Section 10 of the Personal Data Act (523/99)

EU General Data Protection Regulation 2016/679

1. The controller

Toyrock Oy
Business ID 2636324-8

High Tech Center
Lemminkäisenkatu 46
20520 Turku

2. Registrar or contact person:
Rebecca Crusoe
tel. +46 702 79 54 55

3. Name of the register
Toyrock Marketing Register

4. Purpose of the processing of personal data
Delivery of newsletters to licensors
Announcement of competition wins

5. A description of the group of data subjects and the information content of the register
The register contains:
Name
Address
Telephone number
Email address
Time to register
Consent to direct marketing
competition Answers
Transaction history on Toyrock.fi
Newsletter reading and click history
Other information provided by the customer

6. Regular data transfers and transfers outside the EU
Data may be transferred outside the EU or the EEA to the extent permitted by the Personal Data Act.

7. Registry security principles
Personal information will be kept confidential and will only be accessible to relevant individuals. The registry on the computer network and hardware is protected by a firewall and other necessary measures.

8. Where the information is regularly disclosed
To the authorities in statutory cases.

9. Where information is obtained on a regular basis
From the registrant himself.

10. Rights of the data subject
The registrant has the right to cancel his newsletter subscription at any time.

The data subject has the right to check what information about him or her has been stored in the register, the right to demand the correction of incorrect personal data and the right to have his or her data removed from the register.

The data subject shall have the right to obtain personal data concerning him which he has provided to the controller in a structured, commonly used and machine-readable form, provided that the processing is based on consent or agreement and is carried out automatically.

The data subject has the right to restrict the processing of data in accordance with Article 18 of the EU Data Protection Regulation.

A request for inspection, correction or removal must be sent in writing and signed to the person responsible for registration matters.