Privacy Policy

For the purposes of its business operations, DialOk Communications Finland Oy must collect and process personal data relating to its customers, partners and subcontractors. All personal data is processed with due respect for the privacy of the individuals concerned.

1. Data Controller and Contact Details

DialOk Communications Finland Oy
Business ID: 1709892-1
Address: Keilaranta 1, FI-02150 Espoo, Finland

Data Protection Officer
Heidi Kilpelä
tietosuojavastaava@sfgyhtiot.fi

2. Lawful Processing of Personal Data

Appropriate information management practices ensure that our procedures for processing personal data and the measures implemented to protect such data comply with the requirements of the General Data Protection Regulation (GDPR).

DialOk Communications Finland Oy applies the following principles:

  • Personal data is processed for specified purposes and on a lawful basis. Processing is transparent to the data subject.
  • We only process personal data that is necessary and only for the purposes for which it was originally collected.
  • We do not make decisions based solely on automated decision-making, nor do we carry out profiling based on the personal data we process.
  • Personal data may only be accessed by employees who require it for the performance of their duties. Personal data is disclosed to third parties only where appropriate and necessary.
  • Personal data is stored securely and retained only for as long as necessary.
  • We take reasonable steps to ensure that personal data is accurate and kept up to date.

3. Purpose of Processing Personal Data

We process the personal data of our consumer and contract customers to enable customer service, contract and order management, service delivery, maintenance and invoicing, as well as the handling of other matters related to the customer relationship, such as service-related complaints and communications. In addition, personal data may be processed to safeguard the interests of our consumer customers.

The provision of our services may involve the recording of telephone calls for quality assurance, training, customer service, verification of business transactions and legal protection purposes. More detailed information on the processing of call recordings is available in the privacy notices for the relevant registers.

We also process the personal data of contact persons representing our customer companies and business partners for the purposes described above, as well as to enable the provision of our services and to fulfil statutory obligations related to our business operations.

More detailed information about the purpose of processing is provided in the privacy notice for each individual personal data register (below).

4. Personal Data Registers and Categories of Personal Data

We process and store personal data primarily in the following registers:

5. Legal Basis for Processing

We process personal data for the performance of a contract between the data controller and the data subject and for compliance with the legal obligations applicable to the data controller. Processing may also be based on the data subject’s consent or on the legitimate interests of the data controller.

More detailed information on the legal basis for processing is available in the privacy notice applicable to each individual personal data register (see above).

6. Collection of Personal Data

We primarily collect personal data directly from the individual through various communication channels, for example when a person visits our website or orders a product or service from us. Personal data may also be obtained from the company the individual represents or from other stakeholders through public communications, marketing activities or similar sources.

We may also use systems incorporating artificial intelligence (AI) in the processing of personal data, for example for data analysis, communication processing, supporting customer service processes and improving the quality of our services. AI is always used for a defined purpose, and all processing of personal data is carried out in accordance with applicable data protection legislation.

The information collected is used only for the purpose for which it was originally collected.

7. Retention of Personal Data

We retain personal data for the duration of the customer or business relationship and thereafter only for as long as necessary to fulfil the purposes described in this Privacy Notice and the relevant register-specific privacy notices, or to comply with applicable legal obligations.

Retention periods vary depending on the register. More detailed information on retention periods can be found in the privacy notice for the relevant register.

When the applicable retention period expires, personal data will be deleted or anonymised unless legislation, obligations relating to outstanding claims, regulatory requirements or pending legal proceedings require the data to be retained for a longer period.

8. Disclosure of Personal Data

PPersonal data is disclosed only to DialOk Communications Finland Oy’s group companies (SFG Yhtiöt Oy and Line Carrier Oy) and to service providers and business partners engaged to perform services on our behalf.

Personal data may be transferred or disclosed for the following purposes:

  • services provided by system suppliers and system maintenance
  • centralized customer service
  • IT support
  • external accounting services
  • implementation of marketing communications

In addition, personal data may be disclosed to public authorities where required by law or in response to a legally binding request from a competent authority. Personal data may also be transferred to the information systems used by our service providers.

DialOk Communications Finland Oy uses various service providers and subcontractors that process personal data on behalf of DialOk as data processors.

Such services may include, for example:

  • cloud and information system services
  • IT support and maintenance services
  • financial administration services
  • information security and monitoring services

Appropriate data processing agreements have been concluded with all data processors. Personal data is processed solely in accordance with the instructions provided by the data controller.

9. Transfers of Personal Data Outside the EU or EEA

As a general rule, personal data contained in our registers is not transferred outside the European Union (EU) or the European Economic Area (EEA), nor to international organisations.

However, when providing our services, DialOk Communications Finland Oy may use subcontractors, resources or applications located outside the EEA. In such cases, DialOk Communications Finland Oy ensures that the transfer is based on a lawful transfer mechanism and that personal data is protected through appropriate Data Processing Agreements with the data processor and any sub-processors, the European Commission’s Standard Contractual Clauses (SCCs), and appropriate technical and organisational safeguards.

Where required, a Transfer Impact Assessment (TIA) is also carried out. In all cases, transfers of personal data are carried out in accordance with the GDPR and other applicable legislation and only to the extent strictly necessary for the intended processing purpose.

10. Information Security and Personal Data Processing Practices

Personal data is stored in a secure IT environment and processed only by authorised employees through encrypted connections using secured workstations accessed via personal user credentials.

The organisation ensures that only employees whose duties require the processing of personal data have access to such data and that access rights are strictly limited according to job responsibilities and administrative requirements.

More detailed information regarding the technical and organisational security measures applied to each personal data register is available in the relevant privacy notice (see above).

11. Rights of the Data Subject

The data subject has the right to obtain information regarding the processing of their personal data (right of access) and the right to request the rectification or erasure of their personal data (the right to be forgotten) or the restriction of processing.

The data subject also has the right to object to the processing of their personal data and to decisions based solely on automated decision-making, including profiling.

However, the rights to erasure, restriction or objection do not apply where the processing of personal data is necessary to comply with legal obligations or is otherwise justified under applicable law.

The data subject also has the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data does not comply with applicable data protection legislation.

12. Further Information and Requests

If you have any questions regarding the processing of your personal data or wish to exercise your rights as a data subject, please contact the Data Protection Officer of DialOk Communications Finland Oy:

Data Protection Officer
tietosuojavastaava@sfgyhtiot.fi

If you believe that the processing of your personal data violates the General Data Protection Regulation (GDPR), you have the right to lodge a complaint with the supervisory authority:

Office of the Data Protection Ombudsman
Visiting address: Lintulahdenkuja 4, FI-00530 Helsinki, Finland
Postal address: P.O. Box 800, FI-00531 Helsinki, Finland
Telephone: +358 29 566 6700
Registry: +358 29 566 6768
Email: tietosuoja@om.fi
Website: www.tietosuoja.fi