Privacy Policy

Privacy Statement in Accordance with the Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR)

Created on 28.3.2019
Updated on 17.2.2021

1. Data Controller

Porttipuiston liikuntakeskus Oy (Fit Porttipuisto) (2917143-6)

2. Contact Person Responsible for the Register

Jon Wahrn
0503436434
jon.wahrn@ole.fit

3. Name of the Register

Fit Porttipuisto's customer and marketing register

4. Legal Basis and Purpose of Processing Personal Data

The legal basis for processing personal data under the EU General Data Protection Regulation is the individual's voluntary, documented consent, a contract in which the registrant is a party, or the legitimate interest of the data controller (customer relationship, employment, membership).

The purpose of processing personal data is to communicate with customers, maintain customer relationships, and for marketing.

5. Contents of the Register

The data stored in the register include: person's name, personal identification number, position, company/organization, contact details (phone number, email address, postal address), company website addresses, details of services ordered, billing information, and other customer relationship and ordered service related information.

The data are stored in the register for the duration of the customer relationship and for one year after its termination.

6. Regular Sources of Information

The data stored in the register are obtained from the customer via online forms, email, telephone, social media services, contracts, customer meetings, and other situations where the customer discloses their information.

7. Regular Disclosures of Data and Transfer of Data Outside the EU or EEA

We share your personal data with the following parties:

  • With the police for the investigation of crimes.
  • For marketing-related assignments with partners who analyze, print, or distribute marketing material.
  • Data may also be transferred by the data controller outside the EU or EEA.

If we transfer your data to our partners, they act as data processors under a cooperation agreement. Through the agreement, we obligate our partners to comply with the Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Partners are not allowed to use the register data for any purpose other than the agreed assignment with Fit Porttipuisto.

8. Principles of Register Protection

Care is taken in the processing of the register, and data processed via information systems are appropriately protected. When register data are stored on Internet servers, their physical and digital security is appropriately maintained.

Fit Porttipuisto ensures that the stored data, server access rights, and other critical information for data security are handled confidentially and only by those employees for whom it is part of their job description. Employees handling customer register data are bound by confidentiality.

9. Right of Inspection and Right to Request Correction of Data

Every individual in the register has the right to check their stored data and request correction of any incorrect data or completion of incomplete data. If a person wishes to check their stored data or request a correction, the request should be sent in writing to the data controller. The data controller may request the requester to prove their identity, if necessary.

The data controller responds to the customer within the time stipulated in the EU data protection regulation (generally within one month).

10. Other Rights Related to Processing of Personal Data

An individual in the register has the right to request the deletion of their personal data from the register. The registrant also has other rights under the EU General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests should be sent in writing to the data controller. The data controller may request the requester to prove their identity, if necessary.

The data controller responds to the customer within the time stipulated in the EU data protection regulation (generally within one month).