Privacy policy

This privacy policy has been drafted in accordance with the privacy statement of Steelhouse Group Estonia OÜ and the EU General Data Protection Regulation (GDPR).

1. Controller

Steelhouse Group Estonia OÜ

2. Contact details of the register

info@steelhousegroup.ee

3. Name of the register

Steelhouse Group Estonia OÜ register for the processing of personal data for the purposes of marketing and customer and stakeholder relations.

4. Legal basis and purpose for the processing of personal data

The purpose of the processing of personal data is the management of customer relations and customer interactions. Personal data is used for the company’s communication, marketing and sales activities. The legal basis for the processing of personal data is the legitimate interest of the controller to process personal data and to transmit it to the stakeholders’ contact persons for matters within their responsibility.

5. Content of the information stored in the register

The register processes the following data:

  • Contact details, such as name, email address and phone number;
  • Work-related information, such as job title and responsibilities;
  • Information about the employing company, such as the website address, billing information, and information regarding the services and/or products ordered;
  • Information about the marketing information used by the data subject, such as information about opening a message and clicking on the content.

6. Regular sources of information

The data entered into the register is obtained from the customer, eg from messages sent through online forms, email, telephone or social media services, from agreements, customer meetings and other situations where the customer discloses their data.

Personal data will be retained for as long as necessary for the purpose for which it was collected in accordance with this privacy policy. The retention of personal data takes into account personal data that has become inactive and is regularly deleted.

7. Routine data transfer and transfer outside the EU or EEA

Information is not regularly disclosed to other parties. Information may be disclosed to the extent agreed upon with the customer.

The controller may also transfer data outside the EU or EEA.

Transfer of data outside the EU or the EEA will comply with data protection legislation and, for example, the standard contractual clauses of the European Commission will be used with a controller when entering into agreements on data transfers.

8. Security principles of the register

The register is handled with care and the information processed in the information systems is adequately protected. When register information is stored on internet servers, the physical and digital security of their hardware is adequately addressed. The controller will ensure that the data stored, as well as access rights to servers and other information relevant to the security of personal data, are treated confidentially and only by staff members whose job descriptions so provide.

9. Right of access and the right to rectify information

Any person entered in the register has the right to inspect the data entered in the register and to request that incorrect data be rectified or incomplete data be completed. If an individual wishes to access or request the rectification of data stored about them, the request must be sent in writing to info@steelhousegroup.ee. If necessary, the controller may ask the applicant to prove their identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (usually within one month).

10. Other rights related to the processing of personal data

Any registered person has the right to request the deletion of their personal data from the register (right to be forgotten). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of processing of personal data in certain situations. Applications must be sent in writing to info@steelhousegroup.ee. If necessary, the controller may ask the applicant to prove their identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (usually within one month).