Registry and Privacy Statement

Registry and Privacy Statement

This is the Register and Privacy Statement of RTJ Group Ltd. under the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (1050/2018). Created on May 7, 2018.
Last change on September 8, 2026. We may from time to time change this Privacy Statement by publishing a new version online. Therefore, it is recommended that you review this Register and Privacy Statement regularly. We will notify data subjects separately of any material changes.

1. Registrar

RTJ Group Oy
Vihiluodontie 261 A1
90440 Kempele
Business ID: 2354125-6
E-mail address: info@rtj-group.com
Exchange: +358 (0)75 3285 390

2. Register’s name

The register containing the personal data is called “RTJ Group Oy’s customer records”.

3. Legal Grounds and Purpose of Processing Personal Data

The purpose of processing personal data is to manage and maintain customer relations between RTJ Group and its customers. Personal data is used to identify users of services and e-commerce as well as to deploy, implement, administer and bill services, and provide information and alerts to customers. In addition, personal data may be used for direct marketing, as well as for the investigation and monitoring of misuse. Personal data may also be used to design and develop RTJ Group’s business and services and to monitor the number of customers using the service. In addition, RTJ Group Oy may use and disclose personal data contained in the register for legitimate purposes e.g. direct marketing, direct sales, direct mail, surveys and marketing research in accordance with the Finnish Data Protection Act, the Act on Electronic Communications Services (917/2014) and other applicable laws.

4. Data content of the register

The information to be stored in the registry is: person’s name, status, company / organization, contact details (phone number, e-mail address, address), web site addresses, IP address of the network, IDs / profiles in social media services, changes, billing information, and other information related to customer relationships and ordered products and services.

5. Regular Data Sources

The information to be stored in the registry is obtained from the customer when registering the service or acting in online store or updating own data. In addition, personal data can be obtained from messages sent via web forms, browser cookies, email, telephone, social media services, contracts, customer meetings and other situations where the customer delivers their information.

6. Ordinary deliveries of data and transfer of data outside the EU or the EEA

Personal data contained in the Registry is not regularly disclosed to third parties. However, personal data may be released from time to time in accordance with Finnish law. In addition, personal data may be disclosed for research and marketing purposes including direct marketing.

RTJ Group Oy may use subcontractors to provide and implement online stores and services. In this respect, personal data may be transferred to subcontractors to the extent necessary for the provision of services, for example saving e-mails to a server maintained by a third party on the basis of the assignment of RTJ Group Oy. In such cases, information may be released outside the EU or the European Economic Area.

7. Business transfers and corporate transactions

If RTJ Group Oy sells or transfers its business or a part of it, or is involved in a merger, demerger or other corporate transaction, personal data relating to the transferred business may be transferred to the receiving party as part of that transaction.

Personal data is not sold or disclosed as a separate asset without such a transfer of business.

The recipient may process the transferred personal data only for the purposes for which the data was originally collected. We will inform data subjects of any such transfer and of who acts as the controller after the transfer. A transfer does not limit the rights of data subjects described in this statement.

8. Retention of personal data

Personal data is retained for as long as is necessary for the purposes for which it was collected, as a rule for the duration of the customer relationship and for a reasonable period thereafter.

After that, the data is deleted or anonymised unless law requires it to be retained longer. Invoicing and accounting material is retained for the period required by the Finnish Accounting Act, which is six years from the end of the calendar year in which the accounting period ended.

Data used for direct marketing is retained until the data subject objects to direct marketing.

9. Registry Data Protection

Registry and the data processed by information systems are properly protected. When the customer information is stored on the Internet servers, the physical and digital security of their data is handled appropriately. The customer information register administrator ensures that stored data, server access rights, and other critical data related to the security of personal data are processed confidentially and only by the employees whose job description it belongs.

10. Right of inspection and the right to demand correction of information

Any person in a customer information register has the right to check his / her data stored and to demand that any incorrect information be corrected or incomplete information may be supplemented. If a person wishes to check or require correction of the information stored on him, the request must be sent in writing to the customer information register. The administrator may ask the applicant to prove his / her identity if necessary. The administrator of the customer information register is responsible handle request within the time limit set in the EU Privacy Policy, usually within one month.

11. Other Rights in the Processing of Personal Data

A registered person has the right to request the removal of personal data relating to him / her (“right to be forgotten”). Also, those who are registered have other rights under the EU’s general data protection regulation such as limiting the processing of personal data. Requests must be sent in writing to the administrator of the customer information register. The administrator may ask the applicant to prove his / her identity if necessary. The administrator responds within the time limit set in the EU General Data Protection Regulation, usually within one month.

A data subject also has the right to lodge a complaint with a supervisory authority if he / she considers that the processing of personal data infringes the General Data Protection Regulation. In Finland the supervisory authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).