1. The Registrar
Tablebed Ltd (“Tablebed”) Business ID 2820085-6 Nunnankatu 4, 20700 Turku email@example.com
2. Contact Person Responsible For The Register
Dine Renfors, firstname.lastname@example.org, +358407005223
3. WHAT AND HOW DO WE USE THE INFORMATION?
Tablebed processes the personal data of e-commerce customers for order processing, customer relationship management, and direct marketing purposes. In addition, we process data from our website visitors for analytical purposes.
4. DATA COLLECTED
We collect the following information about registered or ordered placed by customers:
- first and last name;
- email address;
- postal address;
- telephone number;
- title or profession, interests, hobbies and other similar information
- other additional information provided by the customer;
- order and delivery history;
- the chosen payment method;
- possible customer communication or complaints;
- consents and prohibitions related to direct marketing; and
- for business customer representatives, the company name and business ID.
In addition, we may process certain technical information about all visitors to the online store. Such information includes:
- IP address;
- operating system and device type;
- the products you are looking for in the online store; and
- page history within the online store.
5. COOKIES AND ANALYTICAL TOOLS
6. WHERE DO WE GET PERSONAL INFORMATION?
The information stored in the register is obtained from the customer e.g. messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information. Technical analytics data is automatically saved during the visit.
7. TO WHOM DO WE TRANSFER PERSONAL INFORMATION?
In the technical, commercial or operational execution of personal data processing tasks, Tablebed uses subcontractors acting on behalf of Tablebed, for example in the transport and installation of furniture for customers or financial institutions to perform invoicing. Tablebed has a valid agreement with partners and subcontractors to process the data in accordance with the Data Protection Regulation. Partners do not transfer personal information to third parties.
As a general rule, we process personal data within the European Economic Area. However, in accordance with the relevant legislation, the data may be transferred outside the EU and the European Economic Area if the technical implementation of the Tablebed service so requires. Non-EU partners are required to comply with data protection practices regarding data transfers. We secure the transfer of personal data outside the European Economic Area in accordance with the European Commission’s model contract clauses or other appropriate safeguards, such as the Privacy Shield.
The data may be transferred to the competent authorities, for example to investigate irregularities.
8. STORAGE PERIOD
We retain our customers’ personal information only for as long as required by law or as necessary to accomplish the uses identified above.
9. PRINCIPLES OF REGISTER SECURITY
The register shall be handled with due care and the information processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. Tablebed ensures that the stored data as well as server access rights and other information critical to the security of personal data are treated confidentially and only by the employees whose job description it belongs to.
10. RIGHT OF INSPECTION AND RIGHT TO REQUEST CORRECTION OF INFORMATION
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check the data stored about him or her or request a correction, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).
11. OTHER RIGHTS RELATING TO THE PROCESSING OF PERSONAL DATA
A person in the register has the right to request the removal of his or her personal data from the register (“right to be forgotten”). Data subjects also have other rights under the EU’s general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).