The data controller is obligated under the GDPR to provide clear information to data subjects. This statement fulfills the information requirement.
1. Data Controller
Masspap Oy
Contact Details:
Pirkkolankatu 6
45130 Kouvola
+358 207 850 540
toimisto@masspap.fi
For data registry inquiries:
Data Protection Officer:
Sami Soratie, CEO
Phone: 050 366 9355
Email: sami.soratie@masspap.fi
2. Data Subjects
We collect and process personal data from the following categories of data subjects:
- Customers: Individuals who purchase our products or services.
- Customer Company Contacts: Representatives of our client companies.
- Potential Customers: Individuals who have expressed interest in our products/services or whom we have identified as potential clients via directories or websites.
- Business Partners and Collaborators: Individuals involved in partnerships or collaborations.
- Suppliers and Subcontractors: Individuals providing products or services to us.
- Website Users: Visitors to our website whose data is collected via cookies.
- Marketing List Subscribers: Individuals who subscribe to newsletters or other marketing materials.
3. Purpose and Legal Basis for Data Processing
The legal bases for processing personal data include:
- Customer Relationship: Managing customer relationships and delivering products or services.
- Contract Fulfillment: Ensuring obligations are met under agreements.
- Consent: For example, processing data gathered at events or with marketing permissions.
- Legal Obligations: Compliance with requirements like bookkeeping laws.
- Legitimate Interest: Business development, targeted marketing, and customer service improvements.
Specific Purposes:
- Managing sales and customer relationships
- Marketing
- Fulfilling legal obligations
4. Stored Personal Data
The customer registry includes the following information:
- Contact Details: Name, email, phone number, company name, address, and business ID.
- Customer Data: Purchase details, billing address, and payment information.
- Feedback and Communications: Customer feedback and service inquiries.
- Contract Information: Details of agreements made with customers.
5. Data Subject Rights
Data subjects can exercise their rights by contacting Pirkkolankatu 6, 45130 Kouvola or toimisto@masspap.fi.
- Access: Request access to stored personal data.
- Correction: Request corrections to inaccurate or incomplete data.
- Objection: Object to data processing if deemed unlawful.
- Direct Marketing Opt-Out: Opt-out of direct marketing.
- Deletion: Request deletion of unnecessary data, unless legally required for retention (e.g., bookkeeping).
- Consent Withdrawal: Withdraw consent for data processing when applicable.
- File a Complaint: Submit complaints to the Data Protection Ombudsman (www.tietosuoja.fi).
6. Regular Data Sources
Data is collected from:
- Directly from customers via agreements, online forms, or customer service interactions.
- Public records (e.g., trade registers).
- Company directories and websites.
- Events and trade shows where consent is given.
7. Data Sharing
Data is generally not shared for marketing purposes outside Masspap Oy. Data sharing occurs in the following cases:
- Service Providers: Data may be shared with partners such as:
- Google Analytics 4 (GA4): Website analysis.
- Dealfront Leadfeeder: Identifying companies visiting our website.
- Brevo: Managing newsletters.
- Lime CRM: Customer relationship management.
- Legal Obligations: Data may be shared with authorities when required by law.
8. Data Retention
- Customer Relationship: Data is retained for the duration of the customer relationship.
- Legal Obligations: Data may be retained longer if legally required (e.g., bookkeeping laws require retention for 10 years).
- Marketing Lists: Data is retained until unsubscribed via provided links.
- Deletion Requests: Data will be deleted upon request unless legally required otherwise.
9. Data Processors
Personal data is processed by:
- Masspap Oy Employees: Authorized employees who require the data for work purposes.
- Outsourced Providers: Third-party services (e.g., accounting or IT support) with strict contractual guarantees to ensure GDPR compliance.
10. Transfers Outside the EU
Personal data is not typically transferred outside the EU or EEA. If data transfer is necessary, measures such as EU standard contractual clauses and additional safeguards are used.
11. Automated Decision-Making and Profiling
We do not use personal data for automated decision-making or profiling.
Cookie Policy
Cookies are used for personalized content, visitor analytics, social media features, and targeted marketing.
You can modify cookie settings via the privacy link at the bottom of our website or through the button at the bottom-right corner of the page (desktop only).
Cookies in Use:
- Complianz: Cookie consent management.
- Google: For analytics and marketing.