1. Data controller
Scene Arts Oy
358 44 501 0062
2. Contact person responsible for the register
Joonatan Niemi, firstname.lastname@example.org, 358 44 501 0062
3. Name of the register
Company customer register
4. Legal basis and purpose of processing personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is
– the consent of the individual (documented, voluntary, individual, informed and unambiguous)
– legitimate interest of the controller (customer relationship)
The purpose of processing personal data is to contact customers, to maintain customer relations and for marketing purposes. The data will not be used for automated decision-making or profiling.
5. Data content of the register
The information stored in the register includes: name of the person, company/organisation, contact details (telephone number, e-mail address), IP address of the network connection, information on ordered services and changes thereto, billing information, other information related to the customer relationship and ordered services.
6. Regular data sources
The information stored in the register is obtained from the customer through, for example, messages sent via web forms, e-mail, telephone, social media services, contracts, customer meetings and other situations where the customer provides his/her data.
7. Regular disclosures and transfers of data outside the EU or EEA
There is no regular disclosure of data to other parties. Data may be published to the extent agreed with the customer. Data may also be transferred outside the EU or EEA by the controller.
8. Principles for the protection of the register
The register will be processed with due care and the data processed by the computer systems will be adequately protected. Where the data are stored on Internet servers, the physical and digital security of the hardware is adequately ensured to the extent possible under the authority of the controller (the external service provider, such as the hosting provider, is responsible for the data protection of its own servers). The controller shall ensure that stored data, server access rights and other information critical to the security of personal data are treated confidentially and only by employees whose job description includes this.
9. Right of access and rectification
Any person in the register has the right to check the data recorded in the register and to request that any inaccurate or incomplete data be corrected or completed. If a person wishes to check or request the correction of data stored about him or her, the request must be sent in writing or electronically to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will reply to the customer within the time limits set by the EU General Data Protection Regulation (as a general rule, within one month).
10. Other rights related to the processing of personal data
A person in the register has the right to request the erasure of personal data concerning him or her from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of the processing of personal data in certain circumstances. Requests should be sent in writing or electronically to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits set by the EU GDPR (as a general rule, within one month).
This site uses different types of cookies. Some cookies are set by third party services that appear on our website. You can change or withdraw your consent on our site via the cookie notice.