73Health Privacy notice

Data Protection and Registry Statement

This is a Data Protection and Registry statement in accordance with the Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR), 73Health ISMS, ISO27001, HIPAA and NIS2.

 

Prepared: 12/05/2022, Last change: 1/8/2024

 

 

1. Controller and contact person

Controller: 73Health Global

Address: Sokasaarentie 93, 87800 Kajaani, Finland

Phone: +358 400 94 44 92

Email: kimmo.nikkanen (at) 73health.fi

Website: https://www.73health.fi/

Contact person: Kimmo Nikkanen, CEO

 

2. Registered

The register processes the personal data of contact persons and trustees of organizations related to the operations of 73Health, as well as job or work-study job applicants (“Registered”).

 

 

3. Basis and purpose of processing personal data

Personal data is processed for the following purposes:

  • Managing customer relations and customer service.
  • Billing
  • Purposes related to the services and products of the registrar, such as the development, provision and implementation of services.
  • Implementation of the rights and obligations of the customer and the controller.
  • Processing of job applications and communication related to recruitment.
  • Depending on the purpose of personal data processing, the legal basis for the processing of personal data is the controller’s statutory obligations, agreement, consent and the controller’s legitimate interest.

 

The legitimate interest of the data controller is the basis for processing when there is a valid connection between the data subject and the data controller. Such a factual connection can be formed, for example, when the data subject is in contact with the data controller on his own initiative, or when the data controller processes the personal data of the data subject, for example in connection with business or cooperation activities between the registered employer and the data controller.

In addition, the data controller may, based on a legitimate interest, record in the customer register the information of potential customers and their contact persons and representatives, whom the data controller can reasonably expect to be interested in acquiring services or products offered by the data controller.

 

Personal data is processed

On the basis of registered consent, in connection with filling out the form, when data is entered and saved in 73Health’s information system.

Based on the file downloaded from our registered website, in which case the personal data is stored in 73Health’s information system.

Personal data is also stored in 73Health’s information system based on the registrant’s own files sent by e-mail.

The registered person has the right to withdraw their consent to the processing of personal data at any time by contacting them using the contact methods indicated in this privacy statement.

 

 

4. Personal data to be processed

The register contains information about the following persons:

Customer register

  • Name
  • E-mail
  • Telephone number
  • Company and position
  • Company address information
  • Information related to the customer relationship and the order
  • Site behavior and analytics

 

Job applicant register

  • Name
  • E-mail
  • Telephone number
  • Job application, curriculum vitae and other additional information provided by the job seeker
  • Information about the progress of recruitment and the final result
  • Our employees’ assessment of the employee’s suitability for the task
  • Communication related to recruitment with the job seeker
 
 

5. Registered

Personal data is obtained mainly from the following data sources:

  • Directly from the registrant himself to manage the customer relationship.
  • Directly from the registered person as part of job search and recruitment.
  • Directly from the registrant himself as part of another cooperative relationship.
  • Directly from the registrant himself as part of another cooperative relationship.
  • From a representative of the registered employer or other entity that has a customer, cooperation or other contractual relationship with the data controller.

 

Customer register:

Personal data is stored in the register if the person belongs to a partner or customer company of 73Health.

 

Job applicant register:

Information is stored in the register after the job seeker fills in the 73Health job application form or contacts us by email. We also collect information from our employees participating in recruitment, who assess the suitability of the job seeker for the open position.

 

 

6. Personal data retention period

The controller processes and stores personal data only as long as it is necessary for the predefined purpose of use of the personal data. Job applications are kept for two years.

Personal data that has become unnecessary and that the controller no longer has grounds to keep or process is deleted at regular intervals in accordance with the controller’s own data protection practices. In connection with the deletion of personal data, please note that the backup affects the final removal of the deleted data from the information systems.

 

 

7. Protection of personal data and information security

Digitally processed personal data is protected and stored in 73Health’s information system, to which access is limited to only those persons who need the data in question to perform their duties. The persons in question have personal usernames and passwords at their disposal.

Personal information is protected from external use. Personal data sent outside 73Health is encrypted. The used workstations and storage media are encrypted.

