Privacy

Privacy Policy

This Privacy Policy applies to the collection, storage and processing of personal data on the Tyylidata website. This policy has been prepared in accordance with the European Union General Data Protection Regulation (GDPR).

Controller

Tyylidata, Tytti Lakka
VAT number: EL-173450850
Address: SAVVA DIAKOU 6 – RHODES, Greece
Email: info@tyylidata.fi
Phone: +30 694 8120234

If required by applicable legislation, Tyylidata will appoint a Data Protection Officer and publish their contact details on this page.

Purpose and legal basis for processing personal data

Personal data is processed for the following purposes:

  • managing and maintaining customer relationships
  • responding to enquiries submitted through the website
  • providing information about services
  • fulfilling contractual obligations

The legal bases for processing personal data are:

  • the legitimate interest of the controller in managing customer relationships and communications
  • the performance of a contract between the data subject and Tyylidata
  • consent given by the data subject, for example when submitting a contact form

Where processing is based on legitimate interest, Tyylidata considers the processing necessary for conducting business and communicating with customers and potential customers.

Categories of personal data processed

The register may include the following personal data:

  • first and last name
  • email address
  • phone number
  • company name
  • company website
  • information submitted through contact forms or communication channels
  • other information voluntarily provided by the individual
Sources of personal data

Personal data is primarily obtained directly from the data subject when they contact Tyylidata, for example:

  • through the contact form on the website
  • by email
  • through other communication channels

Personal data may also be obtained from publicly available sources, such as company websites, where this is necessary for business-related communication.

Recipients of personal data

Personal data is not regularly disclosed to third parties.

However, personal data may be processed by trusted service providers, such as:

  • website hosting providers
  • email service providers
  • IT system service providers

These service providers process personal data only to the extent necessary to provide their services, and they are bound by confidentiality and data protection obligations.

Transfers of personal data outside the EU/EEA

Personal data is primarily processed within the European Economic Area (EEA).

If personal data is transferred outside the EEA, appropriate safeguards required by the GDPR will be used, such as Standard Contractual Clauses approved by the European Commission or other legally accepted transfer mechanisms.

Retention period for personal data

Personal data is retained only for as long as necessary to fulfil the purposes described in this Privacy Policy.

Typical retention periods include:

  • customer communication data: for as long as required for managing the customer relationship
  • accounting material: in accordance with legal requirements, for at least 7 years
  • marketing-related data: until the data subject withdraws their consent or requests deletion of their data
Protection of personal data

Personal data is protected using appropriate technical and organisational security measures.

Manual material is stored in locked and protected premises. Electronic data is stored in secure systems that use access control, authentication mechanisms and monitoring of access rights.

Access to personal data is limited to persons whose work duties require it. All persons processing personal data are bound by confidentiality obligations.

Rights of the data subject

Under data protection legislation, the data subject has the following rights:

  • the right to access their personal data
  • the right to request correction of inaccurate data
  • the right to request deletion of personal data
  • the right to restrict the processing of personal data
  • the right to object to processing based on legitimate interest
  • the right to data portability, where applicable
  • the right to withdraw consent at any time, where processing is based on consent

Requests concerning these rights can be sent to: info@tyylidata.fi

The data subject also has the right to lodge a complaint with the competent data protection authority.

Obligation to provide personal data

Providing personal data through the website contact form is voluntary. However, certain information may be necessary for Tyylidata to respond to enquiries or provide services.

If the required information is not provided, it may not be possible to respond to the enquiry or establish a customer relationship.

Automated decision-making

Tyylidata does not use automated decision-making or profiling that would have legal or similarly significant effects on individuals.

Use of cookies

The website does not use analytics or marketing cookies.

The website is designed to function without analytics, marketing or tracking-related cookies, and no data is stored on the user’s device for these purposes.