Privacy Policy
Using the Website (Websites) and Establishing a Relationship related to Receiving Free or Purchasing Paid Services from the Service Provider implies the User's absolute consent to this practice and the conditions defined therein for the processing of his personal data. If the User disagrees with these terms, he must refrain from using the Website (Websites) and from initiating or continuing any relationship with the Operator.
Edition effective from 02.11.2023
Finland, Helsinki
Privacy Policy
This privacy policy (hereinafter referred to as the "Policy") has been developed in accordance with the requirements of the EU General Data Protection Regulation (2016/679). This Policy is provided and applied by the individual under the law to all information that the Operator Olga Mironova (hereinafter the Operator) may receive from users when using the Operator's Websites at the following web addresses: https://www.instagram.com/koiraolo.fi/, https://www.koiraolo.fi/, https://calendly.com/koiraolo (hereinafter referred to as the "Websites"). The Policy regulates all types of processing of personal data and other information related to individuals who are consumers of the Operator's products or services. This Policy applies to the processing of personal data collected by any means, both active and passive, online and offline, from individuals located anywhere in the world.
1. Personal Data Received and Processed by the Websites
1.1. Within the framework of this Policy, "user's personal data" (the subject of personal data) means:
1.1.1. Personal data that the user voluntarily provides when submitting an application, making purchases, registering (creating an account), or in any other process of using the Websites, including last name, first name; phone number; email address.
1.1.2. Information that the Websites automatically transfer during use to the user's device using installed software, including IP address, cookie data, information about the user's browser (or other program used to access the site), usage time, requested page address, other information about visitors from traffic statistics services (the address of the page where the ad unit is located, the referral (address of the previous page), etc.), geographical information, and other information collected and processed automatically on the Websites owned by the Operator.
These data is collected to gather information about visitors' actions on the site, improve its content, enhance the usability of the site, and consequently create high-quality content and services for visitors. The data subject can change their browser settings at any time to block all cookies or receive notifications about their sending. At the same time, the data subject should understand that in this case, some functions and services of the Websites may not work correctly.
1.1.3. In addition to the data defined in paragraphs 1.1.1-1.1.2, the Operator also records information about purchases made by the data subject on the Websites.
1.2. This Policy applies only to the Websites, and the operator (website administrator) does not control or take responsibility for third-party websites to which the user may follow links on the Websites. Such resources may collect or request additional personal information from the user and perform other actions that are not related to the Operator.
1.3. The Websites do not usually verify the accuracy of the personal data provided by users and do not control their legal capacity. The operator assumes that the user provides reliable and sufficient personal data in the forms of the Website resources and keeps this information up to date.
2. Purposes of Collecting and Processing User's Personal Data
2.1. The Websites collect and store only those personal data that are necessary for providing services and/or other values to visitors of the Websites (data subjects).
2.2. The Operator has the right to use the user's (data subject's) personal data for the following purposes:
2.2.1. Identifying the parties within the framework of agreements concluded with the Website and the Operator.
2.2.2. Providing personalized services, services, and other values to the user.
2.2.3. Communicating with the user, including sending notifications, requests, and information regarding the use of the Website, providing services, and processing user requests and applications.
2.2.4. Improving the quality of the Website, its usability, developing new services and products.
2.2.5. Targeting information materials.
2.2.6. Conducting statistical and other studies based on the provided data.
2.2.7. Entering into, executing, and terminating civil law contracts with individuals, legal entities, individual entrepreneurs, and other persons in cases stipulated by applicable law.
2.2.8. Detecting, preventing, mitigating, and investigating fraudulent or other illegal activities against the Operator.
3. Conditions for Processing User's Personal Data and Transferring to Third Parties
3.1. The Website does not usually verify the accuracy of the personal data provided by users and does not control their legal capacity. The operator assumes that the user provides reliable and sufficient personal data about the proposed matters on these online resources forms and keeps this information up to date (section 1.3).
3.2. The confidentiality of the user's personal data is maintained, except in cases where the user voluntarily provides information for general access to an unlimited number of people.
3.3. The Website has the right to transfer the user's personal data to third parties in the following cases:
3.3.1. The user has expressed his consent to such actions by providing personal data.
3.3.2. The transfer is necessary as part of the user's use of certain Websites or services, values, and/or service provision to the user.
3.3.3. The transfer is made in accordance with the procedure established by law in force in Finland or another applicable law.
3.3.4. To ensure the ability to protect the rights and legitimate interests of the Website or third parties in cases where the user violates the Website's terms of use.
