Membership register privacy policy
This privacy policy applies to the processing of personal data in the Finnish Commerce Federation’s membership register.
1. Data controller
The Finnish Commerce Federation is the data controller and is responsible for the processing of personal data. For the membership register, you can contact the controller in the following ways:
- tietosuoja@kauppa.fi
- tel. +358 9 1728 5151
- Eteläranta 10, PL 340, FI-00131 HELSINKI, FINLAND
2. What information do we process?
In the membership register, we process, for example, the following information on the representatives of the member companies:
- personal data necessary for the monitoring of communications, such as the contact information of the person, for example, first and last name, job title, organisation, e-mail address, telephone number and time of contact
- username for the membership pages
- activities concerning studies and surveys
- caller IDs
- technical information to ensure the quality of service
Personal data have been obtained from the data subject themself or the member company.
3. For what purposes and for how long is your personal data processed?
The purposes of the processing of personal data and the data retention period for each purpose are described in the table below. We process personal data primarily on a membership basis to enforce the agreement. If necessary, we may send direct marketing to implement the legitimate interests of the Data controller.
Purpose of processing | Processed categories of personal data | Data retention period |
Studies and surveys | Name, e-mail address, organisation, position in the company, study/survey answers | The data is kept until the study/survey is completed. Unnecessary data is deleted from the system every year. |
Kauppa.fi member service | Name, username, e-mail address, organisation, telephone number, position in the company and technical information to ensure the quality of service | The information is kept until the end of the membership. |
Membership advisory service | Name, job title, organisation, e-mail address, telephone number, time of activity | The need for data retention is regularly assessed; at the same time unnecessary data is deleted. |
Membership newsletter | Name, e-mail address, information about openings and clicks, information on cancellation | Your personal data will be removed from the mailing lists immediately upon cancellation of the subscription and will be moved to the Cancelled list. In this way, we can technically ensure that the person no longer receives membership newsletters. Data will be removed from the Cancelled list annually upon the termination of membership. |
Management of the joint membership register of the Confederation of Finnish Industries (EK) and the Finnish Commerce Federation | Name, job title (title and role), contact information (e-mail address, telephone number and mailing address) | The data is processed for the membership register managed by the Confederation of Finnish Industries (EK). In the register, EK and the Finnish Commerce Federation maintain information on the managing directors of the member organisations of the Finnish Commerce Federation and the contact persons notified by the organisations.
The need to use personal data is assessed regularly, generally on an annual basis. Unnecessary data is deleted and incorrect data is corrected. |
In addition, we may process personal data to comply with a legal obligation under the statute of limitations, for example based on accounting or labour legislation, or when the processing is necessary to prepare, file or defend a legal claim.
4. What rights do you have?
1. You have the right to know, at your request, whether the Data controller processes your personal data. If we process your personal data, you have the right to receive a copy of the information we process. If we do not process your personal data, you have the right to receive confirmation of this as well.
2. You have the right to demand rectification or supplement of your personal data that is incorrect or incomplete in terms of processing
3. You may have the right to have the controller erase your personal data in certain situations covered by the Regulation. We will erase the personal data at your request if the criteria set out in the legislation are met.
- According to the Regulation, you have the right to have the Data controller erase your personal data from our system if
- your personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed; or
- you object, referring to personal reasons, to processing that is necessary for implementing the legitimate interests of the Data controller or a third party, such as profiling;
- In this case, the Data controller may no longer process the personal data unless the controller can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or if it is necessary for the establishment, exercise or defence of a legal claim.
- your personal data have been processed unlawfully;
- your personal data have to be erased to meet a statutory obligation arising from EU or Member State law to which the Data controller is subject;
- the personal data have been collected from a child in relation to the offer of information society services.
4. You may have the right to restrict the processing of your personal data. We will limit the processing of your personal data at your request in the case of situations defined by law.
- You may restrict the processing of your personal data if
- you contest the accuracy of your personal data, in which case the processing is restricted for the period during which we are able to verify the accuracy of the personal data;
- the processing is unlawful and you object to the deletion of personal data and request the restriction of its use instead;
- the personal data in question is no longer required by the Data controller for the purposes of the processing, but are required by the data subject for the establishment, exercise or defence of a legal claim; or
- you have objected on grounds relating to personal reasons, to processing that is necessary for either the performance of a task concerning the public interest or in the exercise of official authority vested in the Data controller or in implementing the legitimate interests of the Data controller or a third party pending the verification whether the legitimate grounds of the controller override your legitimate grounds.
- If the processing of your personal data is restricted, the personal data shall, with the exception of storage, only be processed with your consent; or to establish, exercise or defend a legal claim; or protect the rights of another natural or legal person; or for reasons of important public interest of the EU or of a Member State.
- You may have the right to object to the processing of your personal data. We will no longer process your personal data at your request in the case of situations defined by law.
- You can object to the processing of your personal data
- that is necessary for implementing the legitimate interest of the controller or a third party, such as profiling, referring to personal reasons;
- In this case, the Data controller may no longer process the personal data unless the controller can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or if it is necessary for the establishment, exercise or defence of a legal claim.
- at any time, if your personal data are processed for the purpose of direct marketing, including profiling, where it relates to such direct marketing.
5. How do you exercise your rights?
You can send us a request to exercise your rights by filling out the form on our website and sending it to us signed either by e-mail or by mail to the Data controller’s address.
If the response contains your personal data, we will primarily provide the information by mail as a registered letter. The letter cannot be acknowledged as received by anyone other than the person marked as the recipient. This will ensure the confidentiality of the data of the correct recipient of the letter.
6. About the recipients of personal data
The Finnish Commerce Federation, as the Data controller, processes personal data itself but also uses various service providers. The Finnish Commerce Federation strives to use the best and most reliable partners and is responsible for the activities of the service providers of its choice when processing personal data.
The Finnish Commerce Federation uses external service providers to carry out, for example, the management of the membership register, financial management, training, communication services and the maintenance and development of the other applications it uses.
Our service provider may transfer personal data outside the EU or the European Economic Area when the service provider is established outside these territories. In these cases, we will take appropriate safeguards to ensure the rights and freedoms of the data subjects.
In addition, the Finnish Commerce Federation acts as a joint Data controller with the Confederation of Finnish Industries (EK) as described in section 3.
Some authorities also have a statutory right of access to information. Such authorities include, for example, the police, the customs, the border guard and tax authorities.
7. Appeal instructions
If you feel we are not processing your personal data in accordance with the EU’s General Data Protection Regulation, you can file a complaint with the supervisory authority in the EU Member State where you have your permanent address or workplace or where you believe the breach has taken place. In Finland, this authority is the Data Protection Ombudsman.
8. Personal data necessary for the membership register
In order to provide you with the benefits or services mentioned in the agreement, we must process the personal data necessary to implement the membership agreement. Such information is the personal data described in section 3.
9. Use of personal data for other purposes
We will not use your personal data for purposes other than those stated in this document. If new needs for use arise later, we will inform you and provide you with the legal processing criteria for the processing of your personal data or, if necessary, we will ask you for your consent to the processing of your personal data for new uses.