Privacy Policy and Data Protection Statement
This is the EU General Data Protection Regulation (GDPR) compliant privacy and data protection statement of Elcoline Oy. Created on 17 August 2022. Last updated on 26 August 2025.
1. Data Controller
Elcoline Group Oy
Puutarhatie 24 D
FI-01300 Vantaa, Finland
2. Contact Information for Registry Matters
Phone: +358 20 155 6300
Email: info@elcoline.fi
3. Name of the Registry
Customer and marketing registry of the company.
4. Legal Basis and Purpose of Processing Personal Data
The legal basis for processing personal data under the GDPR includes the individual’s consent, the legitimate interest of the data controller (direct marketing), and the management of customer relationships.
The purpose of processing personal data is to maintain contact with customers, manage customer relationships, conduct marketing, compile statistics, perform analysis, and support development.
Data is not used for automated decision-making or profiling.
5. Data Content of the Registry
The registry may contain the following information: name, position, company/organization, contact details (phone number, email address, postal address), website URLs, IP address of the network connection, social media profiles, details of subscribed services and changes to them, billing information, and other data related to the customer relationship and subscribed services.
IP addresses of website visitors and cookies necessary for service functionality are processed based on legitimate interest, e.g., for security and statistical purposes when such data is considered personal. Consent is requested separately for third-party cookies when necessary.
6. Regular Sources of Data
Data stored in the registry is obtained from the customer via web forms, email, phone, social media services, contracts, customer meetings, and other situations where the customer provides their information.
Contact details of representatives of companies and other organizations may also be collected from public sources such as websites, directories, and other companies.
7. Regular Disclosures and Transfers Outside the EU/EEA
Data is not regularly disclosed to third parties. Data may be published to the extent agreed with the customer.
8. Principles of Registry Protection
The registry is not disclosed to outsiders. Access requires internal user rights within Elcoline Group Oy. The registry is stored on a password-protected server and customer information system.
A. Manual Data
Personal data is protected against unauthorized access and unlawful processing (e.g., destruction, alteration, or disclosure). Each handler may only process personal data necessary for their tasks.
Documents are stored in locked premises protected from outsiders. Paper documents are printed only when necessary and destroyed after use.
B. Automatically Processed Data
Electronically processed data in the registry is protected by firewalls, passwords, and other generally accepted technical security measures.
Only designated employees of the data controller and its authorized partners have access to the data, granted by the data controller.
9. Right of Access and Rectification
Every individual in the registry has the right to inspect their stored data and request correction of any inaccurate or incomplete information
Requests must be submitted in writing to the data controller. The data controller may request proof of identity. The response will be provided within the timeframe set by the GDPR (typically within one month).
10. Other Rights Related to Personal Data Processing
Individuals have the right to request deletion of their personal data (“right to be forgotten”). They also have other rights under the GDPR, such as restricting processing in certain situations.
Requests must be submitted in writing to the data controller. The data controller may request proof of identity. The response will be provided within the timeframe set by the GDPR (typically within one month).