Pri­vacy Policy of Heina Ltd cus­tom­er and mar­ket­ing register

1. Con­trol­ler of data file

Heina Ltd
Lin­namäen­tie 1
FI-24910 Halikko As.
Fin­land

Busi­ness ID: FI06838568
www.heina.net

2. Data con­tent in the register

The register lists the com­pany’s busi­ness part­ners, cus­tom­ers and poten­tial cus­tom­ers, and per­sons who have made con­tact with the com­pany. We also make use of pub­lic busi­ness data avail­able online or col­lec­ted from vari­ous author­it­ies.

3. Pur­pose of use of per­son­al data

The con­tent of the register is used for man­aging user and cus­tom­er rela­tion­ships:

  • Per­son­al data are pro­cessed based on a registered cus­tom­er rela­tion­ship
  • Per­son­al data are pro­cessed based on con­sent

Pur­pose of data pro­cessing and use of data file. Per­son­al data are only pro­cessed for pur­poses stated in advance, which are as fol­lows:

  • man­aging cus­tom­er rela­tion­ships
  • provid­ing inform­a­tion on our ser­vices
  • ana­lyz­ing, group­ing and report­ing on cus­tom­er rela­tion­ships
  • col­lect­ing and pro­cessing cus­tom­er feed­back
  • car­ry­ing out mar­ket research and sur­veys
  • ful­filling con­trac­tu­al oblig­a­tions

Addi­tion­ally, anonym­ous track­ing data are col­lec­ted on the use of the web­site using the Google Ana­lyt­ics ser­vice:

  • pages vis­ited
  • source of traffic
  • device/browser used
  • dur­a­tion of vis­it

Track­ing can be pre­ven­ted by dis­abling cook­ies or using the browser­’s Do Not Track option.

4. Per­son­al data stored in the register

The cus­tom­er register con­tains the fol­low­ing details:

Con­tact details

  • name
  • com­pany name
  • busi­ness ID
  • address
  • email
  • tele­phone
  • lan­guage

Cus­tom­er inform­a­tion

  • details of pur­chased products/services

5. Rights of the data sub­ject

The rights of the data sub­ject are lis­ted below. Any requests con­cern­ing exer­cising those rights must be addressed to:

Heina Ltd
Lin­namäen­tie 1
FI-24910 Halikko As.
Fin­land

Busi­ness ID: FI06838568
www.heina.net

Right to access per­son­al data
Data sub­jects may check the per­son­al data that we have stored on them­selves.

Right to rec­ti­fic­a­tion of data
Data sub­jects may request that we rec­ti­fy any erro­neous or incom­plete data we have stored on them­selves.

Right to object
Data sub­jects may object to the pro­cessing of their per­son­al data if they con­sider improp­er pro­cessing to have taken place.

Dir­ect mar­ket­ing ban
Data sub­jects have the right to deny the use of their data for dir­ect mar­ket­ing pur­poses by inform­ing the con­trol­ler of the data file in writ­ing.

Right to eras­ure
Data sub­jects have the right to request the eras­ure of their data when pro­cessing of the data is no longer neces­sary. After hand­ling the request, we will either erase the data or provide jus­ti­fi­able grounds as to why we can­not erase them. Please note that the con­trol­ler of the data file may have a right, leg­al or oth­er­wise, not to erase the reques­ted data. The con­trol­ler of the data file is required by the Finnish Account­ing Act (Chapter 2, sec­tion 10) to store account­ing mater­i­als for the peri­od stated in the law (10 years). There­fore account­ing-related data may not be removed before this peri­od expires.

Can­cel­la­tion of con­sent
If the pro­cessing of the data sub­ject’s per­son­al data is based entirely on con­sent (and not on e.g. a cus­tom­er rela­tion­ship or mem­ber­ship), the data sub­ject may can­cel their con­sent.

Com­plaints on decisions may be addressed to the Data Pro­tec­tion Ombuds­man
Data sub­jects have the right to demand that pro­cessing of data involved in a con­flict be restric­ted for the dur­a­tion of the res­ol­u­tion of the con­flict.

Right to appeal
Data sub­jects are entitled to make a com­plaint to the Data Pro­tec­tion Ombuds­man if they feel that we have viol­ated applic­able data pro­tec­tion legis­la­tion in pro­cessing per­son­al data. Data Pro­tec­tion Ombuds­man’s con­tact details: www.tietosuoja.fi/fi/index/yhteystiedot.html

6. Reg­u­lar data sources

Reg­u­lar sources of cus­tom­er details:

  • from the cus­tom­ers them­selves at the start of the cus­tom­er rela­tion­ship
  • from the cus­tom­ers them­selves via an online form
  • from the cus­tom­ers them­selves by email
  • from busi­ness and con­trac­tu­al part­ners and the author­it­ies
  • per­son­al data may also be obtained from pro­viders of iden­ti­fic­a­tion, authen­tic­a­tion, address, update or sim­il­ar ser­vices

7. Reg­u­lar dis­clos­ures of data

Data is not usu­ally dis­closed for mar­ket­ing pur­poses to parties out­side of Heina Ltd. We have ensured that all of our ser­vice pro­viders com­ply with data pro­tec­tion legis­la­tion.

8. Dur­a­tion of pro­cessing

We will store and pro­cess your per­son­al data for as long as it is neces­sary to ful­fill the stated pur­poses. Laws and reg­u­la­tions set cer­tain require­ments for the stor­age and use of mater­i­als con­tain­ing per­son­al data, which affect how long data are stored.

  • Per­son­al data are usu­ally pro­cessed as long as the cus­tom­er rela­tion­ship remains in place
  • Any data sub­ject may unsub­scribe from our mar­ket­ing using the links included in all of our mar­ket­ing emails

9. Pro­cessors of per­son­al data

Per­son­al data are pro­cessed by the con­trol­ler of the data file and its employ­ees. We may also out­source a part of our per­son­al data pro­cessing to a third party, in which case we will con­trac­tu­ally ensure that per­son­al data are only handled accord­ing to val­id data pro­tec­tion legis­la­tion and oth­er­wise appro­pri­ately. The per­sons hand­ling your per­son­al data have all received data pro­tec­tion and pri­vacy train­ing.  Our employ­ees only have access to the per­son­al data that are essen­tial for them to com­plete their tasks. The inform­a­tion sys­tem and its files are pro­tec­ted using tech­nic­al pro­tec­tion meth­ods com­monly used in busi­ness oper­a­tions. Per­son­al data are handled con­fid­en­tially, and the neces­sary level of data and pro­cessing pro­tec­tion is ensured using appro­pri­ate meas­ures. 

10. Trans­fers of data to out­side the European Uni­on

No per­son­al data will be trans­ferred out­side of the European Uni­on or European Eco­nom­ic Area unless it is essen­tial for the main­ten­ance and tech­nic­al ful­fill­ment of ser­vices. In such cases, we will ensure appro­pri­ate data pro­tec­tion as required by law.

11. Valid­ity

This policy was last updated on 29th March 2022, and it is val­id until fur­ther notice.