Privacy Notice

Privacy Notice relating to customer data, customer communications and marketing

This Privacy Notice applies to the processing of personal data relating to the contact persons, representatives and other personnel of IQI Success Insuring Oy’s corporate and organisational clients and prospective clients, as well as private traders (collectively, ‘data subjects’), for the purposes of sales, marketing, communications, the provision of services and the conduct of business operations.

Personal data means any information relating directly or indirectly to an identified or identifiable individual, such as an employee of a corporate client.

1. Data controller

IQI Success Insuring Oy
Business ID: 1923859-6
Address: Satamaradankatu 1, 00510 Helsinki, Finland
Email: privacy@iqi.fi

2. Purposes and legal bases for processing personal data

We process personal data for the following purposes and on the following legal bases under Article 6 of the General Data Protection Regulation (EU) 2016/679 (‘GDPR’):

Customer communications, customer and contractual relationship management and customer service; producing, maintaining and delivering services

Legal bases:

    • The legitimate interests of the controller (Article 6(1)(f) GDPR)
    • Performance of a contract (Article 6(1)(b) GDPR), where the data subject is personally a party to the contract, for example as a private trader

Invoicing, payment monitoring, debt collection, financial administration and accounting

Legal bases:

    • The legitimate interests of the controller (Article 6(1)(f) GDPR)
    • Performance of a contract (Article 6(1)(b) GDPR), where the data subject is personally a party to the contract
    • Compliance with a legal obligation (Article 6(1)(c) GDPR) in relation to accounting and other statutory obligations, such as taxation

Marketing, organising and administering client and marketing events, other events, webinars and promotional prize draws; sales, direct marketing and sales promotion; and planning, measuring and developing marketing and sales

Legal basis:

    • The legitimate interests of the controller (Article 6(1)(f) GDPR)

Developing services, customer experience and business operations; collecting client feedback; conducting market and customer research; and anonymising personal data for statistical purposes

Legal bases:

    • The legitimate interests of the controller (Article 6(1)(f) GDPR)
    • Consent (Article 6(1)(a) GDPR) for the publication of reviews and customer references

Establishing, exercising or defending legal claims

Legal basis:

    • The legitimate interests of the controller (Article 6(1)(f) GDPR)

Fulfilling data subjects’ rights

Legal basis:

    • Compliance with a legal obligation (Article 6(1)(c) GDPR)

Our legitimate interests are based on our right to conduct and promote our business, increase demand for our services, comply with our obligations under client agreements and manage client relationships.

We have assessed the necessity and proportionality of the processing in relation to data subjects’ privacy and the protection of their personal data. In particular, we have considered the business-to-business nature of the processing, the ordinary nature of the data processed and the reasonable expectations of data subjects. We consider that the processing does not override the interests, fundamental rights or freedoms of data subjects.

Processing special categories of personal data

When organising events, training courses and other occasions, we may process and disclose information on special diets and food restrictions provided by participants or registrants in order to arrange catering. We may also process information on accessibility and assistance needs so that these can be taken into account in the arrangements. In addition, we process medical certificates without diagnostic information if a data subject applies for a refund following the cancellation of paid training due to illness.

The information may include health data or other special categories of personal data if the data subject chooses to provide such information. The processing of this information is based on the data subject’s explicit consent (Article 9(2)(a) GDPR).

Electronic direct marketing

We send electronic direct marketing, for example by email, to representatives of companies and organisations concerning services related to their position or professional duties. Recipients may opt out of electronic direct marketing at any time by using the unsubscribe link in the email.

We also send marketing newsletters to recipients who have given their consent to receive them. Consent may be withdrawn at any time by using the unsubscribe link in the email.

Cookies and other tracking technologies

We use cookies and other similar technologies on our website.

Social media pages

We maintain pages on various social media services. Where applicable, including in relation to page visitor data (‘Page Insights’), we act as a joint controller with the relevant service provider. We apply the standard joint controllership terms of Meta Platforms Ireland and LinkedIn Ireland Unlimited.

