Register of Visitors

Prepared 7.2.2025, last reviewed on 7.2.2025

Registrar

Oy NIT Naval Interior Team Ltd. (FI19054949)
Hadvalantie 10, 21500 Piikkiö, Finland

Contact person for matters concerning the register

Sebastian Lagerlöf
sebastian.lagerlof@nit.fi

Legal basis for processing

Legitimate interest

Purpose of processing personal data

The purpose of the register is to ensure the security of the company’s websites. The information obtained (IP address) is only used in the event of a fault or in connection with the investigation of data breaches.

The basis for processing is legitimate interest and, in the case of cookies and similar tracking technologies, consent.

Basis of legitimate interest

The controller must process personal data in order to perform business-related tasks. The processing of personal data in this context cannot necessarily be justified by a legal obligation or a contract with an individual.

The controller has determined in the balancing test that legitimate interest is the most appropriate basis for processing in view of the nature, scope of the processing and the exercise of the rights and freedoms of the data subjects.

The controller has assessed that the activities in accordance with the legitimate interest will not cause serious harm to the rights and freedoms of the individuals (data subjects) concerned.

Personal data categories concerned

IP address, visit time and pages as well as location, browser, device and operating system information.

Recipients and recipient groups

Limited, authorized personnel of the company providing the website hosting server.

Consent

Consent is given via a banner on the website and can be revoked via the “cookie settings” section.

Data content of the register

The personal register contains the following information:

  • IP address
  • Web browsing time
  • Pages the visitor has visited
  • Location information, such as country
  • Browser, operating system and device information

Regular data sources

Information is obtained from the user’s visits to the organization’s website.

Personal data retention period

Data is never deleted separately.

Regular data transfers

The information in the register is for the company’s use only, except when using an external service provider, which is for their use.

The information is not disclosed outside the company or to its partners, except in connection with data breaches and the like.

Transfer of data outside the EU or EEA

The data in the register is not routinely transferred outside the EU or EEA. However, it is possible that service providers outside the EU/EEA are used for processing or that the service providers’ clouds are located outside the EU/EEA, in which case the SCC standard clauses are used as the basis for data transfer and additional safeguards have been implemented in data transfers, such as internal instructions (on pseudonymisation of personal data and the like) and possibly a TIA analysis if the situation requires it.

When the organisation processing personal data has committed to the EU-US Data Protection Framework (DPF), it is used as the basis for the transfer during its validity.

Principles of register protection B: Electronic material

Only designated employees of the organization and companies acting on its behalf have the right to use the website hosting server.

Each designated user has their own personal username and password. Each user has signed a confidentiality agreement. The system is protected by a firewall that protects external connections to the system.

The protection and processing of the data in the register complies with the provisions and principles of the Data Protection Act, official regulations and good data processing practice.

Cookies

We use cookies on our website. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not harm users’ computers or files. The primary purpose of using cookies is to improve and customize the visitor’s user experience on the website and to analyze and improve the functionality and content of the website.

The information collected using cookies can also be used to target communications and marketing and optimize marketing activities. The visitor cannot be identified using cookies alone. However, the information obtained using cookies can be linked to information obtained from the user in other contexts, for example when the user fills out a form on our website.

Cookies collect the following information:

  • the visitor’s IP address
  • the time of the visit
  • the pages browsed and the times they were viewed
  • the visitor’s browser

Your rights

A user visiting our website has the option to prevent the use of cookies at any time by changing their settings from the cookie banner. Some browsers also allow you to disable cookies and delete cookies that have already been saved.

Disabling cookies may affect the functionality of the site.

Right of inspection, i.e. the right to access personal data.

The data subject has the right to check what information about him or her is in the register. The request for inspection must be made in writing by contacting the company from a verifiably identifiable email address.

The data subject has the right to prohibit the processing and disclosure of his or her data for direct advertising, distance selling and direct marketing, as well as for market and opinion research by contacting the company.

The data controller has the right to invoice upon request if obtaining the information incurs costs.

The right to transfer data from one system to another

When using legitimate interest as the basis for processing, the data subject does not have the right to transfer their data from one system to another.

When using consent as the legal basis, the data subject has the right to transfer their data from one system to another.

The transfer request can be addressed to the contact person of the register.

The right to request correction of information

Personal data in the register that is incorrect, unnecessary, incomplete or outdated in terms of the purpose of the processing must be corrected, deleted or supplemented.

A request for correction must be made by means of a personally signed written request to the company from a verifiably identifiable email address.

The request must specify which information is required to be corrected and on what basis. The correction shall be carried out without delay.

The person from whom the incorrect information was received or to whom the information was disclosed shall be notified of the correction of the error. If a request for correction is denied, the person responsible for the register shall issue a written certificate stating the reasons for the denial of the request for correction. The interested party may refer the denial to the Data Protection Officer.

Right to restriction

The data subject has the right to request restriction of data processing, e.g. if the personal data in the register is incorrect. Contact the person responsible for the register.

Right to object

The data subject has the right to request personal data concerning him or her and the data subject has the right to request the correction or deletion of personal data. Requests can be addressed to the contact person of the register.

If you act as a contact person for a company or organization, your data cannot be deleted during this period.

Right to lodge a complaint with a supervisory authority

If you believe that the processing of your personal data has infringed the General Data Protection Regulation, you have the right to lodge a complaint with a supervisory authority.

You can also lodge a complaint in the Member State where you have your permanent residence or place of work.

The contact details of the national supervisory authority are:
Finnish Data Protection Officer Office
PO Box 800, 00531 Helsinki
Tel. 029 56 66700
tietosuoja@om.fi
www.tietosuoja.fi

Other rights related to the processing of personal data

The data subject has the right to prohibit the disclosure and processing of their data for direct advertising and other marketing purposes, to demand anonymization of the data where applicable, and to have the right to be completely forgotten.