Privacy statement for the visitors of Elo’s office building and camera surveillance
Data controller and Data Protection Officer
The data controller for your personal data is Elo Mutual Pension Insurance Company (”Elo”), at Revontulentie 7, 02100 Espoo, p. 020 703 50 (switchboard)
Read more about data protection at Elo or get in contact with our Data Protection Officer:
Tuukka Jousi, email@example.com, p. 020 703 50 (switchboard).
For what purposes do we process your personal data?
What personal data do we process about you?Your personal data is any information that can be linked to you or used to identify you. In access management, we process the name and company or organisation information of the visitors of Elo office building and office premises, as well as information about the host of the visit. In camera surveillance, the cameras on different sides of the office building, record an image recording and information about the place and time of the recording. We process visitors’ network information, including logs and other tracking information, to enable visitors to connect online.
What are the sources of your personal data?Personal data is collected from the visitor directly or from the host of the visit. Personal data is also gathered from camera surveillance recordings and in connection with the use of the network connection.
To whom is your personal data transferred or disclosed?Information is only disclosed to third parties when the recipient has the right, by law, to receive information from Elo, or in exceptional circumstances upon consent of the data subject, for example to safeguard the rights of the visitors or others.
Elo uses trusted external service providers, which process personal data on behalf of Elo. These are for example the camera surveillance service and outsourced administration of the system.
Will your data be transferred outside Europe?The information of the visitors of Elo’s office premises is not transferred outside European Union or European Economic Area.
How long do we retain your data?We retain your personal data only as long as necessary to fulfil the purposes set out in this privacy statement or in accordance statutory retention periods, after which the data will be deleted. The camera surveillance recordings are retained so that the retention period is maximum of twelve (12) months. In access management, the retention period for access information is one (1) year. This retention period also applies to the access information by visitors, if they have been granted an access ID for the duration of the visit.
What are your rights as a data subject?
You have the rights provided by data protection law to the personal data processed at Elo.
• Right to access data: You have the right to know what information Elo is processing about you. You also have the right to receive a copy of the data that is being processed as well as the necessary information related to the data processing.
• Right to rectify information: You have the right to have inaccurate, outdated, or incomplete information about yourself rectified or supplemented.
• Right to deletion of data: You have the right to request the deletion of information concerning you under certain conditions. Personal data may be deleted, for example, if it is no longer needed for the original processing purposes or if you object to the processing of your personal data for direct marketing. Please note that despite of your request, Elo may have to continue processing your information, for example to comply with legal obligations, when it will not be possible to delete the data.
• Right to restrict processing: In certain situations, you have the right to demand that the processing of your personal data is restricted so that Elo only has the right to retain such personal data. You can for example request that the processing of your information is restricted for the period of the investigation, if you consider that the information about you is inaccurate or the accuracy needs to be further investigated.
• Right to request data to be transferred to another system: If the processing of your personal data is based on consent or contract, you have the right to have your data transferred to another data controller. The right of transfer applies to data that you have provided to Elo yourself and that is stored in an electronic information system. If technically possible, data controller must transfer your information directly to another controller.
• Right to object processing: In certain situations, you have the right to object processing of your personal data if the processing is not based on legal obligation or contract.
• Automated decisions, including profiling: You have the right not to be subject of a decision that is based solely on automated processing, such as profiling, which has legal or other significant effects on you.
If you would like to exercise your rights, please submit an identifiable written request to Elo’s Data Protection Officer via email (firstname.lastname@example.org) or by mailing Elo Mutual Pension Insurance Company, Data Protection Officer, 00041 Elo. Please note that you will need to prove your identity before the request is fulfilled, so please include your up-to-date contact details in the request.
Elo will respond to requests without undue delay, in any case within one month of receipt of the request. The provided information and actions based on the data subjects’ requests are primarily free of charge, unless the requests are manifestly unfounded, unreasonable, or repetitive, in which case Elo may also refuse to fulfil the request on these grounds.
If you suspect that your personal data has been processed in breach of data protection law, you have the right to lodge a complaint with the data protection authority, Office of the Data Protection Ombudsman, P.O. Box 800, 00531 Helsinki or www.tietosuoja.fi.