Privacy Policy of Silja Heikkilä tmi (Kht Vermillon)

This is a Privacy Policy of Silja Heikkilä tmi (Kht Vermillon) based on EU GDPR 10 and 24 §. Created on 25.3.2020. Last modified 28.3.2020.

1. Controller

Silja Heikkilä tmi (Kht Vermillon)

Uomarinne 5 A 33, 01600 Vantaa

Business ID 3118111-5

kht.vermillon@gmail.com

2. Contact person

Silja Heikkilä

kht.vermillon@gmail.com

+358 45 327 7623

3. Name of the register

Kht Vermillon customer register

4.  Legal basis and purpose of the processing of personal data

The legal basis for the processing of personal data under the EU General Data Protection Regulation is

- individual consent (documented, voluntary, personalized, informed and unambiguous)

- the agreement

- the legitimate interest of the controller (eg. customer relationship, employment relationship, membership)

The purpose of the processing of personal data is communication with customers, maintenance of customer relations, marketing.

The data is not used for automated decision making or profiling.

5. Content of the register

The information to be recorded in the register is: the name of the person, contact information (phone number, email address, address), information about the ordered products and their changes, billing information, other information related to the customer relationship and the services ordered.

The information is stored for as long as it is useful to the company or the person requests to delete the information.

6. Regular sources of information

Information stored in the register can be obtained from the customer. messages sent via web forms, emails, social media services, contracts, customer meetings and other situations where a customer discloses information.
 

7. Regular transfers of information outside the EU or the EEA

 Information is not trasnferred to other parties. The information may be published to the extent agreed with the customer.

8. Registry protection principles

The records shall be handled with care and the data processed by the information systems shall be appropriately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is properly taken care of. The data controller shall ensure that the stored information, as well as server access and other information critical to the security of personal data, is handled confidentially and only by the employees whose job description it covers.

9. Right to check

Every person in the register shall have the right to have their data recorded in the register checked at any time and to request that any inaccurate information be corrected or incomplete be corrected once a year. If a person wishes to check the information stored about them, the request should be sent by email to the controller. If necessary, the controller may ask the applicant to prove his identity. The controller will respond to the client within the time limit set by the EU Data Protection Regulation (within one month).

10. Other rights related to the processing of personal data

Any person on the register has the right to request that personal data relating to them be removed from the register ("the right to be forgotten"). Registered person also have other rights under the EU General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests should be sent by email to the Registrar. If necessary, the controller may ask the applicant to prove his identity. The controller will respond to the client within the time limit set by the EU Data Protection Regulation (within one month).

11. Changes to Privacy Policy

Kht Vermillon may make changes to this privacy statement and related information.