This is the register and Data Protection Statement in accordance with SCT Events Oy's Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR).
1. The controller
SCT Events Oy
2. Contact person responsible for the register
3. Name of the register
SCT Events Oy's customer register
4. Legal basis and purpose of the processing of personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is the legitimate interest of the controller and / or the consent of the person.
The purpose of personal data processing is customer communication and customer service, customer relationship maintenance and data management, marketing and identification of event-related services to the customer.
5. Information content of the register
The information to be stored in the register is:
- personal data (name, date of birth, nationality and sex)
- contact information (phone number, email address and address)
- network connection IP address, IDs / profiles in social media services
- registration information and / or information about the ordered services and their changes, as well as billing information related to the order
- other information related to the customer relationship and the services ordered
The retention period for personal data is two years, after which the data will be anonymised.
6. Regular sources of information
The information stored in the register is obtained from the customer e.g. website registration, ordering or contact forms, email, telephone, via social media services, contracts, customer appointments and other situations in which a customer discloses their information.
7. Regular transfers of data and transfers of data outside the EU or the EEA
The information is not regularly disclosed to other parties. The information may be published to the extent agreed with the customer.
Data may also be transferred by the controller outside the EU or the EEA.
Personal data may be disclosed to SCT Events Oy's commercial or non-commercial partners in order to provide the service.
8. Registry Security Principles
The register shall be handled with due care and the data processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it includes.
9. Right of inspection and right to request correction of information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check the data stored about him or to request a correction, the request must be sent by e-mail to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The data controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
10. Other rights related to the processing of personal data
A person in the register has the right to request the removal of his or her personal data from the register ("the right to be forgotten"). Likewise, registrants have othersRights under the EU General Data Protection Regulationsuch as restricting the processing of personal data in certain situations. Requests should be emailed to the registrar. If necessary, the controller may ask the applicant to prove his or her identity. The data controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).