Register and Privacy Policy

This is NetSono Oy’s register and privacy policy in accordance with the EU General Data Protection Regulation (GDPR).

Created on 25.07.2023.
Last modified on 25.07.2023.

1. Controller

Name: Netsono Oy
Address: Kaplaskuja 11, FI-90650 Oulu, Finland
Business ID: 2490789-7

2. Contact person for register matters

Contact: Mika Haapea
Address: Kaplaskuja 11, FI-90650 Oulu, Finland
Phone number: +358 40 805 2717
E-mail address: mika.haapea@netsono.com

3. Name of register

Customer register

4. Legal basis and purpose of the processing of personal data

The purpose of processing personal data is to contact customers.

Personal data is collected for a specific, explicit and legitimate purpose in order to fulfill the contractual obligations of the customer relationship. Personal data is collected in accordance with this Privacy Policy and will not be used, modified or transferred in any way other than as set out in this Privacy Policy.

The data will not be used for automated decision-making or profiling.

5. Data content of the register

The information stored in the register includes:

  • Through the contact form:
    • First and last name of the person
    • Phone number
    • E-mail address
    • Content of the message
    • Browser’s user-agent
  • By e-mail or telephone:
    • E-mail address
    • Phone number
    • Content of the message

The following information is stored only for statistical purposes. This data is not treated as personal data because it is strongly anonymized and cannot be linked to an individual person:

  • The website through which you visited our site
  • The parts of our website you visit
  • Date and duration
  • Anonymized IP address
  • Device information:
    • Type of device
    • Operating system
    • Display resolution
    • Language
    • Country of location
    • Browser type

6. Cookies

Our website only uses cookies that are necessary to ensure the technical functionality of the website and are not used for any other purpose. These cookies cannot be disabled. We also do not use third party services where cookies are required.

Necessary cookies:

  • elementor
    • Stores information about the user’s visit, this information is not collected or used for anything. The cookie is deleted at the end of the session.
  •  pll_language
    • Stores information about the user’s language choice and saves it for the next visit to the site. The cookie is valid for one year.
  • _lscache_vary
    • Used to improve site performance.The cookie is valid for two days.

7. Regular sources of information

The information stored in the register is obtained from the customer through, for example, messages sent via web forms, e-mail, telephone, contracts, customer meetings and other situations in which the customer discloses their information.

8. Regular disclosures and transfers of data outside the EU or EEA

The data are not regularly disclosed to other parties, nor transferred outside the EU or EEA by the controller. Data may be published to the extent agreed with the customer.

In individual cases, the controller will disclose the customer’s data to a designated party if the party concerned requests the controller to do so or if, by law, a public authority with the force of res judicata requires the controller to disclose individually identifiable information from a database held by the controller.

9. Principles for the protection of the register

The register is processed with due care and the data processed by the information systems are adequately protected. Where the data are stored on Internet servers, the physical and digital security of their hardware shall be adequately ensured. The controller shall ensure that stored data, as well as access rights to servers and other information critical to the security of personal data, are treated confidentially and only by employees whose job description includes this.

10. Right of inspection and right to request correction of information

Every person in the register has the right to check the information stored in the register and to request that any inaccurate or incomplete information be corrected or completed. If a person wishes to check or request a correction of the data stored about him or her, the request should be sent by e-mail to the controller. The controller may, if necessary, ask the person making the request to prove his or her identity. The controller will reply to the customer within the time limits set by the EU General Data Protection Regulation (as a general rule, within one month).

11. Other rights related to the processing of personal data

A person in the register has the right to request the erasure of personal data concerning him or her from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of processing of personal data in certain circumstances. Requests should be sent by e-mail to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits set by the EU GDPR (as a general rule, within one month).