This is Siimli Oy's register and privacy policy in accordance with the EU's General Data Protection Regulation (GDPR). Prepared on January 1, 2025. Last updated on January 7, 2025.
Siimli Oy Ulvilantie 29
00350 HELSINKI Finland
Business ID: 3460932-4
Contact information for matters concerning the register:
Siimli Oy
+358 50 3802608
Customer Register
Personal data is processed for managing the customer relationship, fulfilling contracts, and developing the service. The processing is based on our legitimate interest in maintaining active customer relationships, providing services that meet customer needs, processing orders and contracts, and developing our business. In some cases, the processing is based on the data subject's voluntary consent, which the data subject can withdraw at any time.
Purpose of Processing Personal Data and Use of the Register
Personal data is processed for the following predefined purposes: providing the service and managing the customer relationship (including service delivery, communication, maintaining customer information, managing contracts, and invoicing), analyzing service usage (statistics and research), targeting advertising, and developing services (planning new features and functionalities).
Our customer register may contain the following information:
The data subject has the following rights, requests for the exercise of which should be sent to info@siimli.com:
As a rule, information is obtained directly from the data subject themselves, for example, when a customer relationship begins, through online forms, when using services, in customer service situations, or in other direct contacts.
We may also collect and update personal data from public and generally available sources, such as the trade register, the Finnish Patent and Registration Office (PRH), or the Tax Administration. We may also receive information from third parties, such as credit information companies and marketing partners, if the data subject has given consent for the disclosure of their data for marketing purposes.
Personal data is not primarily disclosed to other parties. However, data may be disclosed with the customer's consent, when required by law, or to service providers necessary for the implementation of our services. We only disclose the necessary information for each purpose. Such service providers include IT service providers (server maintenance, software provision), marketing and sales service providers (email marketing, analytics), payment service providers (online payment processing), debt collection agencies (invoice collection), law firms (legal advice), and cloud service providers (data storage). Our service providers comply with data protection legislation.
Care is taken in the processing of personal data, and appropriate data security measures are implemented. Information systems and data stored on internet servers are appropriately protected by physical and digital security measures. Only authorized employees process data confidentially. We regularly assess the necessity of data retention in accordance with legislation. During the customer relationship, data is generally processed, and invoicing data is retained in accordance with the Accounting Act.
Personal data is processed by the data controller and its employees who, by virtue of their work, have the right to process customer data. We may also outsource the processing of personal data in part to a third party, in which case we ensure through contractual arrangements that personal data is processed in accordance with applicable data protection legislation and otherwise appropriately. Such parties include accounting firms, IT support, or other outsourced services of the company that have access to information systems. Data is collected in databases that are protected by firewalls, passwords, and other technical means.
In some cases, data may be regularly transferred outside the EU or the European Economic Area if we use service providers located outside the EU/EEA. If data is transferred outside the EU and EEA, we ensure an adequate level of protection for personal data, among other things, by agreeing on matters related to the confidentiality and processing of personal data in the manner required by law. We always ensure that there is an appropriate legal basis for the transfer and that the level of data protection is adequate.
We do not use automated decision-making based solely on automated processing, which has legal effects on the data subject or otherwise significantly affects them.
Siimli Oy reserves the right to change the content of this privacy policy without separately notifying the data subject. It is the data subject's responsibility to review the content of the privacy policy regularly.
Every person in the register has the right to check their data stored in the register and demand the correction of any incorrect information or the completion of incomplete information. A person in the register has the right to request the deletion of their personal data from the register. Requests should be sent to the data controller. The data controller may, if necessary, ask the requester to prove their identity.