3. Categories of personal data processed

We process the following categories of personal data:

  • Basic information, such as name and contact details (including email address, telephone number and address), company or other organisation and job title, LinkedIn profile information and, in the case of private traders, the trader’s name and Business ID
  • Client relationship information, such as order history; registration and attendance information for training courses and other events; customer communications and enquiries; client reviews and feedback; marketing campaign information; and direct marketing consents and objections
  • Contract and invoicing information
  • Cookie data, including personal data collected through cookies and similar technologies
  • Social media data, such as likes, comments and messages
  • Other information provided by the data subject, such as dietary information; information about accessibility and assistance needs; medical certificates without diagnostic information; information stored on the learning platform; and responses to surveys relating to training courses

Providing personal data to the controller is not mandatory. However, if the necessary information is not provided, the controller may be unable to process an enquiry, establish or manage a relationship with the client organisation represented by the data subject, deliver services or fulfil its other obligations.

4. Sources of personal data

Personal data is collected:

  • Directly from the data subject, for example through forms, emails, meetings and the use of the website and services
  • From the corporate or organisational client with which the data subject is associated, for example the data subject’s employer
  • From public sources, such as company registers, and from business and contact information services
  • From partners, such as koulutus.fi

We always comply with data protection legislation and good data-processing practices when collecting and processing personal data.

5. Disclosure and transfer of personal data

Personal data is transferred to subcontractors and service providers selected by the controller, such as providers of IT and cloud services and suppliers of CRM, marketing, communications or invoicing systems. These parties process personal data on our behalf under data processing agreements that comply with the GDPR.

Personal data may be disclosed:

  • In connection with corporate transactions, such as a merger, business acquisition or business transfer, for example to the parties involved and their advisers
  • In connection with legal proceedings or regulatory processes
  • To competent authorities as required by law

In addition, information on participation in training may be disclosed to the purchaser of the training or the participant’s employer to verify the accuracy of invoicing.

Personal data may be transferred outside the European Union and the European Economic Area, for example when we use service providers whose subcontractors are located outside the EU and the EEA, provided that the transfer has a legal basis under the GDPR.

A transfer may be based, for example, on an adequacy decision by the European Commission, the EU-US Data Privacy Framework where the recipient is certified under it, or standard contractual clauses approved by the European Commission and, where necessary, supplementary safeguards.

6. Retention of personal data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or for as long as required by legislation, contractual obligations or the establishment, exercise or defence of legal claims.

When there is no longer a legal basis for retaining personal data, the data is deleted or anonymised.

7. Rights of data subjects

Data subjects have the following rights:

  • Right of access: Data subjects have the right to obtain confirmation as to whether personal data concerning them is being processed and to access that data and receive information about its processing.
  • Right to rectification: Data subjects have the right to have inaccurate or incorrect personal data rectified and incomplete personal data completed.
  • Right to erasure: Data subjects have the right to request the erasure of their personal data, for example where the controller no longer has another legal basis for processing following the withdrawal of consent or an objection to processing.
  • Right to restriction of processing: Data subjects have the right to request the restriction of processing under the conditions set out in the GDPR.
  • Right to data portability: Where processing is based on consent or the performance of a contract, data subjects have the right to receive the personal data they have provided to the controller in a structured, commonly used and machine-readable format and to transmit that data to another controller.
  • Right to object: Data subjects always have the right to object to the processing of their personal data for direct marketing. Data subjects also have the right to object, on grounds relating to their particular situation, to processing based on legitimate interests.

However, the controller may refuse such a request if there are compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject, or if the processing is necessary for the establishment, exercise or defence of legal claims.

  • Right to withdraw consent: Where processing is based on consent, data subjects have the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
  • Right to lodge a complaint: Data subjects may lodge a complaint with a supervisory authority if they consider that the controller has processed their personal data in breach of this Privacy Notice or applicable legislation. The supervisory authority in Finland is the Office of the Data Protection Ombudsman.

Data subjects may obtain further information about exercising their rights and may exercise those rights by contacting the controller. The controller’s contact details are provided in section 1 above.

Requests concerning the exercise of rights must be sufficiently specific for the controller to process them. The controller may request additional information to verify the identity of the data subject.

8. Data security

Personal data is protected through appropriate technical and organisational measures. Access is restricted to persons who are authorised and need the data for their work. Persons who process personal data are subject to confidentiality obligations. The controller protects personal data through measures including access control, information system security, staff instructions and other safeguards appropriate to the nature and risks of the processing.

9. Changes to this Privacy Notice

The controller updates this Privacy Notice as necessary, for example as its services and operations develop, change or expand. Changes may also result from amendments to legislation, case law or guidance issued by supervisory authorities. The updated Privacy Notice will be published on our website. We encourage you to review the Privacy Notice on our website regularly.