Electronic Communications Register
Electronic Communications Register
Data Controller
TK Talous Oy (0925979-9)
Luvakuja 16
21260 Raisio
Contact Person for Register Matters
Kari Virtanen
kari.virtanen(at)tktalous.fi
Register
Electronic Communications Register
Date of Preparation
2024-10-28
Legal Basis for Processing
Legitimate Interest
Purpose of the Processing of Personal Data
The purpose of the register is to enable the electronic communications of the Data Controller’s organisation. The information collected (email addresses and any contact details or other personal data contained in email messages and their attachments) is used to establish and maintain customer relationships and to fulfil the other communication-related needs of the Data Controller.
Basis of Legitimate Interest
Direct marketing constitutes a Legitimate Interest of the Data Controller under the General Data Protection Regulation (GDPR). The Data Controller must process personal data in order to carry out activities related to its business operations. In this context, the processing of personal data cannot necessarily be justified on the basis of a legal obligation or a contract concluded with the individual. Following a Legitimate Interest Assessment (LIA), the Data Controller has concluded that Legitimate Interest is the most appropriate legal basis for processing, taking into account the nature and scope of the processing and the rights and freedoms of the data subjects. The Data Controller has assessed that processing based on Legitimate Interest does not cause significant harm to the rights and freedoms of the individuals concerned (data subjects).
Categories of Personal Data
Electronic contact details.
Recipients and Categories of Recipients
The Data Controller’s personnel and, where applicable, outsourced service providers (financial administration, IT administration, etc.), as well as communication parties.
Contents of the Register
The personal data register contains the following information:
• First name and surname
• Represented organisation
• Email address
• Postal address
• Telephone number
• Information relating to previous orders
• Information relating to communications between correspondents
• Other personal data that may be contained in attachments
Regular Sources of Personal Data
Information is obtained from email messages received from customers. Information may also be obtained from other stakeholders, for example through mass communications, communication groups, forwarded messages or similar communication situations. Personal data are not disclosed outside the organisation maintaining the register or to its partners, except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The data subject’s personal data will be deleted at the request of the data subject unless legislation, the ability to manage the customer relationship, outstanding invoices or debt collection procedures prevent their deletion.
Retention Period for Personal Data
Personal data are retained for ten years.
Regular Disclosure of Personal Data
The information contained in the email register is used solely by the Data Controller, except where an external service provider is engaged to provide value-added services or to support credit decision-making. Personal data are not disclosed outside the Data Controller’s organisation or to its partners, except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The data subject’s personal data will be deleted at the request of the data subject unless legislation, the ability to manage the customer relationship, outstanding invoices or debt collection procedures prevent their deletion.
Transfers of Personal Data Outside the EU or EEA
The information contained in the register is not regularly transferred outside the European Union (EU) or the European Economic Area (EEA).
However, it is possible that processing involves service providers located outside the EU/EEA or that the cloud services used by service providers are located outside the EU/EEA. In such cases, transfers are based on the European Commission’s Standard Contractual Clauses (SCCs).
Additional safeguards have also been implemented for such transfers, including internal guidance on the pseudonymisation of personal data and similar protective measures, as well as, where necessary, a Transfer Impact Assessment (TIA).
Where an organisation processing personal data has committed to the EU–US Data Privacy Framework (DPF), this will be used as the legal basis for the transfer for as long as the framework remains in force.
Principles of Register Protection
A: Manual Records
Documents containing customer information that are processed manually (for example, printed emails or their attachments) are stored, following their initial processing, in locked and fire-resistant storage facilities. Only specifically authorised employees who have signed a confidentiality agreement are entitled to process manually stored customer information.
B: Electronic Records
Only specifically authorised employees of the organisation and companies acting on its behalf are entitled to use the email system and maintain its data. Each authorised user has a personal username and password. Every user has signed a confidentiality agreement. The system is protected by a firewall that safeguards it against unauthorised external access. Access to any multifunction devices, such as scanners, and to any information stored on them is restricted where appropriate.
Cookies
We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not damage users’ computers or files. The primary purpose of cookies is to improve and personalise the visitor’s experience of the website, as well as to analyse and improve the website’s functionality and content. Information collected through cookies may also be used to target communications and marketing activities and to optimise marketing measures. Visitors cannot be identified solely by means of cookies. However, information obtained through cookies may be linked to information that the user has provided in another context, for example when completing a form on our website.
The following information may be collected through cookies:
• Visitor’s IP address
• Date and time of the visit
• Pages viewed and time spent on those pages
• Visitor’s web browser
Your Rights
Visitors to our website may prevent the use of cookies at any time by changing their preferences in the cookie banner. Some web browsers also allow cookies to be disabled and previously stored cookies to be deleted. Disabling cookies may affect the functionality of the website.
Automated Decision-Making and Profiling
Personal data are not processed by automated means.
Right of Access to Personal Data
The data subject has the right to verify what personal data relating to them are contained in the register. A request for access must be submitted in writing or sent from a verifiable email address. The data subject has the right to prohibit the processing and disclosure of their personal data for the purposes of direct advertising, distance selling, direct marketing, market research and opinion surveys by contacting the Data Controller’s customer service.
Right to Data Portability
Where the processing is based on Consent or a Contract, the data subject has the right to transfer their personal data from one system to another. Requests relating to data portability may be addressed to the contact person for the register.
Right to Request Rectification of Data
Personal data contained in the register that are incorrect, unnecessary, incomplete or outdated in relation to the purpose of the processing must be rectified, erased or completed. A request for rectification must be submitted in writing, signed by hand, to the Data Controller’s customer service or sent from a verifiable email address. The request must specify which data are to be rectified and the grounds on which the rectification is requested. The rectification shall be carried out without undue delay. The party from whom the incorrect data were obtained, or to whom the data were disclosed, shall be notified of the rectification. If a request for rectification is refused, the person responsible for the register shall provide a written certificate stating the reasons for the refusal. The data subject may refer the refusal to the Office of the Data Protection Ombudsman for consideration.
Right to Restriction of Processing
The data subject has the right to request the restriction of processing, for example if the personal data contained in the register are inaccurate. Requests should be addressed to the person responsible for the register.
Right to Object
The data subject has the right to request access to the personal data concerning them and has the right to request the rectification or erasure of their personal data. Requests may be addressed to the contact person for the register. If you act as the contact person for a company or organisation, your personal data cannot be erased during this period.
Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data infringes the General Data Protection Regulation (GDPR), you have the right to lodge a complaint with the supervisory authority. You may also lodge a complaint with the supervisory authority in the Member State where you have your habitual residence or place of work.
Contact Details of the National Supervisory Authority
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, FI-00530 Helsinki
Postal address: P.O. Box 800, FI-00531 Helsinki
Telephone (switchboard): +358 29 566 6700
tietosuoja(at)om.fi
(https://tietosuoja.fi)
Other Rights Relating to the Processing of Personal Data
The data subject has the right to prohibit the disclosure and processing of their personal data for direct marketing and other marketing purposes, to request the anonymisation of their personal data where applicable, and to exercise the right to be forgotten.

