Effective from 15/10/2021

With this Privacy Notice we provide you information on why and how we process your personal data in the course of our business operations.

We process your personal data for the following purposes in the course of our business operations:

  • Customer relationships
  • Strategic analysis of customer data to develop services and fulfil customer needs
  • Direct marketing
  • Business partner relationships
  • Recruiting
  • Communication
  • Social media
  • Cookies

The controller of your personal data is Dirä Oy (3194119-6), which is located at Karstulantie 8 A 8, 00550 Helsinki.

If you have any questions regarding the privacy notice, please contact Brian Simiyu (brian.simiyu@dira.fi).

1. What terms are used in this Privacy Notice?

Privacy notice means a document drawn up in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (hereinafter “GDPR”), through which the controller informs data subjects of the ways their personal data is processed.

Controller means the party responsible for processing the personal data of the data subject.

Processor means the party who processes personal data on behalf of the controller.

Data subject is a term for a human being in accordance with data protection laws.

Personal data means any information concerning the data subject or information by which the data subject can be identified.

Purpose for processing means the reason why the controller processes the data subject’s personal data.

Legal basis for processing means the legal ground on which the controller processes the data subject’s personal data. The lawfulness of processing is described in Article 6 of the GDPR.

2. When do we act as a processor?

We also act as a processor of personal data when we process the personal data of our merchant customers members on behalf of the merchants through our Dirä service. The merchants are the controllers of such personal data.

We apply the provisions of our Data Protection Agreement with regard to the processing of those personal data (see Section 9 of the Merchant Terms).

3. Why do we process your personal data?

We process your personal data in accordance with the processing purposes listed below. In the sections on processing purposes, you will find information on what personal data we process and on what legal basis we process your personal data.

Customer relationships

We process the personal data of our customers for the purposes of customer relationships. For these purposes we process the customers’ contact details as well as customer relationship data.

The legal basis for processing is the performance of our contractual obligations.

Strategic analysis of customer data to develop services and fulfil customer needs

We process the personal data of our customers to develop our services and better fulfil customer needs. For these purposes we process the customers’ contact details as well as data related to the use of Dirä service.

The legal basis for processing is our legitimate interests, according to which we develop our services and better fulfil customer needs.

NB! You may have a right to object data processing for these purposes (see section concerning your rights).

Direct marketing

We process the personal data of persons who wish to receive marketing for direct marketing purposes. In direct marketing, we process the contact details of the persons’ who wish to receive marketing.

Concerning company customers, the legal basis for processing is our legitimate interests, as we must sell our services in order to carry out our business.

Concerning consumer customers, the legal basis for processing is the consent given in accordance with the Act on Electronic Communications Services (917/2014), according to which we can target direct marketing to those who have given their consent.

NB! You have a right to object data processing for these purposes (see section concerning your rights).

Business partner relationships

We process the personal data of our business partners for the purposes of business partner relationships. For these purposes we process the business partners’ contact details.

The legal basis for processing is the performance of our contractual obligations.

Recruiting

We process the personal data of job applicants for recruiting purposes. For these purposes we process the job applicants’ contact details, CV information and other data disclosed to us.

The legal basis for processing is our legitimate interests, according to which we govern our recruiting practices.

NB! You have a right to object data processing for these purposes (see section concerning your rights).

Communication

We process the personal data of people who contact us for communication purposes. For these purposes we process contact details and other data disclosed to us.

The legal basis for processing is our legitimate interests, according to which we govern our communication.

NB! You may have a right to object data processing for these purposes (see section concerning your rights).

Social media

We process the personal data of our social media contacts for social media purposes. In the context of social media, we process contact details.

The legal basis for the processing is our legitimate interests, according to which we manage the contact requests made to us.

NB! You may have a right to object data processing for these purposes (see section concerning your rights).

Cookies

We process IP address data of the people who visit our website for purposes concerning the use of cookies.

The legal basis for processing is consent given in accordance with the Act on Electronic Communications Services of Finland (917/2014).

4. From where do we collect your personal data?

We collect your personal data from different sources, depending on our purposes for processing personal data.

Customer relationships, Business partner relationships, Direct marketing and Communication

We collect your personal data for these purposes from yourself, our business partners, authorities, and different public sources, such as the trade register.

Recruiting and strategic analysis of customer data to develop services and fulfil customer needs

We collect your personal data for these purposes only from yourself.

Cookies

We collect your personal data by using cookies.

5. Do we transfer your personal data?

We may transfer your personal data to third parties, e.g. data storage service providers, as a normal course of our business. When doing so, we ensure that the transfers are carried out in a secure way considering data security, and that adequate data protection agreements are concluded.

Your personal data may be transferred to our business partners, data storage service providers and communication service providers, as well as to accounting and auditing service providers.

We may transfer personal data to third countries. When doing so, we ensure an adequate level of data protection, e.g. by using standard contractual clauses issued by the European Commission, and other similar arrangements.

6. How long do we retain your personal data?

The retention period of your personal data depends on the purposes for which we process your personal data. We inspect the necessity of the retained personal data regularly and keep records of the inspections.

Customer relationships

We retain personal data for as long as our contractual relationship is in effect.

Strategic analysis of customer data to develop services and fulfil customer needs

We retain personal data for as long as it is necessary to fulfil the purpose of data processing.

Direct marketing

We retain personal data for as long as it is relevant or until you prohibit us (i.e. opt out) from processing your personal data for direct marketing purposes, or when we find out that you no longer wish to receive marketing.

Business partner relationships

We retain necessary personal data for as long as our contractual relationship is in effect.

Recruiting

We retain the necessary personal data for a maximum of twelve (12) months from the receival day of your job application.

Communication

We retain the necessary personal data for three (3) years after the contact.

Social media

We retain information on our social media channels until individuals remove their information from the channels.

Cookies

The retention period depends on each cookie used.

7. What data protection rights do you have?

You may be entitled to use the below listed data protection rights. The contacts concerning the rights shall be submitted to the controller’s contact person in writing. Your rights can be put into action only after you have been satisfactorily identified.

You may also have a right to lodge a complaint to the supervisory authority, if you think that the processing of your personal data infringes the data protection laws.

Right to inspect

The data subject has a right to inspect what data the controller has stored of him/her.

Right to rectify and erasure

The data subject has a right to request the controller to rectify or erase the personal data concerning the data subject on the grounds provided by law.

Right to restriction of processing

The data subject can request the controller to restrict the processing of personal data concerning the data subject on the grounds provided by law.

Right to data portability

The data subject shall have a right to receive the personal data concerning him/her, which he/she has provided to the controller, in a structured, commonly used and machine-readable format, if the processing is based on consent or a contract between the controller and the data subject, and the processing is performed automatically.

Right to object

If personal data is processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him/her for such marketing.

If personal data is processed on the basis of the legitimate interests of the controller, the data subject shall have the right to object the processing of personal data concerning him/her for such purposes in accordance with the law.

Right to object to automated individual decision-making, including profiling

The data subject shall have a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him/her or similarly significantly affects him/her.

Right to withdraw consent

If the legal basis for the processing of personal data is consent given by the data subject, he/she shall have the right to withdraw his/her consent.

8. Can this Privacy Notice be amended?

We may unilaterally amend this privacy notice. We update the privacy notice as necessary, for example, when there is a change in legislation. Amendments to this privacy notice will take effect immediately when we post an updated version on our website.

If we make significant changes to the privacy notice, or if there is a significant change in the way it is used, we will notify the data subjects.