Customer register B2C

Privacy policy
Last updated
20.03.2024

Registrar

Oy Duell Bike-Center Ab (2464132-0)
Kauppatie 19
65610 Mustasaari

Contact person in matters concerning the register

Sami Ilvonen sami.ilvonen (at) duell.eu

Legal basis for processing

Contractual

Purpose of personal data processing

The purpose of the filing system is the maintenance of the company’s customer register, managing customer orders, data filing and processing, and the maintenance of customer relations. Information can be used to improve the company’s operation, for statistical purposes, and for producing more personalised content in our online services. Personal data are processed in accordance with the requirements of the Personal Data Act. Data in the filing system can be used in the company’s own filing systems for example for targeted advertising without disclosing personal data to external parties. The company may use partners to maintain customer and service relationships, which means that part of the data held within the filing system may be transferred onto a partner’s server due to technical requirements. These data will be processed solely for the purpose of maintaining the company’s customer relationships using technical interfaces. The company has the right to publish data contained in the customer register as an electronic or written list unless the customer especially prohibits this. In this case a list means for example address labels used for direct mail advertising. The customer has the right to prohibit the publication of data by notifying the company’s customer service by email (email address) or by contacting the filing system’s contact person.

Basis of legitimate interest

Processing is not based on legitimate interest

The personal data groups in question

Name, contact details, billing information.

Recipients and recipient groups

The data controller’s personnel and outsourcing partners when applicable.

Data content of the register

Personal data filing system contains the following information: - First and last name of person - Email address - Postal address - Phone number - Information on previous orders

Regular sources of information

Data are obtained during a customer’s purchase in a company’s shop, online service or retailer, or from client notifications when a customer uses a service provided by the company. Data are obtained from registrations made by the customer as well as other notifications received during the course of the customer relationship. Updates to names and contact information are also received from authorities and companies providing update services. Data can also be obtained from subcontractors related to the use or production of a specific service. 
Data on the customers’ other activities in the digital environment can be obtained from partner websites, data systems or other digital sources using electronic sign-in (link), cookies or customer-specific identifiers. The data stored in the customer register are used solely by the company, except when an external service provider is used either to provide added value services or to support credit-related decision-making. Data will not be disclosed to external parties or to the company’s partners except for purposes related to credit applications, debt collection or invoicing as well as in situations required by law. Personal data will not be transferred outside the European Union unless necessary for ensuring the technical implementation of the company’s or its partners’ activities. A data subject’s personal data will be removed upon the data subject’s request unless such removal is prohibited by legislation, outstanding invoices, or debt collection.

Personal data retention period

10 years from the end of the customer relationship.

Regular transfers of information

The data stored in the customer register are used solely by the company, except when an external service provider is used either to provide added value services or to support credit-related decision-making. Data will not be disclosed to external parties or to the company’s partners except for purposes related to credit applications, debt collection or invoicing as well as in situations required by law. A data subject’s personal data will be removed upon the data subject’s request unless such removal is prohibited by legislation, outstanding invoices, or debt collection.

Data transfer outside the EU or EEA

The data in the register will be transferred outside the EU or EEA to the UK. It is also possible that service providers outside the EU/EEA are used for processing or that the clouds of service providers are located outside the EU/EEA, in which case SCC standard clauses are used as the basis for data transfer and additional safeguards are implemented for data transfers, such as internal guidelines (on pseudonymisation of personal data and the like) and possibly TIA analysis where appropriate.

Principles of register protection A: Manual material

Contact information collected during customer events and other manually processed documents containing customer data are stored in a locked and fireproof space after initial processing. Only specific employees who have signed confidentiality agreements have the right to process manually stored customer data. The protection and processing of data in the register complies with the provisions and principles of the Data Protection Act, regulations of the authorities and good data processing practice.

Principles of register protection B: Electronic material

Only specific employees working for or on behalf of the company have the right to use the customer-owner or customer register and maintain data stored in it. Each specific user has his or her personal username and password. Each user has signed a confidentiality agreement.
The system is protected by a firewall to prevent external attacks on the system. The protection and processing of data in the register complies with the provisions and principles of the Data Protection Act, regulations of the authorities and good data processing practice.

Cookies

We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not cause any harm to the user’s computer of files. The primary purpose for the use of cookies is to improve and personalise a visitor’s user experience on our website as well as to analyse and improve the functionality and content of our site. Data collected with cookies can also be used in targeted communication and marketing as well as optimising marketing activities. Visitors cannot be identified based solely on cookies. However, data collected with cookies can be linked with possible data received from the user in other situations, for example when the user fills in a form on our website. The following types of data are collected using cookies: - visitor’s IP-address - time of visit - browsed pages and time of browsing - visitor’s browser Your rights A user visiting our website has the right to prohibit the use of cookies at any time by changing his or her browser settings. Most browser software give the option of disabling cookies and of removing cookies that have already been saved. Disabling cookies may affect the functionality of the website.

Inspection right, i.e. the right to get access to personal data.

The data subject has the right to check what data has been stored about him or her in the filing system. A request for data access must be given in writing by contacting the company’s customer service or the filing system’s contact person either in Finnish or English. The request for data access must be signed.
The data subject has the right to prohibit the processing of his or her data and its disclosure for the purposes of direct marketing, distance marketing or opinion polls by contacting the company’s customer service.

The right to transfer data from one system to another

Data subjects do not have the right to transfer their data from one system to another.

The right to demand correction of information

Taking into account the purposes of processing, any data stored in the filing system that is inaccurate, unnecessary, incomplete, or outdated must be erased or rectified. A written request for rectification, signed by hand, should be sent to the company’s customer service or the personal data filing system’s administrator. The request should specify what information should be rectified and on what grounds. Rectification shall be carried out without delay. Notification of rectification will be sent to the party who provided the inaccurate data or to whom the data were disclosed. If a request for rectification is denied, the responsible person of the filing system will provide a written document stating the grounds for the denial of the request for rectification. The data subject concerned may then pass the matter along to the Data Protection Ombudsman.

Right of limitation

The data subject has the right to request restriction of processing, for example if the personal data in the register are inaccurate. Contact the person responsible for the register.

Right to object

The data subject has the right to request personal data concerning him or her and the right to request the rectification or erasure of personal data. Such requests may be addressed to the contact person of the register. If you are the contact person of a company or organisation, your data cannot be deleted during this period.

The right to file a complaint with the supervisory authority

If you consider that an infringement of the General Data Protection Regulation has occurred in the processing of your personal data, you have the right to lodge a complaint with a supervisory authority. The complaint can also be lodged in a member state where you are a permanent resident or where you are employed. Contact information for the Finnish national supervisory authority: Office of the Data Protection Ombudsman PL 800, Lintulahdenkuja 4, 00530 Helsinki tel. +358 29 566 6700 tietosuoja@om.fi www.tietosuoja.fi/en/

Other rights related to the processing of personal data

Data subjects have the right to object to the disclosure and processing of their data for direct marketing and other marketing purposes, to request that their data be made anonymous where applicable, and to be completely forgotten.