Privacy policy

This is the privacy policy of Tomtoi Oy in accordance with the EU General Data Protection Regulation (GDPR). Last modified 31.12.2023

1. Data controller

Tomtoi Oy, Tolkkisten Satamatie 2, 06750 Tolkkinen [email protected]

2. Name of the register

Tomtoi Oy Privacy Policy

3. Legal basis and purpose of the processing of personal data

Tomtoi Oy operates a website (“Service”) and processes personal data of users and visitors to the Service in order to conduct its business and provide the Service. Tomtoi Ltd may also process information to improve and develop the Service and its business. Data of visitors to the Service is also processed to ensure the functionality of the Service and for the development of the Service.

The processing of personal data is based on Tomtoi Oy’s legitimate interests and, in the case of users, to fulfil its obligations under contractual relationships. Tomtoi Oy’s legitimate interests in this context are to conduct, maintain and develop its business, to market and promote sales, to manage customer relations and to deal with any claims that may be made. In addition, Tomtoi Ltd may process personal data to comply with a legal obligation (e.g. accounting obligations and taxation).

If you choose not to provide Tomtoi Ltd with the information requested in connection with your use of the Service, Tomtoi Ltd may not be able to provide you with the full features and functionality of the Service.

The information will not be used for automated decision making or profiling.

4. Data content of the register

The information stored in the register includes: the name of the person, the company/organisation, contact information (phone number, e-mail address, address), website addresses, information about the services ordered and any changes thereto, billing information, other information related to the customer relationship and the services ordered. In addition, analytical data obtained through the cookies on the website are stored.

The data will be stored only for the time necessary to provide the Service or for the other purposes described above, or for the time that Tomtoi Ltd is required to retain the data by law. We may retain personal data for longer periods to the extent necessary to respond to legal claims and to defend ourselves. The retention period will therefore depend on the personal data concerned.

The IP addresses of visitors to the website and cookies necessary for the operation of the service are processed for legitimate interests, including for security purposes and for the collection of statistical data on visitors to the website where they can be considered to be personal data. Third party cookies are subject to separate consent where necessary.

5. Regular sources of information

The information stored in the register is obtained from the customer through, for example, messages sent via web forms, email, telephone, social media services, contracts, customer meetings and other situations where the customer discloses their information. Information from contact persons of companies and other organisations may also be collected from public sources such as websites, directory services and other companies.

6. Regular disclosures and transfers of data outside the EU or EEA

In principle, personal data will not be disclosed to anyone outside Tomtoi Oy’s organisation other than the subcontractors/service providers used by Tomtoi Oy. Tomtoi Oy is responsible for the actions of subcontractors as if they were its own and will ensure that subcontractors process personal data only for the purposes set out in this Privacy Policy and in accordance with Tomtoi Oy’s instructions and applicable law.

Personal data may be disclosed to other third parties only if required by law or if necessary to comply with legal requirements and to protect the interests of Tomtoi Ltd.

In addition, personal data may be disclosed to a third party if Tomtoi Oy is party to a business transaction (such as a business sale or merger). Tomtoi Oy will ensure that personal data remains confidential in these situations as well.

In principle, personal data will not be transferred to third countries. If data is transferred outside the European Economic Area, Tomtoi Oy will take all measures required by law to ensure that the level of protection of personal data is adequate also in the country to which the personal data is transferred.

7. Principles of protection of the register

The register is processed with due care and the data processed by the information systems are adequately protected. Where the data are stored on Internet servers, the physical and digital security of their hardware shall be adequately ensured. The controller shall ensure that stored data, as well as access rights to servers and other information critical to the security of personal data, are treated confidentially and only by employees whose job description includes this.

8. Right of inspection and right to request correction of information

Every person in the register has the right to check the information stored in the register and to request that any inaccurate or incomplete information be corrected or completed. If a person wishes to check or request a correction of the data stored about him or her, the request should be sent by e-mail to the controller. The controller may, if necessary, ask the person making the request to prove his or her identity. The controller will reply to the customer within the time limits set by the EU General Data Protection Regulation (as a general rule, within one month).

9. Other rights related to the processing of personal data

A person in the register has the right to request the erasure of personal data concerning him or her from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of processing of personal data in certain circumstances. Requests should be sent by e-mail to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will respond to the customer within the time limits set by the EU GDPR (as a general rule, within one month).

Log in