Privacy Statement
General principles for the processing of personal data
Data protection and your privacy are important to us. When you use our services, you provide us with information about yourself and we want to prove worthy of your trust.
- We process personal data carefully and professionally.
- We protect personal data with appropriate technical solutions
- The processing of personal data is systematic and in accordance with the law.
- We do not collect extra information about you.
- We strive for transparency in our operations.
- We explain the policies in plain language.
Personal data is all data that can be linked to a natural person.
Data processor or data controller?
In some cases, we are the handlers of information and not the record keeper. When we cannot specify the purpose and manner in which personal data is processed, we are the processor of personal data, in which case we have access to the personal data of the controller.
For example, when the customer provides us with the personal data of its employees for some purpose, the customer is the data controller. In this case, our customer determines the purpose and means of processing personal data.
The personal data processor may only process personal data for the purposes specified by the controller. The controller's obligations towards the controller are defined in the assignment agreement between us and the customer.
We act as a data controller in a situation where we process personal data on our own behalf, i.e. we decide for ourselves what purpose and how we collect personal data.
What personal data do we collect?
The collection of data is affected by the service you use. If you only use the website and refuse all cookies, we will not collect any information about you. If you are our customer, of course we know more about you. Of course, not all information is stored in our rectifier. Below are examples of different situations in which your personal data is stored in our register.
General information
In order to be able to communicate with you, we store your contact information on different systems. Such general information includes, for example, name, telephone number, e-mail address, address information for instant messengers.
Customer information
When a customer relationship is established between us, the amount of information naturally increases. We use this information to provide the service and manage the customer relationship. If you are a business customer, we store information about your employer, i.e. the company. Such information includes, for example, your company address, billing information, location of your workplace, available services, company-specific IDs for the necessary systems, notes of appointments.
Calls and other contacts
We may record phone calls or other conversations we have had for quality monitoring, training, or fulfilling our obligation to demonstrate. Email and social media conversations are automatically saved, even if we do not do the above. There may also be log information about conversations, such as when they were sent.
Newsletter subscription
When subscribing to the newsletter, we store your email address. In addition, we may ask for your name and interests.
Website visit
By default, no personal information remains in our system when visiting the website. If you accept all cookies, Google Analytics stores your IP address and a unique user ID, which allows us to separate individuals from individual website visits.
Collecting personal data in a concise manner
Customer | Query or information questioner | Newsletter Subscriber | Website Visitor | |
---|---|---|---|---|
First name | X | X | X | |
surname | X | X | X | |
Company | X | X | ||
Office | X | X | ||
X | X | X | ||
Phone number | X | X | ||
Role/area of responsibility | X | X | ||
Debates | X | X | ||
Offers issued | X | X | ||
IP Address | X | |||
Where do we obtain (i.e. collect) your personal data?
The sources from which we obtain personal data are listed below. The most common source is contact through websites or email.
Straight from you
We collect your information when you contact us, subscribe to our newsletter or use our services.
From the website
Our website uses cookies to optimise your service experience. This information is not always identifiable, that is, it is not personal data. Learn more about our use of cookies about our cookie policy.
From partners and public sources
For example, we can search for connection and billing information using different databases.
How do we use your personal data?
Caring for customers and providing a service
We process your personal data in order to identify you as our customer, to communicate with you and to send you messages at different stages of the customer relationship.
Business Development
We process your personal data to improve our business and services and to carry out marketing research and analysis, such as customer satisfaction surveys.
Marketing
We collect and analyze personal information, such as your behavior on the website or your location, to send you information about our services or other messages that you may find useful. In addition, we can improve the user experience of our website and the relevance of advertising based on your personal data.
Statistics
We also use the information we collect for statistics and to develop our own operations.
Basis of processing personal data
We process your personal data on the following grounds:
- You have given us your consent to process your data. Consent can be given by using our services or by contacting our customer service. You can withdraw your consent at any time.
- The processing is necessary for the realization of our legitimate interests or those of third parties. This may include, for example, a situation where we process your data to prevent fraud or to target direct marketing to you, or to maintain the security of our information systems.
