Privacy statement

This is the registration and data protection statement of Niocell Oy in accordance with the EU General Data Protection Regulation (GDPR).

1. Registrar

Registrat: Niocell Oy

Business ID: 3364019-4

Address: Komeetankuja 3 B, 02210 Espoo

Email: info@niocell.com

2. Contact person responsible for the register

Contact person: Tomas Toro

Email: info@niocell.com

3. Register name

Niocell Oy's customer register

4. Legal basis and purpose of processing personal data

The legal basis for processing personal data according to the EU General Data Protection Regulation is

– an agreement to which the data subject is a party.

The purpose of processing personal data is to keep in touch with customers.

5. Information content of the register

The information stored in the register is: person's name, company/organization, phone number, email address, website addresses, IP address of the network connection, information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services.

IP addresses of website visitors and cookies that are necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to take care of information security and for the collection of statistical data of website visitors in those cases when they can be considered as personal data. If necessary, consent is requested separately for third-party cookies.

6. Regular data sources

The data to be stored in the register is obtained from the customer, e.g. From messages sent via www forms, by e-mail, by phone, through social media services, contracts, customer meetings and other situations where the customer discloses their information.

Information about companies and other organizations' contact persons can also be collected from public sources such as websites, directory services and other companies.

7. Regular transfers of data and transfer of data outside the EU or EEA

Data is not regularly transferred to other parties. Information can be published to the extent agreed with the customer.

Information will not be disclosed or transferred outside the EU or the European Economic Area.

8. Principles of register protection

Care is taken when processing the register, and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.

9. Right of inspection and right to demand correction of information

Every person in the register has the right to check their information stored in the register and to demand correction of any incorrect information or completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing or electronically to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller will respond to the customer within the time stipulated in the EU data protection regulation (generally within a month).

10. Other rights related to the processing of personal data

A person in the register has the right to request the deletion of personal data about him from the register ("right to be forgotten"). Data subjects also have other rights according to the EU General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests should be sent in writing or electronically to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).