Name and address of data controller
Company
Rideer Nordic Oy
Aittakorventie 2
48400 Kotka
Website
Person in charge of registry matters
Registry name
Tilausajot.net service customer registry.
Use of data
The purpose of processing registry data is to maintain the customer relationship between the Service provider (Tilausajot.net) and the Service user (Customer) and support the company’s business planning and development through various research methods. Data is used for customer communications and potentially direct marketing, if allowed by law and the Customer gives their consent.
Legal basis for processing
Processing of personal data is based on one or more of the following grounds:
- Processing and forwarding of the user's offer request to service providers and providing the service to the user.
- Consent given by the customer
- Legitimate interest of the service provider in providing, developing and securing the service and maintaining the customer relationship
- Statutory obligations applicable to the service provider
Source of data
Data is obtained primarily from the data subject themselves:
- when submitting offer requests
- when creating a user account
- when the user updates their information
- when the user uses the service
In addition, technical data may be collected through cookies and similar technologies when using the service.
Data may also be obtained automatically from log and analytics data generated when using the service.
Data accuracy, timeliness, and completeness
The Service Provider does not check for accuracy of the information. When logged in, Customer can view their submitted requests for quote and their Customer information in the registry. Customers cannot view other use information through the Service.
Customers can correct their information by logging in to the service. The customer has the right to review personal data stored about them in accordance with applicable data protection legislation. Requests for access must be submitted in writing to the controller.
Registry data content
The registry contains the following information about the customer:
- Customer information
- Name
- Email address
- Mobile phone number
- City of residence
- Any other additional information provided by the customer
- Offer request and usage data
- Saved requests for quote
- Information provided in connection with offer requests
- Any other additional information provided by the customer
Disclosing information to others
The service provider discloses the customer's offer request and related contact details to the service providers to whom the request is forwarded in order to enable the operation of the service and to fulfil the offer or contact request requested by the customer. Otherwise, data is not disclosed to third parties without a legal basis or the customer's consent.
Data may be disclosed for research or marketing purposes if the customer has given prior consent. With the customer's specific consent, data may also be disclosed for use in a third party's business.
Data is also disclosed to authorities when and to the extent required by applicable law.
Transferring data outside the EU and EEA
Personal data is processed within the European Union or the European Economic Area. The exception is external service providers used by the Service Provider, such as analytics, marketing and other technical services, in connection with which personal data may also be processed or transferred outside the EU or the EEA.
When personal data is processed or transferred outside the EU or the EEA, the transfer of data complies with applicable data protection legislation and appropriate safeguards are used to protect personal data.
Removing data from the registry
Customer and usage data are retained only for as long as necessary to fulfil the purposes described in this statement or as required by legislation.
Customer and usage data are removed from the register after the customer relationship ends in database clean-ups carried out in accordance with the service provider's current practices.
Order-related data may be retained for the period required by applicable legislation to fulfil accounting and other statutory obligations.
If the service provider terminates the customer relationship, customer and usage data may be retained for up to five (5) years after the end of the relationship to ensure the security of the service.
Rights of the data subject
Under applicable data protection legislation, the customer has the right to:
- be informed about the processing of their personal data
- access personal data concerning them
- request correction of inaccurate or incomplete data
- request erasure of their data where permitted by law
- restrict the processing of their personal data
- object to the processing of their personal data
- receive personal data they have provided in a structured, commonly used format and transmit it to another controller where applicable
- withdraw consent they have given to the extent processing is based on consent
Requests relating to these rights must be submitted in writing to the controller.
Right to lodge a complaint with a supervisory authority
The customer has the right to lodge a complaint with the Office of the Data Protection Ombudsman if they consider that the processing of their personal data violates applicable data protection legislation.
Further information is available on the website of the Office of the Data Protection Ombudsman.
Cookies
To monitor and enable use of the service, cookies and similar technologies may occasionally be placed in the customer's browser. Cookies collect the data defined in this statement for the purposes stated herein.
Cookies and similar technologies are used for example to:
- enable the operation of the service
- develop the user experience
- analyse visitor and usage data
- measure and develop use of the service
- measure the effectiveness of marketing and advertising
- target marketing and remarketing
The service provider may use third-party analytics, marketing, advertising and other online services to fulfil these purposes.
Users can manage cookies through their browser settings and any cookie preference tools. Blocking cookies may affect the functionality of the service.
Registry protection (data security)
All individuals processing the register have personal access rights granted by the controller (username, password and access level).
Use of the register is logged and each login is recorded. Access to the customer's personal data is limited to persons who need this information to perform their duties. These include the service provider's customer service staff and the technical administrators of the service.