Privacy Policy
Tietokettu save and processes personal data in accordance with the EU
GDPR and the current General Data Protection Regulation (679/2016).
This Privacy Policy has been prepared in
accordance with Section 4 of the Personal Data Act
Updated 3.4.2024
1) Registrar
Tietokettu (HD-decor oy)
Business ID: 0706238-6
Rantaharju 15
37500 Lempäälä
2) Register contact person
Registrar / Data Protection Officer:
Kimi Syrjä
kimi.syrja@tietokettu.net
+358 44 204 2526
3. Purpose of personal data processing
We use personal data for invoicing, administration and internal marketing. Internal marketing includes newsletters if you have subscribed to them. If you do not accept the processing of your data in our service, you must stop using the service immediately and request the deletion of your data.
4. Legal basis for the processing of personal data
The processing of personal data is based on the consent given by the data subject. If you do not accept the processing of your data in our service, you must stop using the service immediately and request the deletion of your data.
5. Data content of the register
Data stored in the register:
- Name
- Personal identity number (required for domain registration by individuals and dedicated server purchases)
- Email address
- Company name (if applicable)
- Address
- Phone number
- IP address history, operator and login history
- Place of residence, province and postal code
- Information collected through browser cookies
- Tax number (if applicable)
- Registration date
Purchase history and customer payment transaction identifiers and used payment method
Customer statistics (e.g. CPU usage history, disk space usage, network usage and history, and IO usage and history)
Information collected through browser cookies
Use of personal identity number:
The personal identity number is required for the registration of some domain names by individuals and for the purchase of dedicated servers.
Billing information:
Billing information, such as name, email address, company name, address, phone number, residence information, tax number and purchase history, is stored for 10 years for accounting purposes. Therefore, this information cannot be deleted even if the customer requests it separately.
Inactive customer accounts:
Inactive customer accounts that have not been logged in or made any purchases for 5 years will be automatically deleted, including all of the above information.
6. Regular data sources
Data provided by the customer during registration or purchase. Additionally, customer-related data is automatically collected when the customer uses our website.
7. Regular transfers of information
Information is not regularly disclosed to third parties without the customer's consent. When necessary, information is disclosed to third parties in accordance with Section 8 of the Personal Data Act.Information is disclosed outside the EU or EEA in the following situations:
- When the customer has given their consent to the disclosure.
- When the disclosure is necessary for the performance of a contract between the customer and the company.
- When the disclosure is required by law.
- When the disclosure is necessary to protect the vital interests of the customer or another natural person.
In other cases, information is not disclosed outside the EU or EEA. Such situations include, for example, the transfer or registration of a .FI domain name, where we provide information to the Finnish Communications Regulatory Authority.
8. Principles of personal data protection
The documents are kept in a locked room where access is limited only to those employees who have the highest right to process the materials. Data is destroyed by shredding and then burning.Access to electronic information is limited only to those employees who have the right to do so. The registrar takes care of data security and that the data cannot be accessed by parties to whom the data does not belong. Data is stored on iron, to which only some of the employees who have the rights to maintain the equipment have access. The servers are protected by a firewall and the hardware cannot be accessed, as they are in a locked space with access control. The servers are located in Lempäälä in Tietokettu's own premises.
When disposing of old metal such as hard drives, we destroy the hardware so that no data can be read or compiled from it, which could end up in the wrong hands.
9. Rights of the registrant
Right of access (inspection right)
The data subject has the right to check what information about them is stored in the data controller's systems. The right of inspection may be denied on the grounds provided for by law.
Right to demand rectification of data
The data subject has the right to demand that the data controller rectify inaccurate and erroneous personal data concerning them without undue delay. Taking into account the purposes for which the data was processed, the data subject has the right to have incomplete personal data completed, including by providing a supplementary statement.
Right to demand erasure of data and the right to withdraw consent given
The data subject has the right to obtain from the controller the erasure of personal data concerning them under certain conditions, such as when the basis for processing the personal data no longer exists or the data subject withdraws their consent to the processing of their personal data. If there is no other legal basis for the processing than consent, the controller must then delete the data subject's personal data.
The right to erasure of data does not apply in certain exceptions provided for by law, for example, when the data is processed for the performance of a legal task.
Data erasure is done by creating a support request on our website (https://tietokettu.net) in which you request the data to be deleted. If this proves difficult, you can ask the data controller for help.
Right to restrict processing
The data subject has the right to demand that the data controller restrict the processing of their personal data, for example, when the data subject is waiting for the data controller's response to a request to rectify or delete their data.
Right to data portability
To the extent that the data subject has personally provided data to the customer register, which is processed on the basis of the data subject's consent or contract, the data subject has the right to receive such data in a structured, commonly used and machine-readable format and to transmit such data to another controller.
Right to object to processing
The data subject has the right to object to the processing of their data on certain grounds, such as profiling and direct marketing.
Right to lodge a complaint with the supervisory authority
The data subject has the right to lodge a complaint with the competent supervisory authority if the data controller has not complied with the applicable data protection regulations in its activities.
The contact person for matters relating to the data subject's rights is the data protection officer, contact details in section 2 of the statement.
PayPal Holdings, Inc
Purpose of disclosure: Processing of payment transactions
Data transferred: First name, last name, email address, payment card information, account number, account holder, necessary browser cookies and IP address
Privacy: https://www.paypal.com/webapps/mpp/ua/legalhub-full