This Privacy Notice applies to the processing of personal data relating to the contact persons, representatives and other personnel of IQI Success Insuring Oy’s corporate and organisational clients and prospective clients, as well as private traders (collectively, ‘data subjects’), for the purposes of sales, marketing, communications, the provision of services and the conduct of business operations.
Personal data means any information relating directly or indirectly to an identified or identifiable individual, such as an employee of a corporate client.
IQI Success Insuring Oy
Business ID: 1923859-6
Address: Satamaradankatu 1, 00510 Helsinki, Finland
Email: privacy@iqi.fi
We process personal data for the following purposes and on the following legal bases under Article 6 of the General Data Protection Regulation (EU) 2016/679 (‘GDPR’):
Legal bases:
Legal bases:
Legal basis:
Legal bases:
Legal basis:
Legal basis:
Our legitimate interests are based on our right to conduct and promote our business, increase demand for our services, comply with our obligations under client agreements and manage client relationships.
We have assessed the necessity and proportionality of the processing in relation to data subjects’ privacy and the protection of their personal data. In particular, we have considered the business-to-business nature of the processing, the ordinary nature of the data processed and the reasonable expectations of data subjects. We consider that the processing does not override the interests, fundamental rights or freedoms of data subjects.
When organising events, training courses and other occasions, we may process and disclose information on special diets and food restrictions provided by participants or registrants in order to arrange catering. We may also process information on accessibility and assistance needs so that these can be taken into account in the arrangements. In addition, we process medical certificates without diagnostic information if a data subject applies for a refund following the cancellation of paid training due to illness.
The information may include health data or other special categories of personal data if the data subject chooses to provide such information. The processing of this information is based on the data subject’s explicit consent (Article 9(2)(a) GDPR).
We send electronic direct marketing, for example by email, to representatives of companies and organisations concerning services related to their position or professional duties. Recipients may opt out of electronic direct marketing at any time by using the unsubscribe link in the email.
We also send marketing newsletters to recipients who have given their consent to receive them. Consent may be withdrawn at any time by using the unsubscribe link in the email.
We use cookies and other similar technologies on our website.
We maintain pages on various social media services. Where applicable, including in relation to page visitor data (‘Page Insights’), we act as a joint controller with the relevant service provider. We apply the standard joint controllership terms of Meta Platforms Ireland and LinkedIn Ireland Unlimited.
We process the following categories of personal data:
Providing personal data to the controller is not mandatory. However, if the necessary information is not provided, the controller may be unable to process an enquiry, establish or manage a relationship with the client organisation represented by the data subject, deliver services or fulfil its other obligations.
Personal data is collected:
We always comply with data protection legislation and good data-processing practices when collecting and processing personal data.
Personal data is transferred to subcontractors and service providers selected by the controller, such as providers of IT and cloud services and suppliers of CRM, marketing, communications or invoicing systems. These parties process personal data on our behalf under data processing agreements that comply with the GDPR.
Personal data may be disclosed:
In addition, information on participation in training may be disclosed to the purchaser of the training or the participant’s employer to verify the accuracy of invoicing.
Personal data may be transferred outside the European Union and the European Economic Area, for example when we use service providers whose subcontractors are located outside the EU and the EEA, provided that the transfer has a legal basis under the GDPR.
A transfer may be based, for example, on an adequacy decision by the European Commission, the EU-US Data Privacy Framework where the recipient is certified under it, or standard contractual clauses approved by the European Commission and, where necessary, supplementary safeguards.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or for as long as required by legislation, contractual obligations or the establishment, exercise or defence of legal claims.
When there is no longer a legal basis for retaining personal data, the data is deleted or anonymised.
Data subjects have the following rights:
However, the controller may refuse such a request if there are compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject, or if the processing is necessary for the establishment, exercise or defence of legal claims.
Data subjects may obtain further information about exercising their rights and may exercise those rights by contacting the controller. The controller’s contact details are provided in section 1 above.
Requests concerning the exercise of rights must be sufficiently specific for the controller to process them. The controller may request additional information to verify the identity of the data subject.
Personal data is protected through appropriate technical and organisational measures. Access is restricted to persons who are authorised and need the data for their work. Persons who process personal data are subject to confidentiality obligations. The controller protects personal data through measures including access control, information system security, staff instructions and other safeguards appropriate to the nature and risks of the processing.
The controller updates this Privacy Notice as necessary, for example as its services and operations develop, change or expand. Changes may also result from amendments to legislation, case law or guidance issued by supervisory authorities. The updated Privacy Notice will be published on our website. We encourage you to review the Privacy Notice on our website regularly.