Privacy policy

This is the register and data protection statement in accordance with the EU General Data Protection Regulation (GDPR). Prepared on 20.11.2024. Last modified on 20.11.2024.

1. Data controller

Jyri Kalliola

2.Contact person responsible for the register

Jyri Kalliola
info@staylevi.fi
050 0555 055

3. Name of the register

Asiakasrekisteri

4. Legal basis and purpose of processing personal data.

The legal basis for processing personal data in accordance with the EU General Data Protection Regulation is:
  • The individual’s consent (documented, voluntary, specific, informed, and unambiguous)
  • A contract to which the data subject is a party
  • Law (e.g., accounting law)
  • The legitimate interest of the data controller (e.g., customer relationship prior to a contract)
The purpose of processing personal data is to maintain contact with customers, manage customer relationships, and conduct marketing. The data is not used for automated decision-making or profiling.

5. Register data content

The information stored in the register includes:

  • Name
  • Email address
  • Phone number
  • Details of ordered services and their changes
  • Billing information.

6. Regular data sources

The information stored in the register is obtained from the customer through messages sent via web forms, email, phone, social media services, contracts, and other situations where the customer provides their information.

7. Regular disclosures of data and transfer of data outside the EU or EEA

Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer. Data may also be transferred by the data controller outside the EU.

or ETA

Data is not transferred to the United States.

8. Principles of register protection

Care is taken in handling the register, and data processed through information systems is appropriately protected. When register data is stored on Internet servers, the physical and digital security of the hardware is duly ensured. The data controller ensures that stored data, server access rights, and other information critical to the security of personal data are handled confidentially and only by those whose job description includes it.

9. Right of access and right to request correction of information

Every individual in the register has the right to check their stored data and request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check their stored data or request a correction, the request must be sent in writing to the data controller. The data controller may ask the requester to prove their identity if necessary. The data controller will respond to the customer within the time frame stipulated by the EU Data Protection Regulation (generally within one month).

10. Other rights related to the processing of personal data

Individuals in the register have the right to request the deletion of their personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as restricting the processing of personal data in certain situations. Requests must be sent in writing to the data controller. The data controller may ask the requester to prove their identity if necessary. The data controller will respond to the customer within the time frame stipulated by the EU Data Protection Regulation (generally within one month).