Thus, the Operator does not disclose personal data to third parties or share personal data without the data subject's consent, except as required by applicable law and this Policy. In particular, the Operator transfers the User's personal data to third parties to provide services to the latter (e.g., training on the Getcourse platform) in accordance with the provisions of this Policy and takes measures to keep them.
3.4. When processing the personal data of the Websites' users, the Operator complies with the data protection laws.
3.5. The Operator organizes the processing of personal data according to the following principles:
3.5.1. Legality, fairness, and justice of the purposes and methods of personal data processing in the Operator's activities.
3.5.2. Reliability of personal data, their sufficiency for the processing purposes, unreasonableness of collecting personal data in relation to the purposes announced during the collection of personal data.
3.5.3. Processing only personal data that meets the processing purposes.
3.5.4. Correspondence of the content and quantity of processed personal data with the stated processing purposes. Processed personal data should not be excessive in relation to the purposes of their processing.
3.5.5. Combining databases containing personal data that are processed for purposes incompatible with each other is not allowed.
3.5.6. Ensuring the accuracy, sufficiency, and, if necessary, relevance of personal data in relation to the purpose of processing personal data. The Operator takes the necessary measures or ensures their introduction to eliminate or clarify incomplete or inaccurate data.
3.5.7. Keeping personal data in a form that allows determining the data subject, no longer than the time required to achieve the purposes of processing personal data.
3.6. The Operator processes personal data for the time necessary to achieve the purposes for which they were collected, in any legal way, including using automation tools to process personal data in information systems or without using such tools (mixed processing) on the Internet. In any case, the personal data of the user is stored and processed for no more than 10 (ten) years from the date the user has given consent to the processing of data.
3.7. All personal data is provided (collected) directly by the user as the subject of personal data.
The data subject independently decides whether to provide or withhold his personal data and agrees that the Operator processes them freely, voluntarily, and in his own interest.
3.8. The consent given by the data subject to the processing of personal data includes the user's consent to transfer his personal data to third parties, entrust the processing of this data to third parties, and the user's consent to the cross-border transfer of this data to the Internet (when such transfer is necessary for the effective provision of services by the operator or is necessary to achieve other goals set forth in this Policy), as well as to receive emails and text messages within the framework of a paid service agreement made with the Operator or to receive advertising and marketing materials.
At the same time, cross-border data transfer means the transfer of data to third parties both in countries where the level of data protection is sufficient and not related to these countries. In any case, the Operator provides the necessary level of protection for personal data by complying with the conditions set out in section 5 of this Policy.
3.9. The user gives his consent to the processing of personal data by filling out special order forms on the Operator's website, applying for a free service from the Operator (strategic consultation, webinar registration, etc.), and concluding an appropriate service agreement (public offer) or directly when paying for services under the contract (acceptance of a public offer) by placing a "tick" confirming his consent to the processing of personal data in a special "checkbox". However, this action has legal force only with written consent.
3.10. In some cases expressly provided for in the Operator's local regulations, the user provides personal data in a different way (other than indicated in section 3.9 of this privacy statement). For example, when filling out applications for the provision of certain types of services, submitting an application for the return of funds paid for the Operator's services, the user transfers his personal data to the Operator by sending a letter to the email address: info@koiraolo.fi; at the same time - if it concerns the transfer of information other than the data listed in section 1.1 of this privacy statement - the user also agrees separately to the processing of the reported information.
4. User-Made Changes to Personal Data
4.1. The user can at any time modify (update, supplement) the personal data provided or their parts, as well as the confidentiality parameters, by sending an application to the Website administrator at the email address: info@koiraolo.fi.
4.2. The user can at any time withdraw their consent to the processing of personal data by submitting their statement to the administration at the email address: info@koiraolo.fi.
5. Measures to Protect User's Personal Data
5.1. In processing personal data, the Entrepreneur applies legal, organizational, and technical measures to ensure the security of personal data.
The assurance of personal data security is achieved, in particular, by:
5.1.1. Evaluating the effectiveness of measures ensuring the security of personal data before using such measures.
5.1.2. Detecting unauthorized access to facts and taking action to eliminate them and prevent recurrence.
5.1.3. Restoring personal data modified or destroyed due to unauthorized access.
5.1.4. Establishing rules for access to personal data processed in the personal data system, as well as ensuring the registration and recording of all operations performed with personal data in the personal data system.
5.1.5. Ensuring the availability of clauses on the confidentiality of personal data in agreements with the Operator's third parties and including them in contracts if necessary.
