Privacy Policy

Date of preparation: 12.08.2026.

1. Data Controller

Suomen Teollisuus Service Oy

Business ID: 3291140-7

Hiipakantie 48 61810 Kauhajoki

2. Contact Person for the Register

Lasse Hautala

Tel. 040 145 2400

lasse.hautala@teollisuusservice.fi

3. Name of the Register

Suomen Teollisuus Service Oy's customer, stakeholder, and marketing register.

4. Purpose and Legal Basis for Processing Personal Data

The legal bases for processing personal data comply with the EU General Data Protection Regulation (GDPR):

  • Management, administration, and development of customer relationships
  • Preparation, execution, and monitoring of contracts
  • Fulfillment of statutory obligations
  • Communication with customers and stakeholders
  • Marketing communications

The basis for processing is a customer relationship, a contract, a legal obligation, or the consent of the data subject. Data is not used for automated decision-making or profiling.

5. Data Content of the Register

The data stored in the register includes: full name, job title, company/organization, contact details (phone number, email address, physical address), website URLs, IP addresses, handles/profiles on social media services, details of ordered services and changes to them, invoicing details, and other information related to the customer relationship and ordered services.

Website visitors' IP addresses and cookies essential to the site's functionality are processed on the basis of legitimate interest (e.g., to ensure data security and collect visitor statistics) where they can be considered personal data. Consent for third-party cookies is requested separately when necessary.

6. Regular Data Sources

Data stored in the register is obtained directly from the customer through website forms, email, telephone, social media services, contracts, customer meetings, and other situations where the customer provides their information.

Contact details for corporate and organizational representatives may also be gathered from public sources, such as websites, directory services, and other businesses.

7. Regular Disclosures and Data Transfers Outside the EU or EEA

Data is not regularly disclosed to third parties. Information may be published to the extent agreed upon with the customer. However, data may be disclosed to authorities where required by law.

As a rule, personal data is not transferred outside the European Union or the European Economic Area. However, data transfers may occur if:

  • The controller has operations outside the EU/EEA, or
  • We use service providers (e.g., cloud service providers) whose servers are located outside the EU/EEA.

In such cases, we ensure that the transfer complies with applicable data protection legislation requirements.

8. Data Retention Period

Personal data is retained only for as long as necessary to manage customer relationships, fulfill contracts, or meet statutory requirements.

9. Protection of the Register

Due care is exercised in processing the register, and data processed via information systems is appropriately protected. When register data is stored on internet servers, the physical and digital security of the hardware is duly maintained. The controller ensures that stored data, server access rights, and other information critical to personal data security are handled confidentially and only by employees whose job description requires it.

10. Right of Access and Right to Request Data Rectification

Every individual in the register has the right to inspect their stored personal data and request the correction of any inaccurate data or the completion of incomplete data. To inspect or rectify their data, the request must be submitted in writing to the controller. The controller may request proof of identity if necessary. The controller will respond within the timeframe specified in the GDPR (generally within one month).

11. Other Rights Related to Personal Data Processing

Data subjects have the right to request the erasure of their personal data from the register ("right to be forgotten"). Data subjects also hold other rights under the EU General Data Protection Regulation, such as restricting processing under certain circumstances. Requests must be sent in writing to the controller, who may request proof of identity if necessary. The controller will respond within the timeframe set by the GDPR (generally within one month).