Pentik Oy Privacy Statement
1. Controller and contact information
Pentik Oy (Business ID: 0210532-4)
Maaninkavaarantie 4 A
97900 Posio
Tel. +358 16 3722 272
Fax. +358 207 220 201
E-mail: tietosuoja@pentik.com
For written inquiries, please specify "data protection matters" in the message. Upon contact, you will be assigned a contact person to handle your matter.
2. Purpose and basis for processing personal data
The purpose of processing and using personal data is to process orders, typically based on a contract, for consumer customers (B2C) and corporate customers (B2B), as well as to manage, prepare, communicate, maintain, administer, and analyze other customer relationships. For consumer customers, data related to loyalty programs (Pentik Klubi) is also processed. For B2B customer data, information about partners belonging to stakeholder groups is also processed in relation to the nature of the cooperation. The data may also be used for developing the controller's business operations, customer service, and stakeholder relationships. The controller may also have a statutory obligation to process data.
The controller, any joint controller or contractual partner, or companies belonging to the same group as the controller, may have the right to use personal data for advertising, distance selling, or other direct marketing, opinion or market research, or other similar targeted mailings, including informing about loyalty benefits, electronic direct marketing (email and SMS marketing), and targeting direct marketing, as well as improving business operations, based on, among other things, the person's consent or legitimate interest. The data subject has the right to prohibit direct marketing. Despite the prohibition, data subjects may be sent information concerning their customer relationship or loyalty if it is necessary for managing the customer or loyalty relationship.
For camera surveillance, the purpose of processing personal data is to prevent crimes, ensure the safety and legal protection of staff, and protect property and information. Register data is used to investigate criminal and damage incidents and, if necessary, to identify individuals who have moved within the premises.
3. Data processed
The data processed includes:
Basic information
- first and last name (possible contact person role, title)
- company
- contact information (phone number, email address, and postal address)
- gender
- date of birth
- language of communication
Information related to customer relationship, loyalty program, and other relevant connections
- identification data related to the use of services (e.g., customer number, usernames, and passwords)
- start date of customer relationship or cooperation
- information on made offers, orders, and purchases (e.g., purchases in the online store and physical stores)
- home store and stores visited
- use of services (e.g., newsletter subscription, browsing products in the online store)
- information about belonging to Pentik Klubi (loyalty program) (incl. member number) and start date of membership
- product returns
- benefits and campaigns targeted at the registered person and their use
- information related to invoicing, payments, debt collection, and contracts
- areas of interest and other information provided by the registered person themselves
- contact and communication related to customer relationship, loyalty program, and other relevant connections (such as complaints and other feedback, customer service call recordings and notes, and email and online discussions, e.g., in social media channels)
- direct marketing permissions and prohibitions
- information collected through cookies
Data generated by camera surveillance
- camera footage of the person
- date and time of events
4. Regular sources of information
Personal data is collected from the data subject themselves and in connection with registration for services, customer relationship, loyalty program, and the use of services.
Personal data may also be collected and updated from the registers of the controller and its group companies, the Population Information System, credit information registers, registers maintained by ASML Finnish Association of Marketing, Technology & Creativity (ASML) and Posti, and other similar public or private registers and data sources providing information services.
Camera surveillance is carried out in areas marked with "Recording camera surveillance". The areas include properties and business premises under the control of the controller.
5. Disclosure, transfer, recipients of data, and related processing practices
Personal data may be transferred or disclosed to third parties, such as authorities, within the limits permitted and mandated by applicable law.
The controller may also disclose and transfer data within the limits permitted and mandated by applicable law, including to companies belonging to its chain or group. Data may also be disclosed, for example, for the implementation of e-commerce, customer service, customer and loyalty program communications, invoicing, and marketing to the controller's contractual partners and to the contractual partners of the controller's IT systems. In such cases, data processing is handled through agreements between the parties.
If the controller is a party to a merger, business acquisition, or other corporate transaction, it may permanently disclose and transfer personal data to a third party involved in that corporate transaction. However, in such cases, the controller will ensure that all personal data remains confidential. No automated decision-making is made based on personal data.
Data will not be transferred outside the European Union or the European Economic Area unless it is necessary for the technical implementation of the service. In such cases, the controller ensures an adequate level of data protection and other necessary measures (such as contractual mechanisms) as required by law.
Camera surveillance data is disclosed when a competent authority specifically requests individualized data for a purpose stipulated by law, and in criminal and civil cases to the relevant authorities. Camera surveillance data is not disclosed to other parties or outside the EU.
6. Register protection
The databases where information is stored are protected by firewalls, passwords and other technical means. The databases and their backups are located in locked premises. Manually processed documents containing registered data are also stored in locked premises in such a way that unauthorised persons are prevented from accessing them. The controller ensures that only the company's employees and the employees of companies acting on its behalf, who need access to the data for the performance of their duties, have such access and that they comply with the confidentiality obligation.
If, despite the data security measures, a data breach occurs that is likely to have harmful effects on an individual's privacy, we will notify all affected parties of the breach as required by applicable legislation, and, if required by applicable data protection legislation, notify the authorities as soon as possible.
