Privacy Policy
This is Soulanniina's registration and privacy policy in accordance with the EU General Data Protection Regulation (GDPR). The policy was prepared on 20.5.2025. Last modified on 20.5.2025.
DATA CONTROLLER
SoulAnniina
Business ID: 3483842-6
CONTACT PERSON RESPONSIBLE FOR THE REGISTER
Anniina Koivula
+358 40 1313 101
REGISTER NAME
SoulAnniina's customer register
REGISTER
INTENDED USE
The purpose of processing personal data is to contact customers, maintain customer relationships, manage customer relationships and
processing of registration information.
INFORMATION CONTAINED IN THE REGISTER
Name, telephone number, email address, booking information and customer relationship management information provided by the customer,
billing information and other necessary information related to customer relationships.
REGISTER REGULATIONS
INFORMATION SOURCES
The register collects customer information about registrations, reservations, and contact information provided by the person themselves.
DATA DISCLOSURE
OR DATA TRANSFER
OUTSIDE THE EU OR EEA
The data is not routinely disclosed outside the company. The data is not transferred by the controller to the EU or European
outside the economic area.
PRINCIPLES OF REGISTER PROTECTION
The registry data is handled with care and is protected by usernames and passwords. Access to the data is only granted to
by the controller who needs the information for his/her tasks. Manual material: Paper materials are kept in a locked space accessible to the designated administrator and are destroyed
appropriately when the information is no longer needed.
REGISTER DATA RETENTION PERIOD
The data controller only retains data for as long as is necessary for the purpose of the register.
RIGHT OF INSPECTION
& CORRECTION OF DATA
Every person in the register has the right to check their data stored in the register and to demand correction of any incorrect data.
correcting information or completing incomplete information.
If a person wishes to check the information stored about them or request
to them, the request must be sent in writing to the controller. The controller may, if necessary, ask the requester
to prove their identity. The controller will respond to the customer within the time period specified in the EU Data Protection Regulation
(usually within a month).
OTHER RIGHTS
A person in the register has the right to request that personal data concerning him or her be removed from the register ("right to be
forgotten"). Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to access personal data
restriction of processing in certain situations. Requests must be sent in writing to the controller. The controller may request
if necessary, the requester to prove their identity. The controller is responsible for the customer in the EU Data Protection Regulation
within the stipulated time (usually within a month).