- The processing is necessary to comply with our legal obligations.
Automated decision making and profiling
We may use automated decision making in some of our services, for example in the automated processing of service requests. Automated decision-making is based on the information provided to us.
We use profiling to send you marketing messages that we believe are appropriate for you. In this way, we also avoid sending irrelevant messages. You have the right to refuse profiling in connection with direct marketing.
Data Retention and Security
We are committed to ensuring the security of your data through good data management and careful handling of personal data. We use appropriate technical, physical, legal and organizational measures to protect your data.
We will retain your personal data for as long as necessary for the purposes specified in the data protection and registration statements unless a longer retention period is required or permitted by law.
- As a rule, personal data is processed for a period of two years from the date of sending the last offer or invoice.
- Newsletter subscribers can unsubscribe from the list themselves.
- The data of visitors to the website will be processed for two years,
It should be noted that the controller may have a statutory or other right not to delete the requested information. The controller is obliged to keep the accounting records in accordance with the Accounting Act (Chapter 2, Section 10) for a period of time (10 years). Therefore, material related to accounting cannot be deleted before the expiry of the deadline.
Disclosure of your personal data to third parties
We will not disclose your personal data to third parties without your consent unless one of the following conditions is met:
- The disclosure of information is based on a law, regulation or contract binding us.
- We and the third party have an agreement regarding the processing of personal data.
- The disclosure of personal data is necessary for the implementation of a service provided to you.
- Your personal data has been collected in connection with an event organised jointly with our partners. We may disclose your information to the partners who organize the event for marketing communications related to the event.
We regularly use the following service providers in order to carry out the services provided to you. We have ensured that all of our service providers comply with data protection legislation and, if necessary, have agreed separately to the use of data.
- Accounting firm -
- Website maintenance - Janne Parri Oy, Finland
- Webflow - Webflow Inc., United States
- Zapier - Zapier Inc., United States
- Dropbox - Dropbox Inc., United States
- Google Drive - Google LLC, United States
- Microsoft 365 - Microsoft Corporation, United States
- Google Tag Manager- Google LLC, United States
- Google Analytics - Google LLC, United States
- Google Ads - Google LLC, United States
- ActiveCampaign - ActiveCampaign LLC, Stati Uniti d'America
- Facebook Ads - Facebook Inc., United States
- We may disclose information to a collection agency if it is necessary to monitor the payment
International transfer of your personal data
In principle, your personal data is only stored within the European Union (EU) and the European Economic Area (EEA).
However, we use cloud services, a website platform, advertising services and other applications based in the United States. In this case, it is likely that personal data will be processed outside the EU/EEA. These services and their privacy statements are listed below.
- Webflow Inc., United States - Privacy Statement - PS*
- Dropbox Inc., United States - Privacy Statement - PS*
- Google LLC, United States - Privacy Statement - PS*
- Microsoft Corporation, United States - Privacy Statement - PS*
- ActiveCampaign LLC, United States - Privacy Statement - PS*
- Facebook Inc., United States - Privacy Statement - PS*
- Zapier Inc., United States - Privacy Statement
PS* marked companies operate within the framework of the EU-U.S. Privacy Shield, whereby the transfer of data is legal in accordance with the EU General Data Protection Regulation and the level of data protection is ensured: EU-U.S. Privacy Shield
Your rights
You have the right, among other things, to review your data in our registers, to demand that incorrect information be corrected, the right to delete the data, i.e. the right to be forgotten, the right to transfer your data to another service and the right to restrict the processing of your personal data.
If you want to take any of the previous steps, you can contact the person who handles the registry:
Eksempel Person
Exemplo Kontaktinformasjon
Register-specific information
The previous paragraphs dealt with the management of personal data in general. Companies like us may have several personal data registers. Often companies have a customer register and an employee register. The following information relates to our customer register. You're going to run into the same things in these breakdowns as well.
