Billing Register 

Billing Register

Data Controller
TK Talous Oy (0925979-9)
Luvakuja 16
21260 Raisio

Contact Person for Register Matters
Kari Virtanen
kari.virtanen(at)tktalous.fi

Register
Billing Register

Date of Preparation
28 October 2024

Legal Basis for Processing
Contract and Legitimate Interest

Purpose of the Processing of Personal Data
The purpose of the register is to enable the delivery of invoices to customers. The data may also be used for the development of the Data Controller’s business operations. The legal basis for processing is Contract or Legitimate Interest.

Categories of Personal Data
• Personal data relating to representatives of B2B customer organisations.
• Personal data relating to B2C customers.

Recipients and Categories of Recipients
The Data Controller’s personnel and, where applicable, external service providers (including financial administration and debt collection service providers).

Contents of the Register
The Billing Register contains the following information:
• First name and surname
• Organisation represented (B2B)
• Email address
• Postal address
• Telephone number
• Pricing and payment information

Regular Sources of Personal Data
Personal data is obtained from customer registrations and from information provided by customers during the customer relationship. Updates to names and contact details may also be obtained from public authorities and companies providing data update services. Personal data may also be obtained from subcontractors involved in the provision or delivery of the service. The data contained in the Billing Register is used solely by the Data Controller, except where an external service provider is engaged to provide value-added services, billing services or credit assessment services. Personal data is not disclosed outside the Data Controller or made available to its cooperation partners except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The personal data of the data subject will be deleted at the data subject’s request unless legislation, outstanding invoices or debt collection procedures prevent the deletion of the data.

Retention Period for Personal Data
Personal data is retained for 10 years following the termination of the customer relationship.

Regular Disclosure of Personal Data
The data contained in the Billing Register is used solely within the Data Controller’s organisation, except where an external service provider is engaged to provide value-added services or credit assessment services. Personal data is not disclosed outside the Data Controller or made available to its cooperation partners except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The personal data of the data subject will be deleted at the data subject’s request unless legislation, outstanding invoices or debt collection procedures prevent the deletion of the data.

Transfers of Personal Data Outside the EU or EEA
Personal data contained in the register is not routinely transferred outside the European Union (EU) or the European Economic Area (EEA).
However, processing may involve service providers located outside the EU/EEA or cloud services hosted outside the EU/EEA. In such cases, transfers are carried out on the basis of the European Commission’s Standard Contractual Clauses (SCCs). In addition, supplementary safeguards have been implemented, including internal instructions regarding the pseudonymisation of personal data and equivalent protective measures, as well as, where required, a Transfer Impact Assessment (TIA).
Where personal data is transferred between the EU and the United States, the organisation processing the personal data must be certified under the EU–US Data Privacy Framework (DPF), which serves as the legal basis for such transfers for as long as the framework remains valid.

Principles of Register Protection
A. Manual Records
Contact details collected during customer interactions and other documents containing customer data that are processed manually are, following their initial processing, stored in locked and fire-resistant storage facilities. Only specifically authorised employees who have signed a confidentiality undertaking are entitled to process customer data stored in manual form. The protection and processing of the data contained in the register are carried out in accordance with the provisions and principles of data protection legislation, the requirements of the competent authorities, and good data processing practice.

B. Electronic Records
Only designated employees of the organisation and companies acting on its behalf are authorised to access and maintain the Billing Register. Each authorised user is provided with a personal username and password. Every user has signed a confidentiality undertaking. The system is protected by a firewall that safeguards it against unauthorised external access. The protection and processing of the data contained in the register are carried out in accordance with the provisions and principles of data protection legislation, the requirements of the competent authorities, and good data processing practice.

Cookies
We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer or other device. Cookies do not damage users’ computers or files. The primary purpose of cookies is to improve and personalise the visitor’s experience on the website, as well as to analyse and improve the functionality and content of the website. Information collected through cookies may also be used for targeted communications and marketing, and for optimising marketing activities.
A visitor cannot be identified solely by means of cookies. However, information obtained through cookies may be linked with other information provided by the user in another context, for example when the user completes a form on our website.

The following information may be collected through cookies:
• IP address of the visitor
• Date and time of the visit
• Pages viewed and time spent on those pages
• Browser used by the visitor

Your Rights
Visitors to our website may prevent the use of cookies at any time by changing their cookie preferences through the cookie banner. Certain web browsers also allow cookies to be disabled and previously stored cookies to be deleted. Please note that disabling cookies may affect the functionality of the website.

Right of Access to Personal Data
The data subject has the right to obtain confirmation as to what personal data concerning them is contained in the register. A request for access must be submitted in writing by contacting the Data Controller’s customer service or from a verifiable email address. The data subject also has the right to object to the processing and disclosure of their personal data for the purposes of direct advertising, distance selling, direct marketing, market research or opinion surveys by contacting the Data Controller’s customer service.

Right to Rectification
Personal data contained in the register that is inaccurate, unnecessary, incomplete or outdated in relation to the purposes of the processing must be rectified, erased or supplemented. A request for rectification must be submitted either by means of a written request bearing the data subject’s handwritten signature to the Data Controller’s customer service or from a verifiable email address. The request must specify which personal data is to be rectified and the grounds on which the request is based. The rectification shall be carried out without undue delay. The rectification shall be notified to the party from whom the inaccurate personal data was obtained or to whom the personal data has been disclosed. Where a request for rectification is refused, the person responsible for the register shall provide the data subject with a written certificate stating the reasons for the refusal. The data subject has the right to refer the matter to the Office of the Data Protection Ombudsman for consideration.

Right to Restriction of Processing
The data subject has the right to request the restriction of the processing of personal data, for example where the personal data contained in the register is inaccurate. Requests should be addressed to the person responsible for the register.

Right to Object
The data subject has the right to object to the processing of personal data relating to them and to request the rectification or erasure of their personal data. Requests may be addressed to the contact person for the register. Where you act as the contact person for a company or organisation, your personal data cannot be deleted during the customer relationship.

Right to Lodge a Complaint with the Supervisory Authority
If you consider that the processing of your personal data infringes the General Data Protection Regulation (GDPR), you have the right to lodge a complaint with the competent supervisory authority. You may also lodge a complaint with the supervisory authority in the Member State of your habitual residence or place of work.

Contact Details of the National Supervisory Authority
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, FI-00530 Helsinki, Finland
Postal address: P.O. Box 800, FI-00531 Helsinki, Finland
Telephone (switchboard): +358 29 566 6700
tietosuoja(at)om.fi
(https://tietosuoja.fi)

Other Rights Relating to the Processing of Personal Data
The data subject has the right to prohibit the disclosure and processing of their personal data for the purposes of direct marketing and other marketing activities, to request the anonymisation of personal data where applicable, and to exercise the right to be forgotten.

GDPR Compuance