Registry and Privacy Statement
This is the Registry and Data Protection Statement of Kuopion startupien tukiyhdistys ry in accordance with Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Completed: 11/3/2021 Last modified: 11/3/2021
Kuopion startupien tukiyhdistys ry
044 787 0860
2. Person in charge for the register
+358 44 787 08 60
3. Name of the register
Name of the register is Kuopion startupien tukiyhdistys ry’s website’s (www.hubpanostamo.fi) customer register.
4. Legal basis and purpose of processing personal data
The purpose of processing personal data is to communicate with customers and maintain customer relationships. The data is not used for automated decision making or profiling.
The legal bases for the processing of personal data are the following in accordance with the EU General Data Protection Regulation (hereinafter also referred to as the “GDPR”):
1. The data subject has given consent to the processing of his or her personal data for one or more specific purposes (GDPR 6 art. 1.a);
2. Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (GDPR 6 art. 1.b);
3. Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party (GDPR 6 art. 1.f).
The data controller’s legitimate interest referred to above is based on a relevant and appropriate relationship between the data subject and the data controller which is a result of the data subject being a customer of the data controller, and when processing happens for purposes which the data subject could reasonably have expected at the time of data collected and in the context of an appropriate relationship.
5. Information content of the register
The information stored in the register is contact information that can be sent using the page forms.
Kuopion startupien tukiyhdistys ry does not store personal data for longer than is necessary for their purposes, or as required by agreement or law.
6. Regular sources of information
The information stored in the register is obtained from the customer through contact forms.
7. Regular transfers of data and transfers of data outside the EU or the EEA
The information is not regularly disclosed to other parties. The information may be published to the extent agreed with the customer. The data will not be transferred by the controller outside the EU or the EEA either.
8. Principles of Registry Security
The register shall be handled with due care and the data processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees in whose job description it includes.
9. Right of inspection and right to request correction of information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to verify or request the rectification of data stored about him or her, a request for verification must be made in writing and his or her identity must be proved in connection with the request. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).
10. Other rights related to the processing of personal data
A person in the register has the right to request the removal of his or her personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU’s general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).