Privacy Policy

Privacy policy in accordance with Section 10 of the Personal Data Act (523/1999) and the EU General Data Protection Regulation (GDPR).

1. Data Controller

Sunila Solutions Oy Sunilantie 1 48900 Kotka

2. Contact person for register matters

Person in charge of data protection matters Mikko Aarrekoski mikko.aarrekoski@sunilasolutions.fi +358 50 529 8230

3. Name of the register

Sunila Solutions Oy's customer and marketing register.

4. Purpose of processing personal data

Personal data is processed for managing, administering, developing, analyzing, and compiling statistics on customer relationships. In addition, the data may be used for direct marketing, customer surveys, and other similar marketing purposes, unless the data subject has prohibited this.

5. Data content of the register

The register may contain the following information: company name and Business ID, contact person's name, title, phone number and email address, postal address and invoicing details, information on ordered services and their changes, information related to invoicing and debt collection, as well as marketing permissions and prohibitions.

6. Regular sources of information

Information is primarily collected from the customer themselves in connection with making a contract, in customer service situations, via online forms, or in other similar ways. Information may also be collected from public sources (e.g., the Business Information System).

7. Regular destinations of disclosed data

We do not sell or rent register data to external parties. Information may be disclosed to authorities within the limits permitted and obligated by valid legislation.

8. Transfer of data outside the EU or the EEA

As a rule, data is not transferred outside the EU or the European Economic Area. If technical implementation (e.g., cloud services) requires it, we ensure an adequate level of data protection as required by law.

9. Principles of register protection

Care is taken in the processing of the register, and the data processed by information systems is properly protected. Manual material is kept in locked premises. Digital material can only be accessed by authorized employees with personal user IDs and passwords.

10. Right of inspection

The data subject has the right to inspect the data stored in the register concerning them. The inspection request must be sent in writing to the person responsible for register matters.

11. Right to demand correction of information

The data subject has the right to demand the correction of incorrect information by contacting the data controller.