Contract Register

Contract Register

Data Controller
TK Talous Oy (0925979-9)
Luvakuja 16
21260 Raisio

Contact Person for Register Matters
Kari Virtanen
kari.virtanen(at)tktalous.fi

Register
Contract Register

Date of Preparation
2024-10-28

Legal Basis for Processing
Legitimate Interest

Purpose of the Processing of Personal Data
The purpose of the register is to maintain, administer, archive and process contracts relating to the organisation’s customers and other stakeholders, as well as to manage customer relationships. The information may be used to develop the Data Controller’s business operations, for statistical purposes, and to provide more personalised targeted content. Personal data are processed in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection legislation. The information contained in the register may be used within the Data Controller’s own registers, for example for targeted advertising, without disclosing personal data to external parties. The organisation may use partners to maintain customer and service relationships. For technical reasons, parts of the register data may therefore be transferred to the servers of such partners. Personal data are processed solely through technical interfaces for the purpose of maintaining the customer relationship within the Data Controller’s organisation.

Basis of Legitimate Interest
The Data Controller must process personal data in order to carry out activities related to its business operations. In this context, the processing of personal data cannot necessarily be justified on the basis of a legal obligation or a contract concluded with the individual. Following a Legitimate Interest Assessment (LIA), the Data Controller has concluded that Legitimate Interest is the most appropriate legal basis for processing, taking into account the nature and scope of the processing and the rights and freedoms of the data subjects. The Data Controller has assessed that processing based on Legitimate Interest does not cause significant harm to the rights and freedoms of the individuals concerned (data subjects).

Categories of Personal Data
Name, represented organisation, contact details, and matters agreed in the contract.

Recipients and Categories of Recipients
The Data Controller’s personnel and, where applicable, outsourced service providers (financial administration, IT administration, debt collection, etc.).

Contents of the Register
The Contract Register contains the following information:
• First name and surname
• Represented organisation
• Business ID
• Email address
• Postal address
• Telephone number
• Services ordered
• Other mutually agreed business-related matters

Regular Sources of Personal Data
Telephone and other electronic means of communication.
Information may also be obtained from subcontractors involved in the provision or use of the service. Information relating to customers’ activities in the digital environment may also be obtained from the websites, information systems or other digital sources of partners that are accessed via electronic invitations (links), cookies or customer credentials. The information contained in the Contract Register is used solely by the Data Controller, except where an external service provider is engaged to provide value-added services or to support credit decision-making.

Regular Sources of Personal Data
Personal data are not disclosed outside the Data Controller’s organisation or to its partners, except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The data subject’s personal data will be deleted at the request of the data subject unless legislation, outstanding invoices or debt collection procedures prevent their deletion.

Retention Period for Personal Data
The information contained in the Contract Register is retained for 10 years from the termination of the contract.

Regular Disclosure of Personal Data
The information contained in the register is used solely by the Data Controller, except where an external service provider is engaged to provide value-added services or to support credit decision-making. Personal data are not disclosed outside the Data Controller or to its partners, except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The data subject’s personal data will be deleted at the request of the data subject unless legislation, outstanding invoices or debt collection procedures prevent their deletion.

Transfers of Personal Data Outside the EU or EEA
The information contained in the register is not regularly transferred outside the European Union (EU) or the European Economic Area (EEA).
However, it is possible that processing involves service providers located outside the EU/EEA or that the cloud services used by service providers are located outside the EU/EEA. In such cases, transfers are based on the European Commission’s Standard Contractual Clauses (SCCs).
Additional safeguards have also been implemented for such transfers, including internal guidance on the pseudonymisation of personal data and similar protective measures, as well as, where necessary, a Transfer Impact Assessment (TIA).
Where an organisation processing personal data has committed to the EU–US Data Privacy Framework (DPF), this will be used as the legal basis for the transfer for as long as the framework remains in force.

