Privacy Statement
EdenGym Oy’s Privacy Statement
This is EdenGym Oy’s Privacy Statement in accordance with the EU’s General Data Protection Regulation (GDPR).
- Registrar
EdenGym Oy
Paradise Street 2
Nokia 33720
edengym@edengym.fi
2. Person responsible for registration matters
Kim Keskimäki
040 580 2897
edengym@edengym.fi
3. Name of the register
EdenGym Oy: Customer register.
4. Registered
The company’s customers as well as potential customers can be entered in the register.
5. Purpose of personal data
Grounds for maintaining the register:
Retention of contact information, billing and payment information for EdenGym’s gym customers
Personal data is processed with the customer’s consent
6. Purpose of the processing of personal data and the register
Personal data will only be processed for pre-defined purposes, which are as follows:
Making monthly charges for gym customers and managing the customer relationship
Information mailings, newsletters and other marketing
Gym internal statistics and operational development
Personal data to be stored in the register
7. The customer register contains the following information:
Contact
Name
Identity number
Sexual
Address
E-mail
Telephone number
Customer Information
Services purchased and / or ordered by the customer
Purchases
training visits
7. Rights of the data subject
The data subject has the following rights, requests for the use of which must be made to the address edengym@edengym.fi
- The right of inspection
- The data subject can check the personal data we have stored.
- Right to rectification of data
- The data subject may request the correction of incorrect or incomplete information concerning him.
- Of opposition
- The data subject may object to the processing of personal data if he or she feels that the personal data has been processed unlawfully.
- Direct marketing ban
- The data subject has the right to prohibit the use of the data for direct marketing.
- Exhaust-right
- The data subject has the right to request the deletion of data if it is not necessary to process the data. We will process the deletion request, after which we will either delete the data or provide a valid reason why the data cannot be deleted.
- The controller may have a statutory or other right not to delete the requested information. The registrar is obliged to keep the accounting material in accordance with the period (10 years) specified in the Accounting Act (Chapter 2, Section 10). Therefore, accounting material cannot be deleted before the deadline.
- Withdrawal of consent
- If the processing of personal data concerning the data subject is based only on consent and not, for example, on the basis of customer relationship or membership, the data subject may revoke the consent.
- The data subject may appeal against the decision to the Data Protection Officer
- The data subject has the right to demand that we therefore limit the processing of the disputed data until the matter is resolved.
- Right of appeal
- The data subject has the right to lodge a complaint with the Data Protection Officer if he or she feels that we are in breach of the applicable data protection legislation when processing personal data. Contact information of the Data Protection Supervisor: www.tietosuoja.fi/fi/index/yhteoduction.html
8. Regular sources of information
Customer information is obtained regularly:
- from the customer himself when the customer relationship arises
- the access control system operated by the spa
9. Regular disclosures
We provide customer information to our billing partner, and with the customer’s consent, we may provide information to our partners for marketing purposes. Prior to the transfer, we ensure that our partner community is committed to complying with the requirements of the Privacy Policy. We have ensured that all of our service providers comply with applicable data protection laws.
10. Duration of processing
Record how long the information is retained, or general principles regarding the length of processing.
- As a general rule, personal data is processed for as long as the customer relationship is valid and the related obligations have been handled in one way or another.
- The registrant can unsubscribe from our marketing list via the link in each of our marketing emails.
Processors of personal data
11. The controller and its employees process personal and customer data.
Staff have a duty of confidentiality. The controller may also partially outsource the processing of personal data to a third party, in which case we will ensure through contractual arrangements that the personal data will be processed in accordance with applicable data protection legislation and otherwise in an appropriate manner.
12. Data transfer outside the EU
Personal data will not be transferred outside the EU or the European Economic Area.
13. Automatic decision making and profiling
We do not use the information for automatic decision making or profiling.
14. Cookies
We use cookies on our website to improve your user experience.
15. Accepting cookies
By using our website (www.edengym.fi), you agree that:
- we collect information about the use of the website, such as the number of pages visited on our site, the number of visits
- we store browser and device type information (dat