Privacy policy

This is the register and privacy statement of Xabis Oy in accordance with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR), drawn up on 26.02.2024. Last updated on 26.02.2024.

Data Controller

Xabis Oy

Särkiniementie 18 A 5

00210 Helsinki

Business ID: 2283743-4

Contact Person for the Register

Karri Haaparinne

kare.haaparinne@outlook.com

040 0830644

Register Name

Xabis Oy Customer Register.

Purpose of Processing Personal Data

The Xabis Oy customer register is used for the maintenance, development, and communication of customer relationships.

The information is not used for automated decision-making or profiling.

Content of the Register

The information stored in the register includes:

  • Name
  • Phone number
  • Company

The information is retained for as long as it is deemed necessary for the customer relationship.

Regular Sources of Information

The information to be stored in the register is obtained from the customer through various channels such as messages sent via web forms, email, telephone, social media services, contracts, customer meetings, and other situations where the customer provides their information. In addition, information may be collected from publicly available sources within the limits allowed by law.

Regular Disclosures of Data and Transfers of Data Outside the EU or EEA

Data is not disclosed outside the EU or EEA. Data may be published to the extent agreed upon with the customer.

Principles of Register Protection

Care is taken in the processing of the register, and the information processed through data systems is appropriately protected. When register information is stored on Internet servers, the physical and digital security of the hardware is ensured adequately. The data controller ensures that the stored information, as well as server access rights and other information critical to the security of personal data, are handled confidentially and only by employees whose job description includes such tasks.

Right of Inspection and Right to Demand Correction of Information

Every person in the register has the right to check the information stored about them in the register and to demand the correction of any incorrect information or the completion of any incomplete information. If a person wishes to check the information stored about them or demand a correction, the request must be sent in writing to the data controller. If necessary, the data controller may request the requester to prove their identity. The data controller responds to the customer within the time limit set by the EU General Data Protection Regulation (usually within one month).

Other Rights Related to the Processing of Personal Data

A person in the register has the right to request the deletion of their personal data from the register (“right to be forgotten”). Similarly, data subjects have other rights according to the EU General Data Protection Regulation, such as restricting the processing of personal data in certain situations. Requests must be sent in writing to the data controller. If necessary, the data controller may request the requester to prove their identity. The data controller responds to the customer within the time limit set by the EU General Data Protection Regulation (usually within one month).