Registry and Privacy Statement
This is Storico Oy's registry and Privacy Statement in accordance with the EU's General Data Protection Regulation (GDPR). Prepared on 01.03.2022. Last modified: 07.03.2022.
Business ID 2774969-5
Kaivokatu 15 B 29, 20520 Turku
2. Contact person responsible for the register
Thomas Schleutker, email@example.com, telephone number: +358 400 261344
3. Name of the register
This Privacy Statement covers all of Storico Ltd's registers in which personal data are processed. These registers are customer and marketing registers.
4. Legal basis and purpose of the processing of personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is
- the consent of the person
- an agreement to which the data subject is a party
- a legitimate interest of the controller (e.g. pre-contractual customer relationship, employment relationship, membership).
The purpose of processing personal data is to communicate with customers, maintain a customer relationship and market.
5. Information content of the register
The information to be stored in the register is: person's name, position, company / organization, contact information (telephone number, e-mail address, address), website addresses, network connection IP address, information about subscribed services and their changes, billing information, other customer relationship and subscriptions information related to the services.
The information stored in the register is used to maintain the customer and marketing register.
We will process your personal information for as long as the customer agreement for which we need your personal information is valid. Your personal information may then be used for marketing and other purposes mentioned above. We will remove your personal information from our register at your request or when the information is no longer necessary for our purposes.
You always have the right to prohibit us from using your personal information for direct marketing purposes by using the cancellation option provided in connection with direct marketing messages or by notifying us.
The IP addresses of the visitors of the website and the cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to ensure data security and to collect statistics about visitors to the site in cases where they may be considered personal data. If necessary, the consent of third-party cookies will be requested separately.
6. Regular sources of information
The information stored in the register is obtained from the customer e.g. Messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information.
Contact information for companies and other organizations can also be collected from public sources such as websites, directory services, and other companies.
7. Regular transfers of data and transfers of data outside the EU or the EEA
Data will not be regularly transferred to other parties. The information may be published to the extent agreed with the customer.
The data may also be transferred by the controller outside the EU or the EEA.
In addition, we may disclose your personal information to third-party service providers authorized by Storico Ltd, who process the information on our behalf and on our behalf. The transfer is based on an agreement binding on the parties and data protection commitments.
8. Registry Security Principles
The register shall be handled with due care and the data processed by the information systems shall be adequately protected. When registry data is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it belongs to.
9. Right of inspection and right to request rectification of information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check or request the rectification of data stored about him or her, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
10. Other rights related to the processing of personal data
A person in the register has the right to request the removal of his or her personal data from the register ("right to be forgotten"). Data subjects also have other rights under the EU's general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).