1. Data Controller
FlowHouse monitors the information you provide and is responsible for the personal data in accordance with the Data Protection Act.
Kauppakatu 29 B 4th floor, 40100 Jyväskylä
Business ID: 2169806-5
2. Person Responsible for Register Matters and/or Contact Person
Data Protection Officer
Kauppakatu 29 B 4th floor, 40100 Jyväskylä
3. Register Name:
FlowHouse Oy Marketing Register & Customer Register
4. Publicity of the Register
The public availability of FlowHouse’s customer register is restricted for privacy and protection of employees’ personal information, as defined in section 17(3) of the Act on the Protection of Privacy in Working Life. Other location or situational information in the customer register is also restricted to company information and authorized users determined by the data controller.
5. Legal Basis and Purpose of Personal Data Processing
Personal data is collected for specific, explicit, and legitimate purposes. The legal basis for the processing of personal data under the EU General Data Protection Regulation is:
– The data subject’s explicit consent (newsletter subscription)
– A contractual relationship between FlowHouse and the customer, where the data subject is a party
The primary use of the register is email marketing and marketing on social media channels. Email marketing is carried out using a separate email system, and in this case, the email register is located on an external server.
The data will not be used for automated decision-making or profiling.
6. What Information Do We Collect?
We collect the following personal information:
– Email address
– Phone number
– IP address
7. Regular Sources of Information
The data to be stored in the register is obtained from the customer and consists of digital services owned or utilized by FlowHouse.
Through the forms on FlowHouse’s website, which the user fills out
From the customer directly via email, phone, meetings, or other situations where the customer provides their information, based on the customer’s relationship with FlowHouse
Through separate campaign pages where the user fills out a form
8. Regular Disclosures of Data and Transfer of Data Outside the EU or EEA
Data is not regularly disclosed to other parties or transferred outside the EU or EEA unless it is necessary for the technical implementation of FlowHouse or its partner. In accordance with applicable legislation, information may be disclosed to authorities.
The data controller uses external service providers in its operations, and user-provided data is stored on service providers’ servers, including outside the EU, when using the MailChimp system (USA), whose servers are located in the United States. Users give explicit consent for the storage and processing of data outside the EU by providing their personal information through the form and participating in the test, ordering the guide available on the website, or subscribing to the newsletter. No sensitive information or separate password/login information is stored about users.
9. Principles of Register Protection
The register is processed with due
care, and the information systems are appropriately protected. The data controller ensures that stored data, server access rights, and other critical information for the security of personal data are treated confidentially and only by employees whose job description it falls under.
Access to the register requires a username and password, which are granted only to authorized persons. The register is protected by firewalls, passwords, and other technical measures. The data controller’s facilities are located in a locked and guarded facility. Access to the register is monitored and restricted to authorized personnel.
10. Retention Period of Personal Data
The data is kept for as long as it is necessary for the purpose of the processing. Personal data collected for the purpose of a newsletter subscription or marketing communication will be kept until the data subject cancels their subscription or requests their data to be deleted. Personal data collected in connection with a customer relationship will be retained for as long as the customer relationship is active and for a reasonable period thereafter to maintain the customer relationship.
11. Rights of the Data Subject
The data subject has the right to access their personal data and the right to request rectification or erasure of the data or restriction of processing concerning the data subject or to object to the processing, as well as the right to data portability. The data subject also has the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
The data subject has the right to lodge a complaint with the competent supervisory authority if the data subject considers that the processing of personal data infringes the applicable data protection laws.
We use cookie-based information for purposes such as remarketing and displaying content to website visitors. Additionally, we collect information for website analytics. With this information, we aim to improve our website, provide the best possible user experience to website visitors, and target communication based on their interests. The services we use include Google services (Google advertising, Google Analytics) and social media services (Facebook, Instagram, Twitter, LinkedIn).
Currently, our website uses necessary cookies, which are essential for the basic functionality of the site. Statistical cookies help us track website traffic, enabling us to improve the functionality and efficiency of the site, striving for the best possible customer experience. Statistical cookies are used by Google Analytics and Google Tag Manager. Marketing-related cookies aim to ensure that the advertising you may see is relevant to your interests. Marketing cookies enable targeted advertising on various websites. Marketing cookies are provided by Facebook, Instagram, Twitter, Google Ads, and LinkedIn, among others.