1. The controller
W2M Industries Oy, Koivulendontie 2, 01510 Vantaa Finland
2. Contact person responsible for the register
+358 500 438 747
3. The name of the registry
W2M Industries Oy’s customer and marketing register.
4. Legal basis and purpose of the processing of personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is
– consent of the person (documented, voluntary, individualized, informed and unambiguous)
– an agreement to which the data subject is a party
– the legitimate interest of the controller (eg pre-contractual customer relationship, employment relationship, membership).
The purpose of processing personal data is to communicate with customers, maintain a customer relationship, marketing, etc.
The data is not used for automated decision making or profiling.
5. Information content of the register
The information stored in the register is: person’s name, position, company / organization, contact information (phone number, e-mail address, address), website addresses, IP address of the network connection, IDs / profiles in social media services, information about subscribed services and their changes, billing information, other information related to the customer relationship and the services ordered.
The IP addresses of the visitors of the website and the cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to ensure data security and to collect statistics about visitors to the Site in cases where they may be considered personal data. If necessary, the consent of third-party cookies will be requested separately.
6. Regular sources of information
The information stored in the register is obtained from the customer e.g. Messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information.
Contact information for companies and other organizations can also be collected from public sources such as websites, directory services, and other companies.
7. Regular transfers of data and transfers of data outside the EU or the EEA
The information is not regularly disclosed to other parties. The information may be published to the extent agreed with the customer.
The data may also be transferred by the controller outside the EU or the EEA.
We use Google Analytics and Albacross to track traffic to our public website and target sales. Both operate independently under their own privacy clauses and we strongly encourage you to review them:
GDPR – Albacros
8. Registry Security Principles
The register shall be handled with due care and the data processed by the information systems shall be adequately protected. When registry data is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it belongs to.
9. Right of inspection and right to request rectification of information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check or request the rectification of data stored about him or her, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
10. Other rights related to the processing of personal data
A person in the register has the right to request the removal of his or her personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU’s general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
A cookie is a small text file that is stored on a user’s device by an Internet browser. Cookies are set on the user’s terminal only with the site the user invites. Only the server that sent the cookie can later read and use the cookie. Cookies or other technologies do not damage the user’s terminal or files, and cannot be used to access programs or spread malware. The user cannot be identified by cookies alone.
Cookies are divided into subcategories: mandatory cookies, functional cookies, product development and business reporting, advertising reporting, and advertising targeting. Mandatory cookies cannot be blocked. They are related to security and enabling the site. Mandatory cookies do not contain personally identifiable information.
There are some third-party tools or plug-ins that are relevant to the operation of the service:
Embedded social media or video services on the sites, or social media sharing and liking capabilities, may collect information about users of online services, for example, to recommend content or track traffic.
Cookies used to improve our service allow us to track visits and traffic sources in order to measure and improve the performance of our website. With the help of cookies, we are able to develop our service for the best of our customers. If you do not allow these cookies, we will not know when you visited our site and we will not be able to track your activity. These cookies do not contain personally identifiable information.
You can read more about cookies and Finnish cookie recommendations on Traficom’s website
We reserve the right to update our cookie policies, for example, due to service developments or mandatory legislation.