Casemet Oy Privacy Statement

Casemet Oy Privacy Statement

This is the privacy statement of Casemet Oy (Data Protection Act (1050/2018) and the EU General Data Protection Regulation (2016/679)). Last updated on August 27, 2026.

Data controller

Casemet Oy (FI 27376083)
Insinöörinkatu 1, 50100 Mikkeli

Contact person for register matters

Casemet Oy, Tiia Miettinen, tel. +358 40 135 0111

Name of the register

Customer Register

Purpose of processing personal data

Personal data is processed for the management and analysis of the customer relationship and other relevant relationships, the provision of services, the development and planning of our business, as well as marketing, direct marketing, distance selling, opinion and market research, and customer communications, which may also be carried out electronically and in a targeted manner. Depending on the circumstances, the legal basis for processing is the performance of a contract, the data controller’s legitimate interest, or the data subject’s consent. Consent is used where required by applicable legislation, for example for certain types of electronic direct marketing.

We use the MailerLite service to send newsletters. MailerLite acts as a data processor on our behalf. MailerLite processes newsletter recipients’ information, such as their name and email address, for the purpose of sending and managing newsletters. Information concerning MailerLite and the sub-processors it uses is described in MailerLite’s Privacy Policy and Data Processing Agreement.

Personal data processed

The following data may be processed:

For those who have purchased a product and/or service, the customer register may also contain the following data in addition to the above:

Regular sources of information

The personal data is collected directly from them, from various services they use, and through different marketing actions such as promotional lotteries, contests, and events. Personal data may also be collected and updated from the registers of business partners and from authorities and companies providing personal data services.

Retention period for personal data

Personal data is retained only as long as it is necessary for the purposes set out in this statement or for the retention periods set out in our legislation.

Regular disclosures of data

Data may be disclosed in accordance with the applicable laws upon request from competent authorities or other entities. Data may also be disclosed in connection with corporate transactions to buyers if Casemet Oy sells or otherwise restructures its business. Data may be transferred to Casemet Oy’s selected business partners who process data on behalf of the data controller based on a cooperation agreement. In such cases, the data processor is not permitted to process the transferred data for its own purposes in its own registers.

Transfers of data outside the EU or EEA

Data will not be transferred outside the European Union or the European Economic Area unless it is necessary for the purposes of processing personal data or for the technical implementation of data processing. In such cases, data transfers comply with the requirements of the General Data Protection Regulation.

Principles of how the data register is secured

Personal data is protected against unauthorized access and unlawful processing (e.g., destruction, alteration, or disclosure). Each processor may only process personal data necessary for their work tasks. Documents are stored in a locked space protected from unauthorized access. Documents are printed only when necessary, and paper printouts are destroyed after use.

Electronically processed data in the register is protected by firewalls, passwords, and other commonly accepted technical security measures in the industry. Only specifically authorized employees of the data controller and its contracted service providers have access to the register data, granted through access rights by the data controller.

Rights of the data subject

The data subject has the right to inspect what personal data about them has been stored in the register. Upon request, necessary corrections and additions will be made to the personal data, or incorrect, unnecessary, incomplete, or outdated data will be deleted for the purposes of data processing. Inspection and updating of data can be done by contacting Casemet Oy’s responsible person for register matters.

The data subject has the right to request the deletion of their personal data and to object to its processing for direct marketing purposes in accordance with applicable data protection legislation.

Other rights related to the processing of personal data

Casemet Oy reserves the right to modify this privacy statement by posting updates on its website. Changes may also be based on legislative amendments. We encourage regular review of this statement.

This privacy statement was last updated on August 27, 2026.