This is a register and privacy policy of Strömfors Business Park Ltd in accordance with the EU General Data Protection Regulation (GDPR).

1. The controller

Strömforsin Business Park Oy

Malminsuontie 6

49220 Siltakylä

info@stromforsinruukki.com

2. Contact person responsible for the register

Päivi Muurikainen

info@stromforsinruukki.com

The controller will respond to questions and feedback about the register.

3. Name of the register

Strömforsin Business Park Ltd customer register.

4. Purpose of processing personal data

We use personal data in accordance with the law for purposes such as: managing and maintaining customer relationships, sending customer communications, developing services and business, and communicating with business customer contact persons.

5. Data content of the register

The information stored in the register includes: name of the person, company/organisation, contact details, website addresses, IP address of the network connection, information on purchased services and changes thereto, billing information, payment information and other information related to the customer relationship and the services ordered.

The IP addresses of visitors to the website and the cookies necessary for the functioning of the service are processed for legitimate interests, such as ensuring data security and collecting statistics on visitors to the website in cases where they can be considered as personal data. Third party cookies are subject to separate consent where necessary.

6. Regular sources of information

The information stored in the register is obtained from the customer through, for example, messages sent via web forms, email, telephone, social media services, contracts, customer meetings and other situations where the customer discloses their information. Information from contact persons of companies and other organisations may also be collected from public sources such as websites, directory services and other companies.

7. Regular disclosures and transfers of data outside the EU or EEA

Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer. Data will not be transferred outside the EU or EEA.

8. Principles of register protection

The register is processed with due care and the data processed by the information systems are adequately protected. Where the data are stored on Internet servers, the physical and digital security of their hardware shall be adequately ensured. The controller shall ensure that stored data, as well as access rights to servers and other information critical to the security of personal data, are treated confidentially and only by employees whose job description includes this.

9. Right of inspection and right to request correction of information

Every person in the register has the right to inspect the data recorded in the register and to request the correction of any inaccurate or incomplete data. If a person wishes to check the data recorded about him or her or to request a correction. The request must be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits laid down in the EU General Data Protection Regulation.

10. Other rights relating to the processing of personal data

A person in the register has the right to request the deletion of personal data concerning him or her from the register. Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of processing of personal data in certain circumstances. Requests should be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits laid down in the EU GDPR.