Register Notice and Privacy Policy

This is the Company’s register notice and privacy policy in accordance with the EU General Data Protection Regulation (GDPR). Created 17 July 2021. Latest change 17 February 2023.

1. Controller

Micaro Makeiset Oy, VAT FI32661591, Jurvalankuja 2, 54530 Luumäki, Finland

info@micaromakeiset.fi

2. The contact person responsible for the register

Ville Vahersalo, tel. +358 50 5555 994, info@micaromakeiset.fi

3. Name of the register

The customer register of the online store.

4. Legal basis and purpose of processing personal data

The legal basis for processing personal data under the EU General Data Protection Regulation is
– the consent of the individual (documented, voluntary, individual, informed, and unambiguous)
– the contract to which the data subject is a party

The purpose of processing personal data is to contact customers, maintain customer relations, and deliver orders.

The data will not be used for marketing, automated decision-making, or profiling.

5. Data content of the register

The data stored in the register includes: the name of the person, contact information (phone number, email address, address), information about ordered products, billing information, and other information related to the customer relationship and ordered services.

The data is kept for the period required by law.

The IP addresses of visitors to the website and the cookies necessary for the functioning of the service are processed for legitimate interests, such as ensuring data security and collecting statistics on visitors to the website in cases where they can be considered as personal data. Third party cookies will be subject to separate consent where necessary.

6. Regular data sources

The data stored in the register is obtained from the customer via the e-commerce order form and from other situations where the customer provides their data.

7. Regular disclosures or transfers of data outside the EU or EEA

The data will not be regularly disclosed to any third parties. Information may be published to the extent agreed with the customer.

The data will not be transferred by the controller outside the EU or EEA.

8. Principles of register protection

The register is processed with due care and the data processed by the information systems are adequately protected. When the data is stored on Internet servers, the physical and digital security of the hardware is adequately ensured. The controller shall ensure that stored data, server access rights, and other information critical to the security of personal data are treated confidentially and only by employees whose job description includes this.

9. Right of inspection and right to request correction

Every data subject has the right to inspect the data recorded in the register and to request the correction of any inaccurate data or the completion of incomplete data. If a person wishes to check the data stored about them or to request a correction, the request must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove their identity. The controller will respond to the customer within the time limit set by the EU General Data Protection Regulation (usually within one month).

10. Other rights relating to the processing of personal data

A data subject has the right to request the erasure of personal data concerning them from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of processing of personal data in certain situations. Requests should be sent in writing to the controller. If necessary, the controller may ask the applicant to prove their identity. The controller will respond to the customer within the time limit set by the EU General Data Protection Regulation (usually within one month).