 

 

8. Regular sharing and transfer of personal data

As a rule, the controller does not hand over personal data of registered users to outsiders, except if the authorities require it by law or if required by mandatory legislation. In addition, the data controller uses reliable service providers in connection with the technical implementation of its services, who process personal data on behalf of the data controller in accordance with the applicable privacy protection legislation and this privacy statement.

In principle, personal data is not transferred outside the European Union or the European Economic Area. Any transfers of personal data are always carried out in compliance with applicable data protection legislation.

The job seeker’s personal data may be disclosed to 73Health’s partners for the implementation of measures and services related to our company’s operations.

 

 

9. Register protection and information security

Customer register:

Only those persons who need the information in their work tasks have access to the register. Personal data can be processed in different information systems, which are either managed by 73Health or its partners. We have ensured that our partners comply with data protection legislation.

Job applicant register:

Job applicants’ personal data is stored on a server that meets the requirements of the EU data protection regulation. 73Health’s employees have the right to access the register’s information only when their job requires it.

Profiling:

We do not use automatic profiling as part of the processing of personal data.

 

 

10. Rights of the data subject

The registered person has the right at any time to object to the processing of his personal data for direct marketing purposes. The registrant can give 73Health channel-specific consents and prohibitions regarding direct marketing (for example, prohibit marketing messages sent by e-mail), if 73Health uses direct marketing communications.

In addition, the data subject has the right, in principle, at any time in accordance with the applicable data protection legislation:

  • Get information about the processing of your personal data.
  • Get access to your own data and check the personal data processed by 73Health concerning you.
  • Demand the correction and completion of inaccurate and incorrect personal data.
  • Demand the deletion of your personal data.
  • Withdraw consent and object to the processing of personal data to the extent that the processing of personal data is based on the data subject’s consent.
  • Object to the processing of his personal data on grounds related to his personal special situation, insofar as the basis for the processing of personal data is the legitimate interest of 73Health.
  • Receive personal data in a machine-readable format and transfer the data in question to another data controller, provided that the data subject has himself submitted the data in question to 73Health. 73Health processes the personal data in question based on the registered consent and the processing is carried out automatically.
  • Demand the restriction of the processing of your personal data.

 

The registrant must submit a request regarding the exercise of the above-mentioned right in accordance with the Contact section of this privacy statement. We can ask the registrant to specify his request in writing. Please note that before processing the request, we have the right and obligation to verify your identity, which is why we must be able to identify you sufficiently. We may also refuse to fulfill the request on the basis provided by applicable law.

 

The right to complain to the supervisory authority: Every Registered Person has the right to file a complaint with the relevant supervisory authority or the supervisory authority of the Member State of the European Union where the Registered Person’s place of residence or workplace is located, if the Registered Person considers that his/her personal data has not been processed in accordance with the applicable data protection legislation. In Finland, the supervisory authority is the office of the Data Protection Commissioner, whose contact information and instructions can be found at www.tietosuoja.fi.

Contacts: Requests regarding the exercise of the registrant’s rights, questions about this privacy statement and other contacts should be made by email to Kimmo Nikkanen at the address kimmo.nikkanen (at) 73health.fi. The registered person can also contact the address below in person or in writing:

 

 

73Health Global

CEO Kimmo Nikkanen

Sokasaarentie 93, 

87800 Kajaani, Finland

 

 

11. Cookies

We use cookies on this website, which we use to process and analyze information related to the use of our website. Cookies are small text files that are stored on your computer when you visit certain websites.

With the help of cookies, we are able to better understand what kind of content our website users are interested in and thereby improve the user experience of our website.

Cookies do not damage users’ computers or files. However, the user can request the deletion of Google Analytics cookies by clicking here.

 

 

12. Additional information

If you have any questions regarding our processing of personal data, you can contact us using the contact information provided in section 1 or section 10 of this privacy statement.

 

 

13. Changes to this privacy statement

This data protection statement can be updated from time to time, for example when the legislation changes.

This Privacy Statement was last updated on August 1st, 2024.