Privacy policy

This is Best Berry Oy’s privacy policy in accordance with Finnish data protection legislation and the EU General Data Protection Regulation (GDPR). Prepared on 3 March 2021. Last updated on 3 March 2021.

1. Data controller

Best Berry Oy
Vehkalahdentie 36, 00950 Helsinki, Finland

2. Contact person for the register

Sari Merilainen
info@bestberry.fi
+358 40 7568081

3. Name of the register

Best Berry Oy customer register.

4. Legal basis and purpose of processing personal data

The legal basis for processing personal data under the GDPR may be the data subject’s consent, a contract to which the data subject is a party, compliance with a legal obligation, performance of a public task, or the controller’s legitimate interest, such as a customer relationship.

Personal data is processed for customer communication, maintaining customer relationships, service delivery, invoicing, marketing and other purposes related to Best Berry Oy’s business operations. The data is not used for automated decision-making or profiling.

5. Data stored in the register

The register may contain the following information: name, role, company or organisation, contact details, telephone number, email address, postal address, website addresses, IP address, social media profiles, information about ordered services and changes to them, billing information and other information related to the customer relationship and ordered services.

6. Regular sources of data

Data is obtained from customers through website forms, email, telephone, social media services, agreements, customer meetings and other situations where the customer provides information to Best Berry Oy.

7. Regular disclosures and transfers outside the EU or EEA

Data is not regularly disclosed to third parties. Data may be published or disclosed where agreed with the customer or where required by law. Data may also be transferred outside the EU or EEA if this is necessary for service provision and appropriate safeguards are in place.

8. Protection of the register

The register is handled with care. Data processed with information systems is protected appropriately. When register data is stored on internet servers, the physical and digital security of the hardware is maintained appropriately. Stored data, server access rights and other information critical to the security of personal data are handled confidentially and only by employees whose duties require such processing.

9. Right of access and rectification

Every person in the register has the right to access their personal data and request correction of inaccurate data or completion of incomplete data. Requests should be sent in writing to the data controller. The controller may request proof of identity where necessary and will respond within the time limits set by the GDPR, generally within one month.

10. Other rights related to personal data processing

Data subjects have the right to request erasure of personal data concerning them, restrict or object to processing, and request transfer of data from one system to another where applicable under the GDPR. Requests should be sent to the contact person listed above.