Based on the Regulation EU 2016/679 (hereinafter GDPR) we provide you information about personal data processing performed in relation to our business operations.
1.Contact data
Kingspan Finland is the personal data controller, address Kingspan Oy, Halmeenkatu 7, 38700 Kankaanpää; Finland
Contact to the person responsible for personal data protection is:
gdpr.fin@kingspan.com.
2.Table of personal data processing
Processing of personal data for recruitment process
Processing title |
Purpose of the processing |
Personal data category |
Legal title |
Deposition period |
Applying for a job |
In order to perform recruitment process |
Identification data ( e.g. first name, last name)
Contact data |
GDPR Art.6 point 1 a |
For 6 months after ending recruitment process |
Processing of personal data of potential customers
Processing title |
Purpose of the processing |
Personal data category |
Legal title |
Deposition period |
Acquisition of entities interested in business information by contacting them in person |
Communication with potential customers
Performing of offering process |
Identification data ( e.g. first name, last name)
Contact data ( e.g. detailed address, phone number, email address) |
Legitimate interest Art 6 GDPR point.1 f
Art 6 GDPR point.1 b |
Until objection is filed |
Registration of e-mail addresses for distribution of newsletters |
Maintaining contact with both the current and the potential customers |
Only e-mail address |
Legitimate interest Art 6 GDPR point.1 f |
Until objection is filed |
Processing of personal data of customers
Processing title |
Purpose of the processing |
Personal data category |
Legal title |
Deposition period |
Receipt of order |
Ensuring order delivery and enabling the use of warranty |
Contact and invoicing data |
Concluding or performing contract |
Contract performing/ After this period not longer than for 10 years, counting from last calendar day |
Ensuring delivery including hand-over to courier service |
Data for delivery and possible complaint |
Contact and invoicing data |
Concluding or performing contract |
Contract performing/ After this period not longer than for 10 years, counting from last calendar day |
Invoicing and invoice archiving |
Invoice archiving as per law |
Invoices |
Legal obligation |
As per law |
Marketing purposes
Including direct marketing
|
Conducting surveys in order to provide best service |
Email address |
Legitimate interest Art 6 GDPR point.1 f |
Until objection is filed |
Quotation process |
In order to perform offering process of our goods |
Identification data ( e.g. first name, last name)
Contact data |
Concluding or performing contract
Art 6 GDPR point.1 b |
As per law |
Processing of personal data of contractors
Processing title |
Purpose of the processing |
Personal data category |
Legal title |
Deposition period |
Registration of the issued orders and contracts |
Ensuring purchase |
Contact data |
Legitimate interest |
As per law |
Registration and archiving of received invoices |
Legal obligation |
Invoicing data |
Legal obligation |
As per law |
3. Explanations to the Table and Processing
Legal titles - are the legal justifications for processing and are defined in GDPR, Articles 6 and 9.
Saving time - means how long we are authorized or required to process and store your data.
We do not intend to hand over your personal data outside EU or to any international organization.
In cases where the processing is based on the legal title “Conclusion or Performance of Contract”, we need your personal data for concluding the contract and its subsequent performance, without which it is not possible to conclude the contract.
In cases where the processing is based on a legal title “Legal Obligation”, we need to process your personal data based on legal requirements within the time specified by the respective law, and we must not limit or delete the processing for that period.
We will only process your personal data for the purposes listed in the table.
We only collect personal data directly from the data subjects.
4. Description of Rights of the Data Subjects
As a data subject (natural person, about whom the personal data is processed), you hold the following rights to your personal data:
Right |
Specification in detail |
Require excerpt |
This is an excerpt of data we maintain about you, so-called right of access.
We will produce the excerpt in the format according to our capabilities. You do not have the right to request an excerpt in a format you specify.
Exceptions when we must not produce the excerpt include the cases concerning documents, disclosure of which would compromise the rights and freedoms of others. These are personal data of other persons, protection of trade secret, intellectual property, etc. |
Require correction
|
If you discover that we keep inaccurate, obsolete or incomplete information about you, ask for correction or amending it. |
Require deletion |
We must perform deletion in the cases, if we keep the personal data after the defined deposit period, or we do not have valid legal title.
We must not perform the deletion according to law in the cases where the processing is performed based on Performance of Contract or Legal Obligation. |
Require processing limitation |
This applies to processing based on legitimate interest.
Processing will be limited in the case of filing objection, and the limitation will exist for the period of the objection assessment. |
File objection against processing |
Objection may be raided in the cases when the processing is performed based on legitimate interest.
Objection against sending commercial messages will always be acknowledged.
In the case of providing your name or other contact information to the benefit of rendering the services, the possibility of misuse is almost excluded, and the provision is necessary for these activities. Therefore we consider this legitimate interest of ours as prevailing, and we do not acknowledge any objections. |
Recall consent with processing |
This is possible in the cases where processing is performed based on consent. If you granted your consent with processing and you remove it, the processing will be terminated. |
Require excerpt in a portable format
|
You may only require excerpt in a portable format in the cases of processing based on legal titles – contract performance and consent.
You may request excerpting only the data you have given us and which we keep in electronic form, and you are not entitled to choose a format. |
File objection against automated decision making |
We do not perform any processing based on automated decision making. |
File objection to the supervising authority |
If we fail to reply to your request within 1 month, you may file objection to the supervising authority. |
5. Method or Exercise of Rights
If you want to exercise any of the said rights, you may file an electronic application as follows:
- Send it by e-mail to the address gdpr.fi@kingspan.com with a valid electronic signature; the application cannot be acknowledged without such confirmation.
Please specify the following in the application:
- Identification data – name, surname, date of birth
- Exercise of what right you require – see the chapter Description of Rights of the Data Subjects
- Detailed specification of the application – for example in the case of correction, the correct data
- Telephone – for possible detailed specification and agreement on further steps
If there are any doubts concerning your identity, we are authorized to ask you for additional information to confirm your identity.
Acts related to exercise of rights of the data subjects are made free of charge, but we are entitled to charge a fee for more than one copy to cover the administrative costs.
However, if the applications are found as apparently unjustified or inadequate, particularly because they repeat, we may:
- Impose a reasonable fee taking into account the administrative costs
- Refuse to grant the application.