Registry and Privacy Statement
This is a registry and Privacy Statement in accordance with the Bettas Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on 13.05.2019. Last modified 12.04.2020.
1. The controller
Bettas, Kumpulantie 25, 68300 Kokkola
2. Contact person responsible for the register
3. Name of the register
Bettas customer and marketing register.
4. Purpose of personal data
The information is used for customer relationship management, customer communication and to improve the user experience of the Bettas online service, with the aim of targeting our messages so that you get the communication that is right for you. In addition, the information is used for marketing purposes.
Our basis is the legitimate interest in marketing and the implementation of the agreement between you and us in terms of customer relationship management. We will also send you electronic direct marketing messages based on your consent.
5. Information content of the register
The information stored in the register includes: person's name, contact information (phone number, e-mail address, address), IP address of the network connection, information about the ordered services and their changes, billing information, other information related to the customer relationship and the ordered services.
6. Regular sources of information
The information stored in the register is obtained from the customer e.g. Messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information.
7. Regular transfers of data and transfers of data outside the EU or the EEA
The information is not regularly disclosed to other parties. The information may be published to the extent agreed with the customer.
We may use service providers who may have access to your personal information from outside the EU / EEA, such as the United States, to process your personal information. We ensure the proper and lawful execution of transfers in accordance with the legislation on the processing of personal data.
8. Registry Security Principles
The register shall be handled with due care and the information processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it includes.
9. Right of inspection and right to request correction of information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check the data stored about him or her or request a correction, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).
10. Other rights related to the processing of personal data
A person in the register has the right to request the removal of his or her personal data from the register ("the right to be forgotten"). Data subjects also have other rights under the EU's general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).