Name of the registry
Example Company's customer registry
Registrar
Fitme Online Coaching
Person in charge of registry matters
Eksempel Person
Exemplo Kontaktinformasjon
Purpose of processing personal data
The purpose of the processing is to manage the customer relationship, administer it, exercise the rights and obligations of the customer and the controller, and the processing of personal data for purposes related to online services in accordance with the Personal Data Act. In addition, personal data are processed by the controller and companies belonging to the same group at any time for marketing purposes, including direct marketing. Direct marketing can also be carried out electronically.
However, this does not mean that all people on the register end up on the mailing list, for example, after any contact. The customer must always subscribe and confirm the subscription to the newsletter. If you leave a request for quotation on the website, your data may be used on different advertising platforms for targeting and exclusion lists.
Information content of the register
The register may contain the following information. The data contained in the register increases as needed, that is, not all data is collected from all customers. The customer is considered to be in the register if even one personal data is entered in the register.
- person's first and last name
- e-mail address
- postal address
- phone number
- employer (business customers)
- Employer
- Permissions and consents
- location of workplace/office
- information relating to invoicing and collection,
- financial information
- information on processed orders and reservations
- information related to customer relationship and contractual relationship
- unique IP address
- information provided by the data subject
- Information detected from the use of the services
Regular sources of information
The customer can join the register through the contact forms on the site, by purchasing products in the online store, or by personally leaving the information to one of the company's employees.
Retention and protection of data
We are committed to ensuring the security of your data through good data management and careful handling of personal data. We use appropriate technical, physical, legal and organizational measures to protect your data.
We will retain your personal data for as long as necessary for the purposes specified in the data protection and registration statements unless a longer retention period is required or permitted by law.
- As a rule, personal data is processed for a period of two years from the date of sending the last offer or invoice.
- Newsletter subscribers can unsubscribe from the list themselves.
- The data of visitors to the website will be processed for two years,
It should be noted that the controller may have a statutory or other right not to delete the requested information. The controller is obliged to keep the accounting records in accordance with the Accounting Act (Chapter 2, Section 10) for a period of time (10 years). Therefore, material related to accounting cannot be deleted before the expiry of the deadline.
Disclosure of data
We will not disclose your personal data to third parties without your consent unless one of the following conditions is met:
- The disclosure of information is based on a law, regulation or contract binding us.
- We and the third party have an agreement regarding the processing of personal data.
- The disclosure of personal data is necessary for the implementation of a service provided to you.
- Your personal data has been collected in connection with an event organised jointly with our partners. We may disclose your information to the partners who organize the event for marketing communications related to the event.
We regularly use the following service providers in order to carry out the services provided to you. We have made sure that all of our service providers comply with data protection legislation.
- Accounting firm -
- Website maintenance - Janne Parri Oy, Finland
- Webflow - Webflow Inc., United States
- Zapier - Zapier Inc., United States
- Dropbox - Dropbox Inc., United States
- Google Drive - Google LLC, United States
- Microsoft 365 - Microsoft Corporation, United States
- Google Tag Manager- Google LLC, United States
- Google Analytics - Google LLC, United States
- Google Ads - Google LLC, United States
- ActiveCampaign - ActiveCampaign LLC, Stati Uniti d'America
- Facebook Ads - Facebook Inc., United States
- We may disclose information to a collection agency if it is necessary to monitor the payment
Right of review pursuant to Chapter 6, Section 26 of the Personal Data Act
The data subject has the right to inspect the information entered in the register about him, the right to demand the correction of incorrect information and otherwise to rely on his or her rights secured by the Personal Data Act. A written request for verification, erasure and rectification of the data must be addressed to the person responsible for the registry (see: the person in charge of registry matters).
Other rights related to the processing of personal data
The data subject has the right to prohibit the processing of personal data concerning him/her for the purposes of direct marketing, distance selling and other direct marketing, as well as market and opinion research. The ban is entered in the register.
Cookies
We use cookies and other similar methods to provide and develop our websites and services. Our website may also contain other third-party components, for example in relation to social services.
In some cases, these cookies also collect personal data. We treat cookies in more detail in our cookie policy.
At any time, you can block cookies that are not necessary for the functioning of the site from the menu at the bottom left of the page.