Register and Privacy Statement

This is Loistepinta Oy's register and data protection statement in accordance with the EU General Data Protection Regulation (GDPR).


1. Registrar

Loistepinta Oy

Social security number 3329466-6

2. The contact person responsible for the register

Uula Lappalainen
uula.lappalainen@loistepinta.fi


3. Register name

Personal data register, which applies to Loistepinta Oy's personal data in sales, marketing and customer relations.

4. Legal basis and purpose of personal data processing

According to the EU's General Data Protection Regulation, the legal basis for processing personal data is the person's consent to provide their own data via the contact forms on the website.

The purpose of processing personal data is to provide website visitors with the services they need.

Cookies

The loistepinta.fi website uses cookies to improve the user experience, to collect information about the use of the website and to optimize customer communication. By using the website, the user must either accept or reject the use of cookies when visiting the website. In the cookie statement, "cookies" refer to cookies or similar technologies that comply with the requirements of the General Data Protection Regulation. When you visit our website, information can be collected e.g. from the visitor's computer, IP address, browser and server used. The use of cookies is based on the consent of the registered person on the website. Refusal to use cookies can affect the technical functionality of the sites and the smoothness of the site.

What is a cookie?

In this report, we will explain to you, among other things, the theory of cookies and tell you how our site uses cookies. Cookies are small text files created by an opened website. They are stored on the visitor's device so that the user can use the various functions of the website. Loistepinta Oy's website uses both session-specific, time-bound and permanent cookies. A session-specific cookie is temporarily stored in the computer's memory while the visitor browses the site. This cookie is deleted when the visitor closes the website or ends the session. A persistent cookie remains on the visitor's computer until it is deleted. The cookie text file in question cannot damage the computer in any way, and it cannot monitor or cause a privacy threat to the computer user.

5. Data content of the register

The following information can be stored in the register if the customer provides it: name, address, e-mail address, telephone number, apartment code, work warranty-related and other repair information, invoicing and payment information, information regarding marketing permission or prohibition, information generated in connection with opinion polls, information generated in connection with the use of the chat service free-form conversation information and information obtained in connection with the use of communication and other services.

IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to take care of information security and for the collection of statistical data of website visitors in those cases when they can be considered as personal data. If necessary, consent is requested separately for third-party cookies.

6. Regular sources of information

The information to be saved in the register is obtained from the customer, e.g. From messages sent via web forms, by e-mail, by phone, via social media services, contracts, customer meetings and other situations where the customer gives out their information.

Information about contact persons of companies and other organizations can also be collected from public sources such as websites, directory services and other companies.

7. Regular transfers of data and transfer of data outside the EU or EEA

Information is not regularly disclosed to other parties. Information can be published to the extent agreed with the customer.

Data can also be transferred by the controller outside the EU or EEA. Data will not be transferred to the United States without the express consent of the data subjects.

8. Principles of registry protection

Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.

9. Right of inspection and right to demand correction of information

Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

10. Other rights related to the processing of personal data

A person in the register has the right to request the removal of personal data about him from the register ("the right to be forgotten"). Those registered also have other rights according to the EU's General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

V09112023