Data Protection Description
Finnish Personal Data Act (523/1999), Sections 10 and 24
3 August 2016
1. Data Controller
Smart Data Hub Ltd, Finnish Business ID 2724856-7 Address: P.O.Box 20, 00661 Helsinki, Finland Email: info@smartdatahub.io
2. Data File Name
Customer Contact Data File
3. Purpose of Use of the Personal Data
a) Business analysis, development and reporting;
b) Research and development of data services;
c) Delivery of data services;
d) Invoicing, payments, taxation and related financial transactions;
e) Marketing activities;
f) Customer relationship management;
General prerequisites for personal data processing: Finnish Personal Data Act, Section 8, paragraphs 1(2), 1(5) and 1(7).
4. Data Subjects
Employees and other natural persons representing customer companies of Smart Data Hub Ltd.
5. Data Content
First name; Last name; Email address; Telephone number;
Company (employer); Company website URL (if any) Company IP-address (if any)
Credit card number (if any); Credit card validity (if any);
User identification number; Web behavior information (depending on data subject's activity);
6. Regular Sources of Data
Customer contact persons themselves, other persons employed by or otherwise representing the customer companies of Smart Data Hub Ltd, employees and other persons working for or representing Smart Data Hub Ltd.
7. Regular Disclosures of Data and Transfer of Data to countries outside EU and/or EEA
Personal data are not disclosed regularly.
Personal data are not transferred outside EU and/or EEA.
If personal data is transferred to external data processors (subcontractors or vendors) appropriate contractual arrangements, as required by the applicable laws, are executed to secure lawful and appropriate processing of personal data.
8. Security Principles of Data File
Personal data is protected by technical and organizational measures against accidental and/or unlawful access, alteration, destruction or other processing including unauthorized disclosure and transfer of personal data.
Security measures include but are not necessarily limited to proper firewall arrangements, appropriate encryption of telecommunication and messages as well as use of secure and monitored equipment and server rooms.
Data security is of special concern if third parties (e.g. data processing subcontractors) providing and implementing IT systems and services are retained.
Data security requirements are duly observed in IT system access management (e.g. user ids and passwords) and monitoring of access to IT systems. Personnel processing personal data as part of their tasks is trained and properly instructed in data protection and data security matters.
9. Rights of Data Subject
In accordance with the law the data subject has right to:
a) access the personal data on him/her in the data file and at request, receive a copy of the recorded personal data;
b) request inaccurate personal data to be rectified, incomplete personal data to be supplemented and outdated or obsolete personal data to be erased; and
c) prohibit the processing of personal data for the purposes of direct marketing, market research and opinion polls.
In order to use these rights, the data subject shall contact the above mentioned contact persons in writing or electronically.