In the online store for consumers, if credit card, online banking or invoice is chosen as the payment method, the payment service is handled by Paytrail in cooperation with Collector Bank AB or Klarna Bank Ab. Payment by online bank or credit card does not require registration or additional payments. An invoice is an additional paid option and requires the provision of personal data to Collector Bank AB or Klarna Bank Ab. Pentik Oy is responsible for invoicing in the B2B online store.
All data transfers and monetary transactions are SSL-protected, meaning no outside party can view the information. The online store uses the Secure Sockets Layer (SSL) security protocol for transferring personal data. Software using the Secure Socket Layer (SSL) protocol protects your information, such as name, address, bank details and credit card number, when placing an order. SSL protection works with most modern browsers.
7. Principles concerning data rectification and erasure
The controller rectifies, erases or supplements personal data that is incorrect, unnecessary, incomplete or outdated for the purpose of processing, either on its own initiative or at the request of the data subject. The data subject should contact the controller to correct the data.
Customer data is stored for the duration of the customer relationship and after the termination of the customer relationship for as long as the parties can make claims against each other regarding the customer relationship. Legislation (such as legislation on accounting and the expiration of legal claims) may impose obligations on processing times. Data collected on a contractual basis can generally be stored for ten (10) years from the end of the contractual relationship and the fulfilment of the resulting obligations.
For the Pentik Club loyalty program, if a member has not actively used their Pentik Club membership for four (4) years, the membership will expire. The member will be informed of the expiration in advance, at which point it is possible to retain the membership by notifying Pentik if desired.
Camera surveillance data is destroyed by overwriting it with new data. The data is destroyed no later than one (1) year after the recording. However, the recording may be retained beyond this period if it is necessary to complete the processing of a matter as defined by law.
8. Data subject's rights
The data subject's rights are based on the EU General Data Protection Regulation, which in certain situations includes, among other things, the right of access and the right to have data rectified or erased. The data subject can exercise their rights in situations defined by law. Full exercise of these rights may be subject to restrictions.
Requests concerning the data subject's rights must be submitted in writing to the controller's contact person. Situations concerning the exercise of rights are assessed on a case-by-case basis and a separate decision is always issued. Requests for the exercise of data subject rights are generally responded to within one (1) month of receiving the request. The request is free of charge. If the request is manifestly unfounded or excessive, especially if it is repetitive, a reasonable fee may be charged to the data subject or the request may be refused. The data subject has the right to direct their request only to data concerning themselves.
Further information on rights:
Right to access one's own data
The data subject has the right to request access to their own data (right of access) to ascertain whether or not data concerning them is being processed. The data subject's right to obtain information may be restricted or refused under law if the provision of information would adversely affect the rights and freedoms of others. Such protected rights include, among others, the controller's trade secrets or another person's personal data.
Right to rectification and erasure of data
The data subject has the right to demand that the controller rectify inaccurate and incorrect personal data without undue delay. The controller must, at the data subject's request, erase personal data concerning the data subject unless it is not necessary to erase it if processing is necessary, for example, for compliance with a legal obligation to which the controller is subject or for the establishment, exercise or defence of legal claims.
Right to object to data processing or request restriction of processing
The data subject has the right to object to the processing of their personal data on grounds relating to their particular situation, when the data is processed based on legitimate interest. The data subject does not have the right to object to the processing of personal data when the processing is based on a contract between the controller and the data subject. If the data subject has objected to the processing of their data on grounds relating to their particular situation, the data subject must specify the particular situation on the basis of which they object to the processing based on legitimate interest. The controller may continue to process the data despite the objection if there is a compelling and legitimate reason for the processing that overrides the data subject's interests, rights and freedoms, or if it is necessary for the establishment, exercise or defence of legal claims. The data subject has the right, at any time, to object to the use of personal data concerning them for direct marketing. If the data subject objects to the use of personal data for direct marketing, the data must no longer be processed for that purpose.
The controller must, at the data subject's request, restrict the active processing of personal data, among other things, if the data subject disputes the accuracy of the personal data, in which case processing must be restricted for a period enabling the controller to verify the accuracy of the data. During the restriction of processing, data may only be stored as a general rule. Data may also be processed for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest. Before the restriction of processing is lifted, the data subject must be informed.
Right to data portability
Insofar as the data subject has themselves provided personal data which is processed by automated means and on the basis of a contract between the controller and the data subject, the data subject has the right to receive such data in a machine-readable format and to transmit the personal data directly from one controller to another, if technically feasible.
9. Contacts
The data subject can at any time check the information collected about them in connection with the customer or loyalty program and, if necessary, prohibit its use for marketing purposes also on the "My details" page of the online store.
Otherwise, the data subject's contact, such as an inspection request, must be sent in writing and signed using the contact details provided in this statement. The requester must provide the details necessary for finding the information and be prepared, if necessary, to prove their identity in accordance with the controller's instructions.
If the requester is not satisfied with the responses received, they can also contact the Office of the Data Protection Ombudsman:
Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, 00530 Helsinki
Postal address: P.O. Box 800, 00531 Helsinki
Telephone (switchboard): + 358 29 56 66700
Email: tietosuoja@om.fi
www.tietosuoja.fi
10. Amendments and supplementary documents to the statement
The controller has other data protection documents supplementing this privacy statement, such as a privacy statement regarding cookies.
The controller may amend and update this privacy statement as necessary. We ask you to regularly check the current privacy statements on the controller's website, pentik.com.
This statement entered into force on 1 June 2022.