Privacy
Privacy Policy
This is Hostaan Oy's register and privacy policy under the EU General Data Protection Regulation (GDPR).
1. Data controller
Hostaan Oy
Snellmaninkatu 36-38
70100 Kuopio, Finland
2. Contact person responsible for the register and data protection officer
Juha Kouvalainen
+358 17 5800 500
tuki@hostaan.fi
3. Name of the register
Hostaan Oy customer, marketing, stakeholder, and web service user register
4. Legal basis and purpose of processing personal data
Under the EU General Data Protection Regulation, the legal bases for processing personal data are:
– The order agreement to which the data subject is a party
– The data controller's legitimate interest arising from the customer relationship or use of our services
We collect, store, and process personal data only for predetermined purposes, which are:
– Maintaining our services and managing customers
– Customer service and billing
– Communicating with customers and stakeholders
– Marketing for our own purposes
5. Contents of the register
The data stored in the register includes a person's name, position, organization, organization identifier, billing and contact details (address, phone number, email address), personal identity code (when needed for domain registration), usernames and IP addresses, details of ordered services and their changes and payment history, details of other users of the service, technical logs of all use of our services, and other information necessary for managing the customer relationship.
6. Regular sources of data
Information customers provide about themselves, and marketing restrictions they set. Information that accumulates over the course of the customer relationship. Information collected in connection with using the services.
7. Processing and disclosure of personal data to third parties
Your personal data is only processed by our own personnel, always confidentially and only to the extent necessary for their work duties. Data is disclosed to partners only for purposes that support the register's stated purpose.
Personal data may be disclosed to our subprocessors only when necessary for providing the service. A detailed list of subprocessors can be found in our Data Processing Agreement (DPA). Personal data is not otherwise transferred outside the EU/EEA.
We may be required to disclose data at the request of an authority or by court order, in order to investigate a crime or misuse.
8. Principles of register protection and data retention period
The register is processed with care, and data processed with the help of information systems is appropriately protected. Manually processed material is stored in premises to which unauthorized persons do not have access. Where register data is stored on internet servers, the physical and digital security of the underlying hardware is properly taken care of. The data controller ensures that stored data, server access rights, and other information critical to the security of personal data are handled confidentially and only by those employees whose work duties require it.
After the customer relationship ends, personal data is retained for as long as is necessary for the purpose that supports the register's stated purpose, and for as long as legislation requires for certain data (for example, the requirements of accounting legislation regarding invoicing records).
9. Right of access and right to request correction or deletion of data
Every person in the register has the right to inspect the data stored about them and to request that any incorrect data be corrected, that incomplete data be completed, or that data concerning them be deleted ("the right to be forgotten"). If a person wishes to inspect the data stored about them, request a correction to it, or request that it be deleted, they must contact the data controller in writing. The data controller may, if necessary, ask the person making the request to verify their identity, and reserves the right to respond within the time specified in the EU data protection regulation (as a rule, within one month).