top of page

Envitecpolis Oy

​

Privacy Notice for the Customer and Marketing Register

​

1. GENERAL

This Privacy Notice explains how Envitecpolis Oy (hereinafter the “Controller”) processes personal data in accordance with the EU General Data Protection Regulation (2016/879; “GDPR”).

Envitecpolis processes personal data relating to its customers, potential customers and other parties to whom Envitecpolis has sent marketing materials (hereinafter collectively referred to as the “Data Subject”).

 

2. CONTROLLER AND CONTACT DETAILS

 

Controller: Envitecpolis Oy
Website: www.envitecpolis.fi
Address: Koulutie 6, 74300 Sonkajärvi, Finland

Contact person for data protection matters: Matti Arffman
Telephone: +358 44 783 1700
Email: matti.arffman@envitecpolis.fi

The contact person is not a Data Protection Officer within the meaning of the GDPR.

​

3. PURPOSE AND LEGAL BASIS FOR PROCESSING PERSONAL DATA

​

The Controller processes personal data for the purpose of providing and developing its services, managing payments and, where necessary, debt collection, as well as customer communications, customer service and maintaining customer relationships.

 

The legal bases for processing personal data are:

  1. Legitimate interest, where the processing relates to the customer relationship between the Controller and the Data Subject and associated communications.

  2. Contract, where processing is necessary for the performance of a contract between the Controller and the Data Subject.

  3. Consent, where the processing relates to direct marketing or other activities requiring consent.

 

4. WHAT INFORMATION DO WE COLLECT AND FROM WHERE?

​

The Controller collects and processes the following personal data:

  • Customer name and contact details, such as email address, postal address and telephone number

  • Customer feedback, customer surveys, contact requests and photographs, where the customer has added a photograph to the customer information system in use

  • Consents for direct marketing and publication of customer feedback under the customer’s name, marketing opt-outs and feedback

  • Anonymous user data collected through cookies, for example geographical information at continental level; IP addresses are not collected

 

The Controller primarily collects personal data directly from the Data Subject, from a contact person at the Data Subject’s company, or through communications with the Data Subject when they use the Controller’s services.

 

Personal data may also be collected and updated from public sources, for example through information gathered from websites for marketing purposes, from farms that have provided marketing consent, and from paid sources such as the Finnish Food Authority.

 

5. RECIPIENTS AND DISCLOSURE OF PERSONAL DATA

​

As a general rule, personal data is not disclosed to external parties. However, the Controller may disclose personal data to public authorities where required by law.

​

The Controller also uses external service providers, such as providers of technical services, which may process personal data on behalf of the Controller as part of the services they provide. Such processing is carried out in accordance with this Privacy Notice and a separate data processing agreement.

​

Further information on the security of personal data is provided in Section 7.

Where necessary, personal data may be processed outside the EU and the European Economic Area. In such cases, international transfers of personal data are carried out in accordance with the GDPR using appropriate transfer mechanisms.

 

The Controller also requires processors acting on its behalf to comply with the GDPR and to ensure an appropriate level of protection for personal data.

 

6. RETENTION PERIOD

​

The Controller retains personal data for as long as necessary for the purposes of its operations, including the performance of agreements between the Controller and the Data Subject, statistical purposes or compliance with specific legislation.

 

Personal data relating to potential customers is retained for as long as necessary to establish a customer relationship. The necessity of retaining data is assessed regularly, and outdated information is deleted.

 

Personal data is made inactive once five years have passed since the last contact with the Data Subject. No processing activities other than passive storage are carried out in relation to inactive personal data.

 

Such personal data is permanently deleted two years after it has been made inactive, provided that the Data Subject has not been in contact with the Controller during that period.

If a potential customer has opted out of direct marketing, information concerning that opt-out will be retained.

 

7. SECURITY OF PERSONAL DATA

​

Personal data may only be accessed by employees of the Controller or parties acting on behalf of the Controller under a contractual relationship who have committed to complying with all instructions and procedures relating to the Controller’s customer and marketing register.

Access to personal data is only possible using a username and password. The Controller grants access rights only to persons authorised to process personal data and only to the extent necessary for the performance of their duties.

​

All personal data processed in the Controller’s operations is confidential. The Controller’s employees and persons acting on behalf of the Controller are subject to confidentiality obligations that continue even after the employment or contractual relationship has ended.

In addition to the Controller’s employees, personal data may only be processed by service providers that have a contractual relationship with the Controller. These service providers may process personal data only in accordance with the agreement between the Controller and the relevant service provider and the Controller’s instructions.

​

The Controller requires its service providers to implement appropriate technical and organisational measures to protect personal data.

​

8. RIGHTS OF DATA SUBJECTS

​

Under the GDPR, Data Subjects have, among others, the following rights:

  • Right of access: The Data Subject has the right to obtain information about the personal data that the Controller processes concerning them.

  • Right to rectification: The Data Subject has the right to request that the Controller correct inaccurate or incorrect personal data without undue delay.

  • Right to erasure: In certain circumstances, the Data Subject has the right to have their personal data deleted without undue delay.

  • Right to restriction of processing: In certain circumstances, the Data Subject has the right to request that the Controller restrict the processing of their personal data, for example where the Data Subject contests the accuracy of the personal data, the processing is unlawful, or the personal data is no longer required for the original purposes of processing.

  • Right to object: The Data Subject has the right to request removal of their information from marketing lists, after which the Controller will no longer send customer or marketing communications to the Data Subject. Where personal data is processed on the basis of consent, the Data Subject has the right to withdraw that consent at any time.

  • Right to data portability: The Data Subject has the right to receive personal data they have provided to the Controller in a structured, commonly used and machine-readable format and, if desired, to transmit that data to another controller.

 

9. OTHER INFORMATION

​

If you have any questions regarding our data protection practices, please contact the Controller using the contact details provided in Section 2.

​

If the Controller’s activities do not comply with applicable data protection legislation, or if the rights of the Data Subject have not been adequately safeguarded, the Data Subject has the right to lodge a complaint with the competent data protection supervisory authority.

Envitecpolis_Ikoni.png

We provide data-driven insights and expert services to support strategic planning and decision-making in sustainability management across the food value chain, making effective use of digital solutions. Everything we do is built around our customers’ own needs, operations and key performance indicators.

TEXTRIGHT_BLACK_1080x265.png
Envitecpolis_logo.png

FIND US

Berlin (GE)

Espoo

Helsinki

Hämeenlinna

Ivalo

Jalasjärvi

Jyväskylä

Kajaani

Kemiönsaari

Kiuruvesi

Kouvola

Kuopio

Lappeenranta

​

Lapua

Orimattila

Oulu 

Rantasalmi

Rauma

Savonlinna

Seinäjoki

Sonkajärvi

Sotkamo

Suomussalmi

Utajärvi

Varkaus

Äänekoski           

ALL RIGHTS RESERVED © ENVITECPOLIS OY

​

​

bottom of page