Solmio-kassa

Privacy notice

Data controller

Solmio-kassa Oy Email: info@solmiokassa.fi

Contact person for the register: Matti Toorikka, info@solmiokassa.fi

Name of the register

  • Register for managing user accounts and customer relationships
  • Register for service usage and transactions

Purpose and legal basis for processing personal data

Solmio-kassa Oy acts as data controller in the following situations:

  • Identifying and managing application users (e.g. reporting, the till application)
  • Managing the customer relationship, technical support, providing the service
  • Invoicing and communication

Solmio-kassa Oy acts as a data processor in the following situations: processing the end-customer data of a customer (merchant) when Solmio-kassa's systems are used for things like QR code distribution or redemption, email receipts, and campaigns and identifiers. In these cases, Solmio-kassa's customer (the merchant) is the data controller.

Personal data processed

For user accounts: name, email address, access level, log data and activity history, organisation (if applicable).

For consumer data (in the merchant's register): redemption identifier (QR/link), time and place of redemption, product/campaign, email address (receipts), transaction log (terminal identifier, time, transaction).

Regular sources of data

User data is obtained directly from the user or the customer. Consumer data is obtained from the transaction itself or supplied by the merchant.

Retention period for personal data

  • User data is retained for the duration of the customer relationship and for up to 12 months after it ends.
  • Transaction data and logs are retained for up to 12 months from the transaction, unless otherwise agreed.
  • Retention of consumer data is determined by the merchant's instructions.

Recipients and transfers of personal data

Data is not disclosed to third parties without the data subject's consent or a legal basis. Data may be transferred to sub-processors (e.g. cloud services, email services) under GDPR-compliant agreements. Data is not transferred outside the EU/EEA without a lawful transfer mechanism (e.g. the EU's standard contractual clauses).

Register security principles

Systems are protected with firewalls, encryption and access controls. Physical and digital security measures are in place, and access is limited to staff whose duties require it.

Rights of the data subject

The data subject has the right to:

  • access their own data,
  • demand correction of inaccurate data,
  • request erasure of data ("the right to be forgotten"),
  • restrict processing in certain situations,
  • object to processing (to the extent it is based on legitimate interest),
  • transfer data to another controller (GDPR Article 20).

Requests should be sent by email to info@solmiokassa.fi. Where Solmio-kassa acts as a data processor, requests must be addressed directly to the data controller, i.e. the merchant.