Skip to content

Privacy Policy

Privacy Statement for Customer Register of Rento Hockey Oy

  1. Data Controller

Rento Hockey Oy
Business ID: 3484344–4
Kilpeläntie 7b, 93600 Kuusamo
Phone: +358407339619
Email: rentohockeyshop@gmail.com

  1. Name of the Register
    The name of the register is Rento Hockey Oy's customer register.
  2. Purpose of Personal Data Processing
    Personal data is processed for purposes related to managing, administering, and developing customer relationships, providing and delivering services, billing, and developing services. Personal data is also processed in the investigation of potential complaints and other claims.

In addition, personal data is used for customer communications, such as newsletters, information dissemination, and marketing, including direct marketing and electronic direct marketing.

Customers have the right to opt out of direct marketing directed at them.

The data controller processes the data itself and uses subcontractors who process personal data on behalf of and under the responsibility of the data controller.

  1. Legal Grounds for Processing
    The legal grounds for processing personal data under the EU General Data Protection Regulation (GDPR) are:
  • The data subject has given consent to the processing of their personal data for one or more specific purposes (GDPR Art. 6(1)(a)).
  • Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract (GDPR Art. 6(1)(b)).
  • Processing is necessary for the purposes of the legitimate interests pursued by the data controller or a third party (GDPR Art. 6(1)(f)).

The legitimate interest in this context is based on the meaningful and appropriate relationship between the data subject and the data controller, which arises from the data subject being a customer of the data controller, and when processing takes place for purposes the data subject could reasonably expect when the data was collected.

  1. Content of the Register (Processed Personal Data Groups)
    The register contains the following personal data, typically for all registered individuals:
  • Basic personal details and contact information: [first name, last name, address, phone number, email address];
  • Information related to the person’s company or other organization and their position or job title in that company or organization;
  • Direct marketing consents and objections.
  1. Regular Sources of Data
    Personal data is collected from the data subject themselves.

Personal data is also collected and updated from publicly available sources within the limits of applicable law, related to the implementation of the customer relationship between the data controller and the data subject, and to fulfill obligations related to maintaining customer relationships.

  1. Retention Period for Personal Data
    Personal data collected in the register is kept only as long as necessary in relation to the original or compatible purposes for which the data was collected.

The necessity of data retention is regularly evaluated, and in any case, data about a registered individual is removed from the register once the customer relationship with the data controller has ended and all obligations related to the relationship have been completed. For example, accounting records are kept for five years after the end of the financial year.

The data controller evaluates the necessity of data retention regularly according to internal policies. Additionally, the data controller takes all reasonable steps to ensure that inaccurate, incorrect, or outdated personal data is promptly deleted or corrected.

  1. Recipients of Personal Data (Recipient Groups) and Regular Data Disclosures
    Personal data is not disclosed to external parties.
  2. Transfer of Data Outside the EU/EEA
    Personal data in the register is not transferred outside the EU or EEA.
  3. Principles of Data Protection
    Personal data is stored in locked premises, with access limited to authorized individuals based on their role.

Personal data is stored in databases on servers located in locked spaces, and access is restricted to authorized personnel only. The server is protected by appropriate firewalls and technical security measures.

Access to databases and systems is granted only through personal usernames and passwords. The data controller has restricted access to data systems and storage platforms to those individuals who need the information for legal processing. Access events in databases and systems are logged.

The data controller’s employees and other personnel are committed to confidentiality and to keeping the information received in the course of processing personal data confidential.

  1. Rights of the Data Subject
    The data subject has the following rights under the EU General Data Protection Regulation (GDPR):
  • The right to obtain confirmation from the data controller as to whether their personal data is being processed and, if so, the right to access that data, along with the following information:
    1. Purposes of the processing.
    2. Categories of personal data concerned.
    3. Recipients or categories of recipients of the personal data.
    4. The planned retention period for personal data, or the criteria used to determine that period.
    5. The right to request rectification or erasure of personal data or restriction of processing.
    6. The right to lodge a complaint with a supervisory authority.
    7. Information about the source of the data, if it was not collected from the data subject (GDPR Art. 15).
  • The right to withdraw consent at any time without affecting the lawfulness of processing before the withdrawal (GDPR Art. 7).
  • The right to have inaccurate or incomplete personal data rectified (GDPR Art. 16).
  • The right to have personal data erased without undue delay, if:
    1. The data is no longer needed for the purposes for which it was collected.
    2. The data subject withdraws consent and there is no other legal basis for processing.
    3. The data subject objects to processing for direct marketing purposes.
    4. The data has been processed unlawfully.
    5. Erasure is required to comply with a legal obligation (GDPR Art. 17).
  • The right to restrict processing if the data subject disputes the accuracy of the personal data, if the processing is unlawful, or if the data is no longer needed for processing but is required for legal claims (GDPR Art. 18).
  • The right to receive personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller, if the processing is based on consent and is carried out automatically (GDPR Art. 20).
  • The right to lodge a complaint with a supervisory authority if the data subject believes that the processing of their personal data violates the GDPR (GDPR Art. 77).

Requests related to exercising these rights should be directed to the contact person of the data controller mentioned in section 1.

  1. Web Analytics
    The following services collect anonymized data about website visits without using personal information:
  • Google Analytics
  • Facebook Pixel