To front page
Search

Privacy policy

Privacy Notice (updated 23 August 2024) Processing of personal data in Meira Nova Oy’s customer register, supplier register, service provider register, and data of potential customers. General Data Protection Regulation (EU) 2016/679, Articles 12, 13, 14 and 19

1. Controller

Meira Nova Oy, Palkkitie 10, 04300 Tuusula

2. Data Protection Officer contact details

tietosuojavastaava@sok.fi

3. Contact persons responsible for the registers

tietosuoja.meiranova@sok.fiBased on legitimate interest, we process personal data in our customer and supplier registers in order to implement, maintain and develop our customer, supplier and service provider relationships, as well as our other business relationships, and to fulfil our contractual obligations with the customer organisations, supplier or service provider organisations, other stakeholder organisations represented by the data subjects, and potential new customers and suppliers. In addition, we process personal data to comply with legal obligations, such as the requirements of accounting legislation. With the data subject’s consent, we may disclose information such as name, email and phone number to companies within S Group for contact purposes and marketing of services. We use the data collected about data subjects: a) to market products or services related to the data subject’s work duties, area of responsibility or authorised role; b) in customer service functions and order processing; c) to implement and develop Meira Nova’s operations and services; and d) to manage our customer, supplier and stakeholder relationships and for acquiring new customers. Data is not used for automated decision-making or profiling.

5. Content of the registers

Personal data stored and processed in the customer register include:
  • Name of the person and their position in the organisation
  • Company/organisation the person is associated with
  • Contact details (phone number, email address)
  • Information on meetings, such as meetings or matters agreed by phone related to customer relationship management
  • Written communication, such as email correspondence or customer service chat sessions
  • Telephone communication, such as calls with customer service and call recordings
  • Customer feedback or responses, for example to surveys
  • Participant information in customer events
  • Information on recipients of marketing and communication materials such as newsletters or customer magazines
  • User data from the online store (such as login details or orders placed)
  • User data from the customer portal, such as login information
Personal data stored and processed in the supplier register include:
  • Name of the person and their position in the organisation
  • Company/organisation the person is associated with
  • Contact details (phone number, email address)
  • Feedback or responses, for example to supplier surveys
  • User data from supplier portals, such as login information

6. Retention period of personal data

Data in the customer and supplier registers is retained for as long as necessary to: a) manage the relationship between Meira Nova and the company or organisation represented by the data subject; b) fulfil contractual obligations between Meira Nova and the organisation represented by the data subject; c) carry out new customer acquisition targeting the organisation represented by the data subject; or d) comply with legal obligations, such as accounting requirements.We regularly delete data from our registers when we become aware that the data subject no longer acts in a role related to cooperation with Meira Nova and its stakeholders and retention is no longer necessary for the purposes mentioned above. In addition, we review the registers and remove unnecessary data once a year.
  • Data related to sending Meira Nova’s newsletter or other materials (such as the Nova customer magazine) is deleted when the data subject indicates they no longer wish to receive such material.
  • Customer service call recordings are deleted 30 days after the call.
  • Customer service case data (such as emails, chat sessions and call data) is anonymised two years after the case is closed.
  • Contact request data of potential new customers is deleted no later than two years after the contact if no sales process or customer relationship is initiated.

7. Regular sources of data

As a rule, data stored in the registers is obtained from the customer, potential customer, or supplier/service provider themselves. Data may also be obtained from websites of potential customers or suppliers/service providers, companies specialising in compiling business information, other third parties, or other publicly available external sources.

8. Recipients of personal data

Data may be disclosed to authorities or courts where required by law. We may disclose contact persons’ personal data to our sister companies within S Group for marketing activities and customer communications. We use external service partners to provide system and support services. Personal data may be transferred to these partners to the extent necessary for carrying out the assigned tasks. We ensure that our partners provide an adequate level of data protection as required by law.

9. Transfer of data outside the EU or EEA

We use subcontractors in the processing of personal data, and data may be transferred to a limited extent outside the European Union (EU) or European Economic Area (EEA) for the provision, maintenance and support of services.Our maintenance or technical support partners are appropriately committed, for example, to EU standard contractual clauses or other applicable transfer mechanisms, as well as to the data protection and security requirements set by legislation and SOK.

10. Effects of processing and general description of technical and organisational security measures

We protect your personal data carefully throughout its lifecycle by using appropriate data protection and information security measures. Our system providers process personal data in secure server facilities. Access to personal data is restricted and personnel are bound by confidentiality.Within S Group, we protect your personal data, among other things, by proactive risk management and security planning, communication security measures, and by using secure facilities, access control and security systems. Access rights are managed and monitored. We regularly train staff involved in personal data processing and ensure that our partners' personnel also understand the confidential nature of personal data and the importance of secure handling. We carefully select subcontractors and continuously update our internal practices and guidelines.If, despite all protective measures, your personal data were to fall into the wrong hands, it is possible that it may be misused. If we detect such an incident, we will immediately investigate it and seek to prevent any damage. We will notify the relevant authorities and you in accordance with legal requirements.

11. Rights of the data subject

You have the following rights:
  • Right to access your data
  • Right to rectify your data
  • Right to erase your data (e.g. if the legal basis is consent or no legal basis for retention exists)
  • Right to restrict processing (e.g. contesting accuracy or unlawful processing)
  • Right to object to the processing of your personal data for direct marketing or other processing based on legitimate interest
  • Right to be informed of a personal data breach in accordance with the GDPR
If you wish to exercise your rights or obtain further information on the processing of your personal data, you can contact the controller by email at tietosuoja.meiranova@sok.fi You also have the right to lodge a complaint with a supervisory authority if you believe that we are violating applicable data protection regulations in the processing of your personal data. Read our cookie policy here