Registry and Privacy Statement
This is the registry and Privacy Statement of HiiluDesign in accordance with the EU General Data Protection Regulation (GDPR). Prepared on 12.10.2021. Last modified 12.4.2022.
1. Registrar
HiiluDesign Address Kumpulantie 1, 00520 Helsinki
2. The contact person responsible for the register
Katarina Heiskanen
+358408202889
​
3. Register name
HiiluDesign customer register
​
4. Legal basis and purpose of personal data processing
The purpose of processing personal data is to communicate with customers, maintain customer relations, marketing, etc.
The data is not used for automated decision-making or profiling.
5. Data content of the register
Information to be recorded in the register is: person's name, contact information (phone number, e-mail address, address).
Information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services.
IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to take care of information security and for the collection of statistical data of website visitors in those cases when they can be considered as personal data. If necessary, consent is requested separately for third-party cookies.
6. Regular sources of information
The information to be saved in the register is obtained from the customer, e.g. From messages sent via www forms, by e-mail, by phone, via social media services, contracts, customer meetings and other situations where the customer gives out their information.
Information about contact persons of companies and other organizations can also be collected from public sources such as websites, directory services and other companies.
​
​
​
This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services. You consent to our cookies if you continue to use our website.
You can always prohibit the use of cookies, but this may hinder the functonality of the site.
7. Regular transfers of data and transfer of data outside the EU or EEA
Information is not regularly disclosed to other parties.
​
8. Principles of registry protection
Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.
9. Right of inspection and right to demand correction of information
Every person in the register has the right to check their information stored in the register and to demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).
10. Other rights related to the processing of personal data
A person in the register has the right to request the removal of personal data about him from the register ("the right to be forgotten"). Those registered also have other rights according to the EU General Data Protection Regulation , such as limiting the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).