Privacy policy, whistleblowing system of Joo Group Oy

  1. Controller

Joo Group Oy Tunnelitie 1, 02800 Kauniainen, Finland

Tel. +358 (0)20 766 1390 info(at)joogroup.fi

Joo Group Oy (controller) processes personal data in compliance with applicable data protection legislation.

  1. The purposes and legal basis for processing personal data

The purpose of the processing of personal data is to maintain the whistleblowing system of Joo Group Oy, intended in directive (EU) 2019/1937 on the protection of persons who report breaches of European Union law. The whistleblowing system is intended for reporting suspected wrongdoing and it is not intended for claims or customer feedback, for example.

Joo Group Oy processes the personal data submitted in the whistleblowing system. The purpose of the processing of personal data is to investigate suspected wrongdoing in more detail. Reports can, however, also be submitted anonymously.

The legal basis for processing personal data submitted to the whistleblowing system is the data subject’s consent and, regarding the object of the report, the statutory obliga-tion of the controller.

  1. Categories of personal data that are processed

Joo Group Oy collects the following personal data from the whistleblowing system: name and contact details (telephone number, email and street address) and other data submitted by the whistleblower regarding, for example, the suspected wrongdoing. Data regarding the object of the report may also be processed if the object of the report is found to be linked to the suspected wrongdoing on the basis of the report.

  1. Regular sources of data

Personal data from the whistleblowing system is collected from the whistleblower.

  1. The recipients of personal data/disclosure and transfer of personal data

The service provider of the whistleblowing system is Juuriharja Consulting Group Oy. The service provider is the controller’s data processor and processes data with the assistance and on behalf of the controller. The data processor may also use subcontractors.

The controller’s data processor may transfer data outside the European Union or the European Economic Area provided an express written agreement has been made thereof in advance and the data protection legislation valid at a given time is complied with in the transfer.

The data controller does not disclose the personal data of the data subjects to third par-ties, except when the controller has a statutory obligation/right to disclose data to a competent authority.

The controller may not prevent the possible transfer of third-party cookie data from the website outside the European Union or the European Economic Area.

  1. The storage period of personal data

The controller shall process and store the data only for as long as is necessary and proportionate for the purpose according to law. Personal data that bears no clear significance for the processing of a specific report cannot be collected or, if collected accidentally, such data must be erased without undue delay.

  1. Data subjects’ rights

Data subjects have the right to:

  • Receive information on the processing of their data, unless expressly exempted by law.
  • Have access to their personal data
  • Rectify their personal data
  • Have their personal data deleted (right to be forgotten)
    • provided the data subject withdraws their consent and there is no other legal basis for the processing of their personal data.
  • Restrict the processing of their personal data.
  • Be notified of the rectification or deletion of personal data or the restriction of the processing of their personal data.
  • Transfer their personal data from one system to another.

To exercise the aforementioned rights, please contact Joo Group Oy’s customer service team. Contact details can be found in item 1 of this Privacy Policy.

  1. Processing and profiling of personal data

The controller does not process personal data by means of automated decisionmaking.

  1. Further processing of personal data

The controller does not process personal data for purposes other than those described in this Privacy Policy.

  1. General description of the appropriate technical and organisational measures of the controller

The data is processed only by those who are required to do so in order to perform their job and who have committed to the confidentiality provisions.

  1. Changes to the Privacy Policy

This Privacy Policy was updated on 4 May 2022.

The controller has the right to change this Privacy Policy. The controller shall inform data subjects of specific changes to this Privacy Policy before they take effect.

If you have any questions regarding our data processing, we kindly ask you to contact us by email to info(at)joogroup.fi or telephone on +358 (0)20 766 1390.