top of page

Register and privacy policy

This is Millainen Consulting Oy's (3424328-9) register and privacy statement in accordance with the EU General Data Protection Regulation (GDPR). Created on 13.7.2024. Last modified 13.7.2024.

 

1. Data controller

 

Millainen Consulting Ltd (3424328-9)
FI-01600 Vantaa
Suomi Finland
milla@millainen.fi

2. Contact person responsible for the register

 

Founder & CEO, Milla Ranta, milla@millainen.fi

3. Name of the register

 

Company's customer/marketing/stakeholder register

4. Legal basis and purpose of processing personal data

 

The legal basis for the processing of personal data under the EU General Data Protection Regulation is the consent of the individual (documented, voluntary, specific, informed and unambiguous) a contract to which the data subject is a party the legitimate interest of the controller (e.g. customer relationship before the contract, employment relationship, membership, etc.)

The purpose of processing personal data is to communicate with customers and stakeholders, maintain the organization's relationships, quality control and development of the organization's services, marketing, delivery of services, and communications.

5. Data content of the register

 

The information stored in the register includes: the person's name, position, organisation, contact information (phone number, e-mail address, address), website addresses, IP address of the network connection, IDs/profiles in social media services, information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services.

 

If there are several groups of data subjects (e.g. customer register and marketing register), list them and their data content in general.

 

As a rule, the data is stored for the duration of Millainen Consulting Oy's operations. Health data related to the delivery of services and necessary (e.g. food allergies at events or coaching that include catering) will be anonymised whenever possible and deleted after the service has been delivered.

 

The IP addresses of website visitors and cookies necessary for the functions of the service are processed based on legitimate interest, e.g. to ensure data security and to collect statistical information on website visitors in cases where they can be considered personal data. If necessary, consent will be requested separately for third-party cookies.

 

6. Regular sources of information

 

The information stored in the register is obtained from the customer and stakeholders e.g. messages sent via web forms, email, telephone, social media services, contracts, meetings and other situations in which the customer or stakeholder discloses their data.

 

Information on the contact persons of companies and other organisations may also be collected from public sources, such as websites, directory services and other companies.

 

7. Regular disclosure of data and transfer of data outside the EU or EEA

 

Data is not regularly disclosed to other parties. Information may be published to the extent agreed with the customer or stakeholder.

 

Data may also be transferred by the controller outside the EU or EEA. Data will not be transferred to the United States without the explicit consent of the data subjects.

 

Data may be disclosed to partners or subcontractors, for example, in cases where the delivery of a value or service required data processing (for example, the participant's access to the access-controlled facilities of the event or coaching being organised).

 

8. Principles of register protection

 

The register is handled with care and the data processed with the help of information systems is protected appropriately. When register data is stored on Internet servers, the physical and digital security of their hardware is taken care of appropriately. The controller ensures that the stored data, server access rights and other information critical to the security of personal data are processed confidentially and only by the employees whose job description it belongs to.

 

9. Right of inspection and right to request correction of data

 

Every person in the register has the right to check their data stored in the register and to demand the correction of any incorrect data or the completion of incomplete data. If a person wishes to check the data stored about him or her or demand correction of it, the request must be sent by e-mail in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU General Data Protection Regulation (usually within one month).

 

10. Other rights related to the processing of personal data

 

A person in the register has the right to request the removal of personal data concerning him or her from the register ("right to be forgotten"). Data subjects also have other rights under the EU's General Data Protection Regulation, such as restricting the processing of personal data in certain situations. Requests must be sent by e-mail in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU General Data Protection Regulation (usually within one month).
 

Contact us

Milla Ranta

+358 40 080 2727

milla@millainen.fi

  • Instagram
  • LinkedIn
Millainen Consulting Oy

Millainen offers lean, sustainable, people-first solutions in project management and value-driven expertise in AI integration and PMO, evolving with your business. Our end-to-end approach prioritizes customer value and well-being, making us a strategic partner for long-term success.

bottom of page