PRIVACY POLICY

Register and Privacy Policy

This is a Registry and Privacy Statement in accordance with the Company Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR).
Created 01.10.2019. Last modified 01.10.2019.

1. Register Keeper

Loota Music Oy
Lehtikuja 8 A
60150 Hyllykallio
Finland
Europe

2. Person Responsible for the Register

Mika Lilja
lootaverstas(at)gmail.com
+358 40 587 5056

 

3. Name of the Register

This is Loota Music Oy’s customer register and marketing register.

 

4. Legal Basis and Purpose of the Processing of Personal Data 

The legal basis for the processing of personal data under the EU General Data Protection Regulation is
– individual consent
The purpose of processing personal data is to communicate with customers, maintain customer relationships, marketing, etc.

The information will not be used for automated decision making or profiling, nor will it be disclosed to third parties, nor will it be used for purposes other than customer relationship management and marketing.

 

5. Information Content of the Register

The information to be stored in the register is as follows:
the person’s name and contact information, the IP address of the online connection, the IDs / profiles on the social media services, information about subscribed services and changes thereto, billing information, other customer relationship and subscribed services information.

 

6. Regular Sources of Information

Information stored in the register can be obtained from the customer eg. messages sent via web forms, email, telephone, social media services, contracts, customer meetings and other situations where a customer discloses information.

 

7. Regular Disclosures and Transfers of Information Outside the EU or the EEA

Information is not routinely disclosed to other parties. The information may be published to the extent agreed with the customer.

Data may also be transferred by the controller outside the EU or the EEA.

 

8. Registry security principles

The records shall be handled with care and the data processed by the information systems shall be appropriately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is properly taken care of. The data controller shall ensure that the stored information, as well as server access and other information critical to the security of the personal data, is treated confidentially and only by the employees whose job description it is included in.

 

9. Right of Inspection and the Right to Have Data Rectified

Every person in the register has the right to verify their data stored in the register and to request the correction of any inaccurate or incomplete information. If a person wishes to check or rectify the information stored about him / her, the request must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his identity. The controller will respond to the client within the time limit set by the EU Data Protection Regulation (as a rule within one month).

 

10. Other Rights Related to the Processing of Personal Data

A person on the register has the right to request that personal data relating to him be removed from the register (“the right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as restricting the processing of personal data in certain situations. Requests should be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his identity. The controller will respond to the client within the time limit set by the EU Data Protection Regulation (as a rule within one month).