B2C Customer Register
B2C Customer Register
Data Controller
TK Talous Oy (0925979-9)
Luvakuja 16
21260 Raisio
Contact Person for Register Matters
Kari Virtanen
kari.virtanen(at)tktalous.fi
Register
B2C Customer Register
Date of Preparation
2024-10-28
Legal Basis for Processing
Contract and Legitimate Interest
Purpose of the Processing of Personal Data
The purpose of the register is to maintain the organisation’s B2C customer register, administer, archive and process customer orders, and manage customer relationships. The information may be used for the development of operations, statistical purposes and the provision of more personalised targeted content within our online services. Personal data are processed within the limits permitted and required by the General Data Protection Regulation (GDPR). The information contained in the register may be used within the organisation’s own registers, for example for targeted advertising, without disclosing personal data to external parties. The organisation may use partners to maintain customer and service relationships, in which case parts of the register data may be transferred to the partners’ servers due to technical requirements. The information is processed solely for the purpose of maintaining the customer relationship with the Data Controller’s organisation through technical interfaces. The organisation has the right to publish information contained in the customer register in the form of an electronic or printed directory unless the customer specifically prohibits such publication. In this context, a directory refers, for example, to mailing labels for direct marketing or similar purposes. The customer has the right to prohibit the publication of their information by notifying the Data Controller’s customer service, by email or by contacting the contact person for the register.
Basis of Legitimate Interest
If the processing is based on Legitimate Interest:
The Data Controller’s Legitimate Interest in processing the collected and processed personal data is based on the freedom to conduct a business. The Data Controller must process personal data in order to carry out activities related to its business operations. In this context, the processing of personal data cannot necessarily be justified on the basis of a legal obligation or a contract concluded with the individual.
Following a Legitimate Interest Assessment (LIA), the Data Controller has concluded that Legitimate Interest is the most appropriate legal basis for processing, taking into account the nature and scope of the processing and the rights and freedoms of the data subjects. The Data Controller has assessed that processing based on Legitimate Interest does not cause significant harm to the rights and freedoms of the individuals concerned (data subjects).
Categories of Personal Data
Personal data relating to customers.
Customer user information.
Recipients and Categories of Recipients
The Data Controller’s personnel and, where applicable, outsourced service providers (financial administration).
Contents of the Register
The personal data register contains the following information:
• First name and surname
• Email address
• Postal address
• Telephone number
• Website address
• IP address
• Information relating to previous orders
• Login information where this functionality has been made available to the customer
Regular Sources of Personal Data
Information is obtained from customer registrations and from notifications made by customers during the customer relationship. Updates to names and contact details are also obtained from authorities and companies providing update services.
Regular Sources of Personal Data
Information may also be obtained from subcontractors involved in the provision or use of the service. Information relating to customers’ activities in digital environments may also be obtained from partner websites, information systems or other digital sources accessed via electronic invitations, cookies or credentials provided to customers. The information contained in the customer register is used solely by the organisation, except where an external service provider is engaged to provide value-added services or to support credit decision-making. Personal data are not disclosed outside the organisation or to its partners, except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The data subject’s personal data will be deleted at the request of the data subject unless legislation, outstanding invoices or debt collection procedures prevent their deletion.
Retention Period for Personal Data
10 years from the termination of the customer relationship.
Regular Disclosure of Personal Data
The information contained in the customer register is used solely by the organisation, except where an external service provider is engaged to provide value-added services or to support credit decision-making. Personal data are not disclosed outside the Data Controller or to its partners, except where necessary in connection with credit applications, debt collection or invoicing, or where disclosure is required by law. The data subject’s personal data will be deleted at the request of the data subject unless legislation, outstanding invoices or debt collection procedures prevent their deletion.
Transfers of Personal Data Outside the EU or EEA
The information contained in the register is not regularly transferred outside the European Union (EU) or the European Economic Area (EEA).
However, it is possible that processing involves service providers located outside the EU/EEA or that the cloud services used by service providers are located outside the EU/EEA. In such cases, transfers are based on the European Commission’s Standard Contractual Clauses (SCCs).
Additional safeguards have also been implemented for such transfers, including internal guidance on the pseudonymisation of personal data and similar protective measures, as well as, where necessary, a Transfer Impact Assessment (TIA).
