Privacy Policy

Privacy and data protection policy in accordance with the Finnish Personal Data Act (523/1999, Sections 10 and 24) and the EU General Data Protection Regulation (GDPR).

Last updated: 8 July 2026

1. Data Controller and Contact Details

Rengastien Autotarvike Oy (0935935-1)
Rengastie 28
60120 SEINÄJOKI
rat@ratoy.fi
+358 (0)6 420 2820

Contact Person

Tino Nelimarkka

tino.nelimarkka@ratoy.fi

2. Name of the Register

Rengastien Autotarvike Customer Register

3. Purpose of Processing Personal Data

Personal data is processed for the following purposes:

  • providing, delivering and developing our products and services
  • fulfilling our contractual and other commitments and obligations
  • invoicing
  • managing and maintaining customer relationships, providing customer service and acquiring new customers
  • analysing visitor numbers and traffic sources (online behaviour) in order to assess the use of our products and services, improve customer service and enhance information security
  • enabling website maintenance

4. Legal Basis for Collecting and Processing Personal Data

The processing of personal data is based on the company’s legitimate interest in establishing, performing and maintaining a customer relationship and/or contractual relationship.

The processing of personal data may also be based on the data subject’s explicit consent.

5. Personal Data We Process

We process only personal data that is necessary for carrying out our work. The register does not contain sensitive personal data.

For electronic accounts receivable and payable records, Rengastien Autotarvike Oy maintains invoicing and purchase invoice histories. The personal data processed may include: customer number, company name, Business ID, address, email address, telephone number and invoicing information (project identifiers, names of contact persons and e-invoicing addresses).

In connection with website-specific administration and website administrators, the following personal data may also be processed: traffic source (IP address), person’s name, nickname/alias (username) and email address.

In rare cases, an administrator’s address and telephone number may be processed if the administrator has entered this information in their user profile.

IP addresses may be monitored to improve information security by analysing the sources of website traffic and identifying and preventing potentially malicious traffic.

Without the necessary personal data, we may be unable to provide the agreed product and/or service appropriately and securely.

6. Retention of Personal Data

We retain personal data for as long as necessary to provide services to the customer.

Invoicing history and invoicing information are retained in accordance with applicable accounting legislation.

Unnecessary and outdated information stored on websites is deleted without undue delay when we are notified of such information by the customer.

Data collected by Wordfence is deleted in accordance with GDPR recommendations.

7. Collection of Personal Data

The processing of personal data may be based on the data subject’s explicit consent.

We primarily obtain personal data directly from the customer.

Personal data may also be collected and updated from publicly available sources, such as company websites or the Finnish Business Information System (YTJ), for the purposes described in this Privacy Policy.

IP addresses are automatically recorded by the WordPress Wordfence security plugin and collected in anonymised form by the WP Statistics plugin.

8. Disclosure and Transfer of Personal Data

We do not disclose personal data to third parties, such as subcontractors, without a separate agreement, whether verbal or written.

We do not sell or disclose our customers’ personal data to third parties for marketing purposes.

9. Regular Disclosures and Transfers of Personal Data Outside the EU or European Economic Area

We do not regularly disclose personal data outside the company.

Some external service providers or software providers used by the company may store data outside the European Union or European Economic Area.

However, we require our service providers to implement safeguards and procedures that comply with the EU General Data Protection Regulation.

10. Cookies and Analytics

Rengastien Autotarvike Oy uses cookies on its websites to ensure the proper functioning of the website and to collect visitor statistics.

Visitor statistics are generated using the WP Statistics plugin, which is used to monitor information such as visitor numbers, the most popular pages and website usage. Statistical information is used to develop our websites and improve our services.

The website uses CookieYes for cookie consent management, allowing visitors to manage their cookie preferences and provide consent to the use of cookies in accordance with applicable legislation.

The website may use strictly necessary cookies that enable its technical operation. Cookies that are not strictly necessary are used only on the basis of the user’s consent.

10.1 Embedded Content

The website may contain embedded content from third-party services, such as YouTube. Displaying such content may result in the third-party service provider setting its own cookies or processing user data in accordance with its own privacy practices.

Where required, such content will only be loaded after the user has given consent to the relevant cookies.

10.2 Links to Other Websites

The website may contain links to other websites maintained by Rengastien Autotarvike Oy as well as, potentially, websites operated by third parties.

Each website may have its own privacy policy and cookie practices. We recommend reviewing the privacy policy and cookie practices of the relevant website when visiting another website.

11. Protection of Personal Data

Electronic data is protected by firewalls, passwords and other generally accepted technical security measures.

Personal data contained in the register is treated confidentially and may only be processed by employees whose duties require access to such data.

Personal data in paper form is stored in monitored, locked premises accessible only to authorised persons.

The website uses SSL encryption and appropriate security measures, including a firewall, Cloudflare Turnstile bot protection, up-to-date security updates and continuous code auditing.

We also maintain communication with our hosting provider to help ensure that the server environment remains up to date and secure.

Data is backed up regularly and stored using appropriate security measures. The register does not contain sensitive personal data.

12. Automated Decision-Making

We do not carry out automated individual decision-making as referred to in Article 22 of the EU General Data Protection Regulation.

13. Rights of the Data Subject

The data subject has:

  • The right to access the personal data concerning them that has been stored in the personal data register.
  • The right to request that their personal data be updated, corrected or deleted. The deletion of personal data may, however, be restricted where the data is necessary for providing a contractual service or for complying with statutory obligations.
  • The right to request the transfer of personal data from one system to another. Where applicable, personal data will be provided in a machine-readable format for transfer to another data controller.
  • The right to restrict or object to the processing of personal data in accordance with Articles 18 and 21 of the EU General Data Protection Regulation.
  • The right to object to the use of personal data for direct marketing purposes.
  • The right to withdraw previously given consent to the processing of personal data.
  • The right to lodge a complaint with the competent supervisory authority concerning the processing of personal data.

All enquiries and requests concerning this Privacy Policy should be submitted using the contact details provided in Section 1.

We ensure that personal data is processed professionally and in accordance with our confidentiality obligations.

14. Changes to This Privacy Policy

We reserve the right to update and amend this Privacy Policy.

Data subjects are responsible for reviewing the contents of this Privacy Policy regularly.

The current version of this Privacy Policy is always available on this page.