Website visitors

Privacy policy
Last updated
22.11.2023

Registrar

Cardirad Oy (2246563-4)
Pajakatu 5
08150 Lohja Finand

Contact person in matters concerning the register

Cardirad OY Pajakatu 5 08100 Lohja Finland GDPR@cardirad.com

Purpose of personal data processing

The purpose of the filing system is to ensure the security of the company’s website. Collected data (IP address) is only used in the event investigations related to faults or data breaches. The basis of processing is legitimate interest of the data controller.

Basis of legitimate interest

The data controller’s legitimate interest for processing collected and used personal data is based on the freedom to engage in commercial activity.

Recipients and recipient groups

Limited, authorised personnel of the website administration server provider.

Data content of the register

Personal data filing system contains the following information: - IP address - time of visit to website - pages visited by the visitor

Regular sources of information

Data are obtained from the customer when they visit the organisation’s website.

Personal data retention period

The data are never separately removed from the webserver.

Regular transfers of information

The data contained in the filing system is only available to the company, except when an external service provider is used, in which case the service provider in question is given access to the data. Data are not disclosed outside the company or its partners, except in the case of investigations related to data breaches or other similar events.

Data transfer outside the EU or EEA

Personal data will not be transferred outside the European Union unless necessary for ensuring the technical implementation of the company’s or its partners’ activities.

Principles of register protection B: Electronic material

Only specific employees working for or on behalf of the company have the right to use the website administration server. Each specific user has their personal username and password. Each user has signed a confidentiality agreement. The system is protected by a firewall to prevent external attacks on the system.

Cookies

We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not cause any harm to the user’s computer or files. The primary purpose for the use of cookies is to improve and personalise a visitor’s user experience on our website as well as to analyse and improve the functionality and content of our site. Data collected with cookies can also be used in targeted communication and marketing as well as optimising marketing activities. Visitors cannot be identified based solely on cookies. However, data collected with cookies can be linked with possible data received from the user in other situations, for example when the user fills in a form on our website. The following types of data are collected using cookies: - visitor’s IP address - time of visit - browsed pages and time of browsing - visitor’s browser Your rights A user visiting our website has the right to prohibit the use of cookies at any time by changing their browser settings. Most browser software give the option of disabling cookies and of removing cookies that have already been saved. Disabling cookies may affect the functionality of the website. GOOGLE ANALYTICS Usage statistics are collected from the website using the Google Analytics service, the purpose of which is to monitor site activity as well as to develop the site and its marketing. The data collected cannot be linked to individual users or persons. Additionally, we collect Google Analytics Demographics data, which includes for example the age and gender of the visitor as well as topics of interest. Settings related to the collection of these data can be changed using your personal Google account at https://www.google.com/settings/ads Google Analytics monitoring can be disabled with a Chrome add-on.

Automatic processing and profiling

The results of data processing are not used for profiling or other related purposes.

Inspection right, i.e. the right to get access to personal data.

The data subject has the right to check what data has been stored about them in the filing system. Request for access must be made in writing by contacting the company’s customer service or the contact person of the filing system in Finnish or English. The request for data access must be signed. The data subject has the right to prohibit the processing of their data and its disclosure for the purposes of direct marketing, distance marketing or opinion polls by contacting the company’s customer service. The data controller has the right to issue an invoice if costs are incurred by carrying out the request.

The right to transfer data from one system to another

The data subject has the right to transfer their personal data from one system to another. Request of transfer can be sent to the contact person of the filing system.

The right to demand correction of information

Taking into account the purposes of processing, any data stored in the filing system that is inaccurate, unnecessary, incomplete, or outdated must be erased or rectified. The written and signed request for rectification should be sent to the company’s customer service or the personal data filing system’s administrator. The request should specify what information should be rectified and on what grounds. Rectification shall be carried out without delay. Notification of rectification will be sent to the party who provided the inaccurate data or to whom the data were disclosed. If a request for rectification is denied, the responsible person of the filing system will provide a written document stating the grounds for the denial of the request for rectification. The data subject concerned may then pass the matter along to the Data Protection Ombudsman.

The right to file a complaint with the supervisory authority

If you consider that an infringement of the General Data Protection Regulation has occurred in the processing of your personal data, you have the right to lodge a complaint with a supervisory authority. The complaint can also be lodged in a member state where you are a permanent resident or where you are employed. Contact information for the Finnish national supervisory authority: Office of the Data Protection Ombudsman PL 800, Lintulahdenkuja 4, 00530 Helsinki tel. +358 29 566 6700 tietosuoja@om.fi www.tietosuoja.fi/en/

Other rights related to the processing of personal data

Right to restrict processing The data subject has the right to request that the processing of their personal data is restricted for example if data stored in the filing system is erroneous. Requests should be sent to the responsible person of the filing system. Right to object The data subject has the right to request for personal data pertaining to them, and the data subject has the right to request for the rectification or erasure of said data. Request can be sent to the contact person of the filing system. If you are acting as the contact person of a company or organisation, your data cannot be erased during this time. The data subject has the right to prohibit the disclosure of processing of personal data for the purposes of direct marketing or other marketing, the right to demand the anonymization of data where applicable, as well as the right to be completely forgotten.