Where an organisation processing personal data has committed to the EU–US Data Privacy Framework (DPF), this will be used as the legal basis for the transfer for as long as the framework remains in force.
Principles of Register Protection
A: Manual Records
Contact details collected during customer interactions and other manually processed documents containing customer information are stored, following their initial processing, in locked and fire-resistant storage facilities. Only specifically authorised employees who have signed a confidentiality agreement are entitled to process manually stored customer information. The protection and processing of the information contained in the register comply with the provisions and principles of data protection legislation, the requirements of the competent authorities and good information management practice.
B: Electronic Records
Only specifically authorised employees of the organisation and companies acting on its behalf are entitled to access the customer owner register and customer register and to maintain the information contained therein. Each authorised user has a personal username and password. Every user has signed a confidentiality agreement. The system is protected by a firewall that safeguards it against unauthorised external access. The protection and processing of the information contained in the register comply with the provisions and principles of data protection legislation, the requirements of the competent authorities and good information management practice.
Cookies
We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not damage users’ computers or files. The primary purpose of cookies is to improve and personalise the visitor’s experience of the website, as well as to analyse and improve the website’s functionality and content. Information collected through cookies may also be used to target communications and marketing activities and to optimise marketing measures. Visitors cannot be identified solely by means of cookies. However, information obtained through cookies may be linked to information that the user has provided in another context, for example when completing a form on our website.
The following information may be collected through cookies:
• Visitor’s IP address
• Date and time of the visit
• Pages viewed and time spent on those pages
• Visitor’s web browser
Your Rights
Visitors to our website may prevent the use of cookies at any time by changing their preferences in the cookie banner. Some web browsers also allow cookies to be disabled and previously stored cookies to be deleted. Disabling cookies may affect the functionality of the website.
Automated Decision-Making and Profiling
The personal data processed are not subject to profiling or automated decision-making.
Right of Access to Personal Data
The data subject has the right to verify what personal data relating to them are contained in the register. The request for access must be submitted in writing by contacting the Data Controller’s customer service or the contact person for the register in Finnish or English. The request must be sent from a verifiable email address. The data subject has the right to prohibit the processing and disclosure of their personal data for the purposes of direct advertising, distance selling, direct marketing, market research and opinion surveys by contacting the Data Controller’s customer service.
Right to Data Portability
The data subject has the right to transfer their personal data from one system to another. Requests relating to data portability may be addressed to the contact person for the register.
Right to Request Rectification of Data
Personal data contained in the register that are incorrect, unnecessary, incomplete or outdated in relation to the purpose of the processing must be rectified, erased or completed. A request for rectification must be submitted in writing, signed by hand, to the organisation’s customer service or the administrator of the personal data register, or sent from a verifiable email address. The request must specify which data are to be rectified and the grounds on which the rectification is requested.
The rectification shall be carried out without undue delay. The party from whom the incorrect data were obtained, or to whom the data were disclosed, shall be notified of the rectification. If a request for rectification is refused, the person responsible for the register shall provide a written certificate stating the reasons for the refusal. The data subject may refer the refusal to the Office of the Data Protection Ombudsman for consideration.
Right to Restriction of Processing
The data subject has the right to request the restriction of processing, for example if the personal data contained in the register are inaccurate. Requests should be addressed to the person responsible for the register.
Right to Object
The data subject has the right to object to the processing of personal data concerning them and to request the rectification or erasure of their personal data.
Requests may be addressed to the contact person for the register.
If you act as the contact person for a company or organisation, your personal data cannot be erased during this period.
Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data infringes the General Data Protection Regulation (GDPR), you have the right to lodge a complaint with the supervisory authority. You may also lodge a complaint with the supervisory authority in the Member State where you have your habitual residence or place of work.
Contact Details of the National Supervisory Authority
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, FI-00530 Helsinki
Postal address: P.O. Box 800, FI-00531 Helsinki
Telephone (switchboard): +358 29 566 6700
Registry: +358 29 566 6768
(tietosuoja@om.fi)
(https://tietosuoja.fi)
Other Rights Relating to the Processing of Personal Data
The data subject has the right to prohibit the disclosure and processing of their personal data for direct marketing and other marketing purposes, to request the anonymisation of their personal data where applicable, and to exercise the right to be forgotten.

