direct marketing and electronic direct marketing.
Customer has right to forbid direct marketing.
The data controller processes the data itself and uses subcontractors acting on behalf and on behalf of the data controller in the processing of personal data.
4 Legal grounds for processing
The legal bases for the processing of personal data are the following bases according to the EU General Data Protection Regulation (referred to as "GDPR"):
The legitimate interest of the data controller is based on a meaningful and appropriate relationship between the data subject and the data controller, which is a consequence of the fact that the data subject is a customer of the data controller, and when the processing takes place for purposes that the data subject could reasonably have expected at the time of the collection of personal data and in connection with the relevant relationship.
5 Data content of the register (groups of personal data to be processed)
The register basically contains the following personal information about all registered persons:
6 Regular sources of information
Personal data is collected from the registered person himself.
Personal data is also collected and updated within the limits of the applicable legislation from generally available sources, which are related to the implementation of the customer relationship between the controller and the registered person and with which the controller fulfills its obligations related to maintaining customer relationships.
7 Personal data retention period
The information collected in the register is kept only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal information was collected.
The need to retain personal data is evaluated every five years, and in any case, the data concerning the registered person is removed from the register seven years after the customer relationship of the registered person with the controller has ended, and the obligations and measures related to the customer relationship have been completed. For example, accounting documents are kept for six years after the end of the accounting period.
The controller evaluates the necessity of storing data regularly in accordance with its internal code of conduct. In addition, the controller takes all possible reasonable measures to ensure that personal data that is inaccurate, incorrect or outdated in relation to the purposes of the processing is deleted or corrected without delay.
8 Recipients of personal data (recipient groups) and regular transfers of data
Personal data will not be disclosed to external parties.
9 Data transfer outside the EU or EEA
Personal data included in the register will not be transferred outside the EU or EEA.
10 Principles of registry protection
Materials containing personal data are stored in locked rooms, to which only designated and authorized persons have access due to their duties.
The database containing personal data is on a server, which is kept in a locked state, to which only designated and authorized persons have access due to their duties. The server is protected by an appropriate firewall and technical protection.
Access to databases and systems is only possible with separately issued personal user IDs and passwords. The registrar has limited access rights and authorizations to information systems and other storage platforms in such a way that the data can be viewed and processed only by the persons necessary for their legal processing. In addition, the usage events of databases and systems are registered in the log data of the controller's IT system.
The employees and other persons of the registrar are committed to observe the obligation of confidentiality and to keep secret the information they receive in connection with the processing of personal data.
11 Rights of the data subject
The registrant has the following rights according to the EU General Data Protection Regulation:
Requests regarding the exercise of the data subject's rights are addressed to the controller's contact person mentioned in point 1.