Merima Ltd (0678168-8)
Tatti 10
00760 Helsinki
Minna Mäkiranta-Blyth
tietosuoja@merima.fi
Supplier register
2026-03-09
Legitimate Interest
The purpose of the register is to carry out activities related to the organisation’s cooperation arrangements, procurement and subcontracting, as well as to manage supplier and partner relationships. Personal data is processed for the preparation, conclusion, maintenance, performance, archiving and other administration of contracts, as well as for the management and development of partnership relationships.
Personal data may also be used for registering and maintaining supplier information in the controller’s procurement, contract management and financial administration systems, such as supplier and invoicing systems. In addition, the data is used to assess suppliers’ suitability and eligibility, to comply with statutory obligations (such as those related to accounting and tax legislation), for invoicing and payment processing, communication, handling complaints and potential disputes, as well as for the organisation’s risk management and the prevention of misconduct.
The data may also be used for the development of the company’s operations and for statistical purposes.
The organisation may use partners and subcontractors (for example, IT and system service providers) to maintain customer and service relationships. In such cases, personal data may be transferred to and processed on the partners’ servers to the extent required by technical and operational requirements.
The processing is based on the controller’s legitimate interest (GDPR Article 6(1)(f)), which relates to the management of supplier and contractual relationships, the implementation of procurement processes, communication with suppliers’ contact persons, as well as business planning, development, and the documentation and archiving of operations.
The controller has assessed that the processing based on legitimate interest does not override the rights or freedoms of the data subject, as the data processed relates to the data subject’s professional role and the processing is limited to what is necessary.
The following categories of personal data are processed in the register:
– Name of the contact person
– Job title and employer / represented organisation
– Contact details (email address, telephone number, postal address)
– Data related to the contractual relationship and transactions (e.g. invoicing references, contact persons)
The controller’s personnel and, where applicable, external service providers and outsourcing partners (including financial administration, IT services, debt collection, etc.).
The supplier register contains the following data:
– First and last name of the individual
– Represented entity
– Job title
– Business ID
– Email address
– Postal address
– Telephone number
– Other business‑related matters agreed between the parties
Personal data is primarily collected from the data subjects themselves, for example through data collection forms sent to suppliers, as well as via email, telephone and other electronic means of communication.
In addition, data may be obtained from public sources, such as company websites and business information services, insofar as the data relates to the data subject’s professional role.
Data may also be obtained from subcontractors or other cooperation partners where necessary for the fulfilment of contractual obligations or for the provision of services.
Personal data contained in the supplier register is retained only for as long as necessary for the management of contractual relationships, the fulfilment of statutory obligations (including obligations under accounting legislation), or the handling of potential disputes and debt collection matters. The data is retained for a maximum period of ten (10) years from the termination of the contract.
If no contractual relationship is established with the supplier or if the cooperation otherwise does not continue, personal data will be retained at most until the year 2028 for the purposes of documenting procurement and cooperation processes, internal control, and the assessment of potential legal claims.
In connection with a system renewal to be implemented in 2028, the data will be transferred to the new system only to the extent that it remains relevant and necessary for the purposes of processing. All other data will be deleted or anonymised as appropriate.
The data contained in the register is used solely by the controller, except where an external service provider is used for the provision of value‑added services.
The data is not disclosed outside the organisation or made available to its cooperation partners, except in matters related to debt collection or invoicing, or where disclosure is required by law.
The personal data of the data subject will be deleted at the data subject’s request unless deletion is prevented by applicable legislation, outstanding invoices, or ongoing debt collection measures.
The data contained in the register is not routinely transferred outside the EU or the EEA. However, it is possible that service providers located outside the EU/EEA are used for processing, or that the service providers’ cloud services are located outside the EU/EEA. In such cases, the transfer of data is based on the use of Standard Contractual Clauses (SCCs), and supplementary safeguards have been implemented for the data transfers, such as internal guidelines (including pseudonymisation of personal data and similar measures) and, where required, a Transfer Impact Assessment (TIA).
Where the organisation processing personal data is committed to the EU–US Data Privacy Framework (DPF), that framework is used as the transfer mechanism for the duration of its validity.