Principles of Register Protection
A: Manual Records
Contact details and other documents containing customer information that are collected and processed manually for the purposes of the register are stored, following their initial processing, in locked and fire-resistant storage facilities.
Only specifically authorised employees who have signed a confidentiality agreement are entitled to process manually stored customer information. The protection and processing of the information contained in the register comply with the provisions and principles of data protection legislation, the requirements of the competent authorities and good information management practice.

B: Electronic Records
Only specifically authorised employees of the organisation and companies acting on its behalf are entitled to access the Contract Register and maintain its contents.
Each authorised user has a personal username and password. Every user has signed a confidentiality agreement.
The system is protected by a firewall that safeguards it against unauthorised external access. The protection and processing of the information contained in the register comply with the provisions and principles of data protection legislation, the requirements of the competent authorities and good information management practice.

Cookies
We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not damage users’ computers or files. The primary purpose of cookies is to improve and personalise the visitor’s experience of the website, as well as to analyse and improve the website’s functionality and content. Information collected through cookies may also be used to target communications and marketing activities and to optimise marketing measures. Visitors cannot be identified solely by means of cookies. However, information obtained through cookies may be linked to information that the user has provided in another context, for example when completing a form on our website.

The following information may be collected through cookies:
• Visitor’s IP address
• Date and time of the visit
• Pages viewed and time spent on those pages
• Visitor’s web browser

Your Rights
Visitors to our website may prevent the use of cookies at any time by changing their preferences in the cookie banner. Some web browsers also allow cookies to be disabled and previously stored cookies to be deleted. Disabling cookies may affect the functionality of the website.

Right of Access to Personal Data
The data subject has the right to verify what personal data relating to them are contained in the register. A request for access must be submitted in writing or sent from a verifiable email address. The data subject has the right to prohibit the processing and disclosure of their personal data for the purposes of direct advertising, distance selling, direct marketing, market research and opinion surveys by contacting the Data Controller’s customer service.

Right to Data Portability
The data subject has the right to transfer their personal data from one system to another. Requests relating to data portability may be addressed to the contact person for the register.

Right to Request Rectification of Data
Personal data contained in the register that are incorrect, unnecessary, incomplete or outdated in relation to the purpose of the processing must be rectified, erased or completed. A request for rectification must be submitted in writing, signed by hand, to the Data Controller’s customer service or sent from a verifiable email address.
The request must specify which data are to be rectified and the grounds on which the rectification is requested. The rectification shall be carried out without undue delay.
The party from whom the incorrect data were obtained, or to whom the data were disclosed, shall be notified of the rectification. If a request for rectification is refused, the person responsible for the register shall provide a written certificate stating the reasons for the refusal. The data subject may refer the refusal to the
Office of the Data Protection Ombudsman for consideration.

Right to Restriction of Processing
The data subject has the right to request the restriction of processing, for example if the personal data contained in the register are inaccurate. Requests should be addressed to the person responsible for the register.

Right to Object
The data subject has the right to object to the processing of personal data concerning them and to request the rectification or erasure of their personal data.
Requests may be addressed to the contact person for the register. If you act as the contact person for a company or organisation, your personal data cannot be erased during this period.

Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data infringes the General Data Protection Regulation (GDPR), you have the right to lodge a complaint with the supervisory authority. You may also lodge a complaint with the supervisory authority in the Member State where you have your habitual residence or place of work.

Contact Details of the National Supervisory Authority
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, FI-00530 Helsinki
Postal address: P.O. Box 800, FI-00531 Helsinki
Telephone (switchboard): +358 29 566 6700
tietosuoja(at)om.fi
(https://tietosuoja.fi)

Other Rights Relating to the Processing of Personal Data
The data subject has the right to prohibit the disclosure and processing of their personal data for direct marketing and other marketing purposes, to request the anonymisation of their personal data where applicable, and to exercise the right to be forgotten once the contractual relationship has ended.

GDPR Compuance