Privacy Policy
Privacy Policy
1. Controller
SunTiimi Oy, whose registered auxiliary business name is PinkkiBasket
Business ID: 3227060-3
2. Contact person for the register
Mikko Mäntylä
+358 (0)50 312 6644
info (at) pinkkibasket.fi
3. Name of the register
SunTiimi Oy / PinkkiBasket customer register
4. Legal basis and purpose of the processing of personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is:
the data subject’s consent (voluntary enrolment in a course, team or mailing list, sending an inquiry, or acceptance of cookies when visiting the website); and
a contract to which the data subject is or has been a party.
Personal data are processed for the performance of the contract between the Controller and the data subject and, where applicable, on the basis of the data subject’s consent, in connection with and in order to enable orders, enrolments, inquiries, customer service, marketing, reporting and other measures relating to the management of the customer relationship.
The data contained in the register may also be used for profiling and for targeting marketing measures and customer communications so that they are of interest to the data subject. Personal data may be processed in connection with the distribution of newsletters and participation in events and other marketing measures.
5. Data content of the register
The register may contain the following categories of information about individuals:
Name
Email address
Phone number
Address
Services purchased or free trials or team events attended.
When enrolling in a free basketball course, only the first and last name and the email address are collected. Address, phone number and other information are not collected in that case.
6. Regular sources of information
Personal data are collected through forms on the website, cookies, email, telephone, at the point of registration, or otherwise directly from the data subject, as well as from customer meetings and other situations in which the customer provides their information.
The myClub membership service system is used to manage course enrolments as well as member and participant data. The information provided on the website’s enrolment form (name and email address) is stored in the myClub system for the administration of courses and memberships. The provider of the myClub service acts in this respect as a processor of personal data on behalf of the Controller, and a data processing agreement has been concluded in respect of the processing.
Google Analytics, the MailChimp newsletter software, the cookies used on the website and the Facebook pixel are used as additional means of collecting information alongside those referred to above.
7. Regular disclosures of data and transfers of data outside the EU or the EEA
External service providers (including the myClub membership service system and the MailChimp newsletter service) are used in the processing of personal data. These service providers act as processors of personal data on behalf of the Controller in accordance with data processing agreements. The data are stored within the EU/EEA area.
Personal data may, however, also be transferred outside the EU/EEA where this is necessary for the provision of the service or for the use of external service providers. Any such transfers are made in compliance with the transfer mechanisms provided for in the GDPR, in particular on the basis of a European Commission adequacy decision (Article 45 GDPR), appropriate safeguards such as the Commission’s Standard Contractual Clauses or binding corporate rules (Article 46 GDPR), or, where applicable, one of the derogations for specific situations set out in Article 49 GDPR.
8. Principles of protecting the register
Due care is exercised in the processing of the register and data processed by information systems are protected appropriately. When register data are stored on Internet servers, the physical and digital security of the hardware is duly ensured. The Controller ensures that stored data as well as server access rights and other information critical to the security of personal data are treated confidentially and only by those employees whose job description includes such tasks.
9. Data subject’s right of access
The data subject has the right to obtain confirmation from the Controller as to whether or not personal data concerning him or her are being processed. Where such data are being processed, the data subject has the right to see the information concerning him or her. If a person wishes to review the information stored about him or her, or to request its rectification, the request must be submitted in writing to the Controller. The Controller may, where necessary, ask the person making the request to prove his or her identity.
10. Rectification and erasure of data
A person in the register has the right to request the rectification or erasure of personal data concerning him or her from the register (the ”right to be forgotten”). Requests must be submitted in writing to the Controller. The Controller may, where necessary, ask the person making the request to prove his or her identity.
11. Obligation to notify personal data breaches
The Controller must notify the supervisory authority of a personal data breach within 72 hours. Where the breach is likely to result in adverse effects for the data subject, the Controller must also notify the data subject.
12. Changes to privacy practices
The Controller develops its operations continuously and, as a result, may need to amend and update its privacy practices from time to time. Amendments may also be based on changes in data protection legislation.
Where the amendments include new purposes for the processing of personal data, or otherwise materially change the practices, the Controller will notify the data subjects in advance and, where necessary, will request their consent.