Privacy Policy

Prepared 16.12.2024.

1. Data Controller

Laajavuori project / City of Jyväskylä

2. Contact Person Responsible for the Registry

Petter Kukkonen
petter.kukkonen@jyvaskyla.fi
040 866 8711

3. Name of the Registry

Laajavuori project customer registry

4. Legal Basis and Purpose of Personal Data Processing

The legal basis for processing personal data under the EU General Data Protection Regulation is the person's consent (documented, voluntary, specific, informed and unambiguous) or a contract in which the registered person is a party.

The purpose of processing personal data is customer communication and marketing. Data is not used for automated decision-making.

5. Data Content of the Registry

The registry may store name, position, company/organisation, contact details (phone number, email address, postal address), website addresses, network connection IP address, information about ordered services and their changes, billing information, and other information related to the customer relationship and ordered services.

IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of legitimate interest, among other things to ensure information security and to collect statistical data on website visitors in cases where they can be considered personal data. Consent for third-party cookies is requested separately where necessary.

6. Regular Sources of Data

Information stored in the registry is obtained from the customer through messages sent via web forms, email, telephone, social media services, contracts, customer meetings and other situations where the customer provides their information. Contact details of representatives of companies and other organisations may also be collected from public sources such as websites, directory services and other companies.

7. Regular Disclosure of Data and Transfer of Data Outside the EU or EEA

Data is not regularly disclosed to other parties. Data may be published to the extent agreed with the customer.

8. Principles of Registry Protection

The processing of the registry is carried out with care and data processed through information systems is protected appropriately. When registry data is stored on internet servers, the physical and digital security of the hardware is maintained accordingly. The data controller ensures that stored data, server access rights and other information critical to the security of personal data are handled confidentially and only by employees whose job description requires it.

9. Right of Access and Right to Demand Correction of Data

Every person in the registry has the right to check their stored information and to demand the correction of any incorrect data or the completion of incomplete data. If a person wishes to check the data stored about them or demand corrections, the request must be sent in writing to the data controller. The data controller may, if necessary, ask the requester to verify their identity. The data controller will respond to the customer within one month.

10. Other Rights Related to the Processing of Personal Data

A person in the registry has the right to request the deletion of personal data concerning them ("right to be forgotten"). Registered persons also have other rights under the EU General Data Protection Regulation, such as the restriction of personal data processing in certain situations. Requests must be sent in writing to the data controller. The data controller may, if necessary, ask the requester to verify their identity. The data controller will respond to the customer within one month.