B2B Customer Register
B2B Customer Register
Data Controller
TK Talous Oy (0925979-9)
Luvakuja 16
21260 Raisio
Contact Person for Register Matters
Kari Virtanen
kari.virtanen(at)tktalous.fi
Register
B2B Customer Register
Date of Preparation
2024-10-28
Legal Basis for Processing
Legitimate Interest
Purpose of the Processing of Personal Data
The purpose of this register is to maintain the Data Controller’s B2B customer register, process and administer customer orders, manage customer relationships, and support the provision of services. Personal data may also be processed for the development of business operations, statistical analysis, customer communication and, where applicable, the delivery of personalised content through the organisation’s online services. Personal data are processed only for specified, explicit and legitimate purposes and in accordance with the General Data Protection Regulation (GDPR) and applicable data protection legislation.
The Data Controller may use carefully selected service providers to support customer relationship management and the provision of services. Where technically necessary, personal data may be processed on the systems of such service providers acting on behalf of the Data Controller under appropriate contractual safeguards. Personal data are not disclosed to third parties except where required by law or where necessary for the provision of the services, debt collection, invoicing or other legitimate business purposes.
Where applicable, customer contact information may be published in an electronic customer directory unless the customer has objected to such publication. Customers may object at any time by contacting the Data Controller's customer service or the contact person responsible for the register.
Basis of Legitimate Interest
The Data Controller’s legitimate interest in processing personal data is based on the need to conduct and develop its business operations, establish and maintain customer relationships, and communicate with customers and potential customers. The Data Controller must process personal data in order to carry out activities necessary for its business operations. In these circumstances, the processing of personal data cannot always be based on a legal obligation or a contract with the data subject.
Following a Legitimate Interest Assessment (LIA), the Data Controller has concluded that Legitimate Interest is the most appropriate legal basis for processing, taking into account the nature and scope of the processing and the rights and freedoms of the data subjects. The Data Controller has assessed that processing based on Legitimate Interest does not cause significant harm to the rights and freedoms of the individuals concerned (data subjects).
Categories of Personal Data
Personal data relating to individuals representing corporate customers.
User information relating to the above.
Recipients and Categories of Recipients
The Data Controller’s personnel and, where applicable, outsourced service providers (financial administration).
Contents of the Register
The personal data register contains the following information:
• First name and surname
• Represented organisation
• Business ID
• Email address
• Postal address
• Telephone number
• Website address
• IP address
• Information relating to previous orders
• Login information where this functionality is available
• In the Luottoposti service, information identifying the primary administrator of the service
Regular Sources of Personal Data
Information is obtained from customer registrations and from notifications made by customers during the customer relationship. Updates to names and contact details are also obtained from authorities and companies providing update services. Information may also be obtained from subcontractors involved in the provision or use of the service.
Information relating to customers’ activities in digital environments may also be obtained from partner websites, information systems or other digital sources accessed via electronic invitations, cookies or credentials provided to customers.
Regular Disclosure of Personal Data
The information contained in the customer register is used solely by the organisation, except where an external service provider is engaged to provide value-added services or to support credit decision-making. Personal data are not disclosed outside the Data Controller or to its partners, except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The data subject’s personal data will be deleted at the request of the data subject unless legislation, outstanding invoices or debt collection procedures prevent their deletion.
Retention Period for Personal Data
10 years from the termination of the customer relationship or the use of the service.
Transfers of Personal Data Outside the EU or EEA
The information contained in the register is not regularly transferred outside the European Union (EU) or the European Economic Area (EEA).
However, it is possible that processing involves service providers located outside the EU/EEA or that the cloud services used by service providers are located outside the EU/EEA. In such cases, transfers are based on the European Commission’s Standard Contractual Clauses (SCCs).
Additional safeguards have also been implemented for such transfers, including internal guidance on the pseudonymisation of personal data and similar protective measures, as well as, where necessary, a Transfer Impact Assessment (TIA).
Where an organisation processing personal data has committed to the EU–US Data Privacy Framework (DPF), this will be used as the legal basis for the transfer for as long as the framework remains in force.
