Registry description

1. Registrar

iiVii Oy / Myarns.com

Address: Loiskekuja 6B 22 01600 Vantaa

Visiting address: Patotie 2, 01600 Vantaa

Phone: +358 10 200 5980

2. Registry contact

iiVii Oy / Myarns.com

Phone: +358 10 200 5980

3. Registry name

Myarns.com Marketing, Customer and Order Register. The registers consist of several sub-registers

4. Legal basis and purpose of the processing of personal data

The legal basis for the processing of personal data under the EU General Data Protection Regulation is the consent of the individual and the legitimate interest of the controller based on the customer relationship.

The purpose of the processing of personal data is

- Production, management, invoicing, sales and marketing of products or services in the online store services maintained by iiVii Oy

- Communicating with customers

- Customer Relationship Management and Customer Relationship

- direct marketing

- Targeting your offer

The information is not used for automated decision making or profiling.

5. Registry information content

The information to be stored in the registry is:

- The person's name

- Company / Organization

- contact information (phone number, email address, address),

- IP address of the network connection,

- IDs / profiles on social media services

- information about subscribed services and their changes

- Billing information

6. Regular data sources

The registry's contact and customer information is obtained from the customer's notifications to the registrar during and during the customer relationship. A customer relationship is created when

- The customer signs up for the online store

- Customer subscribes to newsletter

- Customer subscribes to a product newsletter

- The customer places an order

- The customer is participating in the survey

- Customer enters a raffle or contest

Customer name and address information can be updated from the Population Register. The ban on direct marketing and the ban on disclosing address information to other companies will be recorded based on the customer's notification. For electronic direct marketing (such as e-mail, text messages), the customer's consent is required separately in accordance with the Personal Data Act. In a credit transaction, the information on creditworthiness according to the Customer's time of order can be checked from Asiakastieto Oy's system.

7. Regular transfers of data and transfers of data outside the EU or the EEA

Information is not routinely disclosed to others. Information may be published to the extent agreed with the customer.

Data may also be transferred by the controller outside the EU or the EEA.

If you provide personal information to different parties, please indicate potential recipients or groups of recipients here.

8. Registry Security Principles

The register is handled with care and the information processed by the information systems is properly protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it includes.

9. Right of inspection and right to request correction of information

Every person in the register has the right to check the information stored in the register and to request that any incorrect information be corrected or that the incomplete information be supplemented. If a person wishes to check the data stored about him or her or request a correction, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).

10. Other rights related to the processing of personal data

A person in the register has the right to request the removal of his or her personal data from the register ("right to be forgotten"). Registrants also have other EU rights under the General Data Protection Regulation , such as restricting the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller shall respond to the customer within the time limits set out in the EU Data Protection Regulationsa (generally within one month).