Any documents containing personal data in manual form (for example, contact details collected in connection with cooperation, meetings or events, or other related documents) are stored after processing in locked and appropriately secured facilities. Such data may only be processed by employees who are authorised to do so based on their duties and who are subject to a confidentiality obligation.
In the processing and protection of the personal data contained in the register, applicable data protection legislation, guidance issued by competent authorities, and good data processing practices are complied with.
Only designated employees of the organisation and of companies acting on its behalf are authorised to access and maintain the supplier and contract register and its data. Each authorised user has a personal user ID and password. All users have signed a confidentiality undertaking.
The system is protected by a firewall that safeguards the system against external access attempts.
In the protection and processing of the data contained in the register, the provisions and principles of data protection legislation, instructions issued by authorities, and good data processing practices are complied with.
We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not cause any harm to the user’s computer of files. The primary purpose for the use of cookies is to improve and personalise a visitor’s user experience on our website as well as to analyse and improve the functionality and content of our site.
Data collected with cookies can also be used in targeted communication and marketing as well as optimising marketing activities. Visitors cannot be identified based solely on cookies. However, data collected with cookies can be linked with possible data received from the user in other situations, for example when the user fills in a form on our website.
The following types of data are collected using cookies:
- visitor’s IP-address
- time of visit
- browsed pages and time of browsing
- visitor’s browser
- other?
Your rights
A user visiting our website has the right to prohibit the use of cookies at any time by changing his or her browser settings. Most browser software give the option of disabling cookies and of removing cookies that have already been saved.
Disabling cookies may affect the functionality of the website.
GOOGLE ANALYTICS
We collect user statistics from our website using the Google Analytics service, the purpose of which is to monitor site activity, improve site functionality and develop marketing. The data collected cannot be linked to individual users or persons.
Additionally, we collect Google Analytics Demographics data, which includes for example the age and gender of the visitor as well as topics of interest. Settings related to the collection of these data can be changed using your personal Google account at https://www.google.com/settings/ads
Google Analytics -monitoring can be disabled with a Chrome add-on.
Data is not subject to automated decision-making or profiling that produces legal or similarly significant effects on individuals.
The data subject has the right to access and review the personal data concerning them that is contained in the register. A request for access must be submitted in writing or from an email address that allows reliable identification of the data subject.
The data subject has the right to object to the processing and disclosure of their personal data for the purposes of direct marketing, distance selling and other direct marketing activities, as well as for market and opinion research, by contacting the company’s customer service.
The data subject does not have the right to data portability, as the processing of personal data is based on the controller’s legitimate interest and not on the data subject’s consent or the performance of a contract.
Personal data contained in the register that is inaccurate, unnecessary, incomplete or outdated in relation to the purpose of processing must be rectified, erased or supplemented.
A request for rectification must be submitted either as a written request signed by hand and addressed to the company’s customer service, or from an email address that allows reliable identification of the data subject.
The request must specify which data is requested to be rectified and on what grounds. Rectification will be carried out without undue delay.
The rectification of erroneous data will be notified to the party from whom the incorrect data was obtained or to whom the data has been disclosed. If a rectification request is refused, the person responsible for the register will provide a written certificate stating the reasons for the refusal. The data subject may refer the refusal to the Data Protection Ombudsman for resolution.
The data subject has the right to request the restriction of processing in accordance with Article 18 of the GDPR, for example if the personal data contained in the register is inaccurate. Requests should be addressed to the person responsible for the register.
The data subject has the right to request access to personal data concerning them, as well as the right to request the rectification or erasure of personal data. Requests may be addressed to the contact person responsible for the register.
Where the data subject acts as a contact person for a company or organisation, their personal data cannot be erased for the duration of that role.
If you consider that the processing of your personal data infringes the General Data Protection Regulation, you have the right to lodge a complaint with a supervisory authority. The complaint may also be lodged in the Member State of your habitual residence or place of work.
The contact details of the national supervisory authority are as follows:
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, 00530 Helsinki
Postal address: P.O. Box 800, 00531 Helsinki
Telephone exchange: +358 29 566 6700
Registry: +358 29 566 6768
tietosuoja@om.fi
www.tietosuoja.fi