Principles of Register Protection
A: Manual Records
Contact details collected during customer interactions and other manually processed documents containing customer information are stored, following their initial processing, in locked and fire-resistant storage facilities.
Only specifically authorised employees who have signed a confidentiality agreement are entitled to process manually stored customer information.
The protection and processing of the information contained in the register comply with the provisions and principles of data protection legislation, the requirements of the competent authorities and good information management practice.
B: Electronic Records
Only specifically authorised employees of the organisation and companies acting on its behalf are entitled to access the customer owner register and customer register and to maintain the information contained therein.
Each authorised user has a personal username and password.
Every user has signed a confidentiality agreement.
The system is protected by a firewall that safeguards it against unauthorised external access.
The protection and processing of the information contained in the register comply with the provisions and principles of data protection legislation, the requirements of the competent authorities and good information management practice.
Cookies
We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not damage users’ computers or files. The primary purpose of cookies is to improve and personalise the visitor’s experience of the website, as well as to analyse and improve the website’s functionality and content.
Information collected through cookies may also be used to target communications and marketing activities and to optimise marketing measures. Visitors cannot be identified solely by means of cookies. However, information obtained through cookies may be linked to information that the user has provided in another context, for example when completing a form on our website.
The following information may be collected through cookies:
• Visitor’s IP address
• Date and time of the visit
• Pages viewed and time spent on those pages
• Visitor’s web browser
Your Rights
Visitors to our website may prevent the use of cookies at any time by changing their preferences in the cookie banner. Some web browsers also allow cookies to be disabled and previously stored cookies to be deleted.
Disabling cookies may affect the functionality of the website.
Automated Decision-Making and Profiling
The personal data processed are not subject to profiling or automated decision-making.
Right of Access to Personal Data
The data subject has the right to obtain information about the personal data processed concerning them. A request for access to personal data must be submitted in writing to the Data Controller’s customer service or to the contact person responsible for the register. The request must be sent from a verifiable email address.
The data subject also has the right to object to the processing of their personal data for the purposes of direct marketing, including direct advertising, distance selling, market research and opinion surveys, by contacting the Data Controller’s customer service.
Right to Data Portability
The data subject has the right to transfer their personal data from one system to another. Requests relating to data portability may be addressed to the contact person for the register.
Right to Request Rectification of Data
Personal data contained in the register that are incorrect, unnecessary, incomplete or outdated in relation to the purpose of the processing must be rectified, erased or completed. A request for rectification must be submitted in writing, signed by hand, to the organisation’s customer service or the administrator of the personal data register, or sent from a verifiable email address. The request must specify which data are to be rectified and the grounds on which the rectification is requested. The rectification shall be carried out without undue delay. The party from whom the incorrect data were obtained, or to whom the data were disclosed, shall be notified of the rectification. If a request for rectification is refused, the person responsible for the register shall provide a written certificate stating the reasons for the refusal. The data subject may refer the refusal to the Office of the Data Protection Ombudsman for consideration.
Right to Restriction of Processing
The data subject has the right to request the restriction of processing, for example if the personal data contained in the register are inaccurate. Requests should be addressed to the person responsible for the register.
Right to Object
The data subject has the right to object to the processing of personal data concerning them and to request the rectification or erasure of their personal data.
Requests may be addressed to the contact person for the register. If you act as the contact person for a company or organisation, your personal data cannot be erased during this period.
Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data infringes the General Data Protection Regulation (GDPR), you have the right to lodge a complaint with the supervisory authority. You may also lodge a complaint with the supervisory authority in the Member State where you have your habitual residence or place of work.
Contact Details of the National Supervisory Authority
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, FI-00530 Helsinki
Postal address: P.O. Box 800, FI-00531 Helsinki
Telephone (switchboard): +358 29 566 6700
tietosuoja(at)om.fi
(https://tietosuoja.fi)
Other Rights Relating to the Processing of Personal Data
The data subject has the right to object to the processing of their personal data for direct marketing and other marketing purposes, to request the anonymisation of their personal data where applicable, and to request the erasure of their personal data in accordance with applicable data protection legislation ("the right to be forgotten").