5.1.6. Monitoring measures taken to ensure the security of personal data and the security level of personal data information systems.
5.2. Third parties who have access to personal data on behalf of the Operator undertake to take necessary organizational and technical measures to ensure the confidentiality of such data on their personal device, where they process personal data.
5.3. The Operator is obliged to immediately cease the processing of personal data at the request of the data subject.
6. Responsibility for the Processing of Personal Data:
6.1. The service provider is personally responsible for the processing of personal data.
6.2. Person Responsible in Operations:
6.2.1. Conducts internal control regarding the compliance of the Operator, its employees, and counterparts with the legislation on personal data to which they gain access from the Operator, including the requirements for the protection of personal data.
6.2.2. Manages the acceptance and processing of registered complaints and requests.
6.2.3. Takes action to detect unauthorized use of personal data and immediate measures to protect personal data.
6.2.4. Performs continuous monitoring to ensure the level of protection of personal data.
6.2.5. Provides, upon signature, the Operator's employees with the provisions of EU legislation on personal data, including requirements for the protection of personal data, and local regulations of the Operator that prescribe the procedure for processing personal data.
6.2.6. Conducts internal control and/or audit of compliance with the processing of personal data.
7. User Responsibility
7.1. Data subjects are obligated to provide the Operator with only reliable personal information and promptly inform them of any changes. However, the Operator does not verify the accuracy of personal information and does not monitor the legal capacity of registered individuals, assuming that the registered individual provides reliable and sufficient personal information on matters proposed in the privacy policy during the registration form (subscription, payment) and keeps this information up to date.
The risk of providing incorrect personal information lies with the data subject.
7.2. The service provider intentionally does not process the personal data of minors. The Operator recommends the use of the site for individuals over 18 years old. The responsibility for the actions of minors, including their purchase of services on the Sites, lies with the legal representatives of the minors. If the Operator becomes aware that they have obtained the personal data of a minor without the consent of legal representatives, such information will be deleted as soon as possible.
7.3. The service provider is not responsible for the processing of personal data by third parties claimed by the recipient of the Operator's services as their own. In this case, the recipient of the Operator's services, who provided false information, bears the risk of being held accountable.
7.4. If the data subject wholly or partially disagrees with the terms of this policy, their use of the Site and its services must be terminated immediately.
8. Retention of Personal Data
8.1. The storage of personal data takes place in electronic form in databases located in the EU's data systems.
8.2. The storage of personal data occurs in a form that allows the identification of the data subject for a period ensuring compliance with the processing goals of personal data set in this privacy policy.
8.3. Storage of personal data occurs with access restrictions, including the creation of appropriate access levels.
8.4. Personal data contained in different electronic databases and processed for different purposes are kept separately.
9. Termination and Destruction of Personal Data Processing
9.1. If incorrect personal data is revealed when the data subject is registered, the Operator is obliged to block this data from the date of the request for the verification period, if blocking does not violate the rights and legitimate interests of the data subject or third parties.
9.2. If the confirmation of the inaccuracy of personal data is established, the Operator, based on the data provided by the data subject, is obliged to clarify the personal data within 7 (seven) working days from the submission of such data and remove the blocking of personal data.
9.3. If the Operator detects the illegal processing of personal data, the latter is obliged to stop the illegal processing of personal data within a maximum of 3 (three) working days from the date of detection.
If it is impossible to ensure the legality of personal data processing, the Operator is obliged to destroy the relevant personal data within a maximum of 10 (ten) working days from the date of detection of the illegal processing of personal data. The Operator is obliged to inform the data subject of the elimination of violations committed with their personal data or the destruction of personal data.
9.4. If the data subject withdraws their consent to the processing, the service provider is obliged to stop the processing and, if the storage of personal data is no longer required for the processing of personal data, destroy the personal data within the period of more than thirty working days from the date of receiving such withdrawal.
9.5. The Operator has the right to continue the use of the data subject's personal data after the withdrawal of consent for processing and ensure the depersonalization of such data.
9.6. The Operator sends a notification of the results of processing requests of registered users defined in this section through the support service info@koiraolo.fi by sending messages to the specified registered email address.
10. Dispute Resolution
10.1. Before filing a lawsuit in court for disputes arising from the relationship between the data subject and the service provider regarding personal data, a claim must be filed (a written proposal for the voluntary settlement of a dispute).
10.2. The recipient of the claim informs the claimant in writing of the results of processing the claim within 30 (thirty) calendar days from the date of receiving the claim.
10.3. If an agreement is not reached, the dispute will be transferred to the legal authority at the location of the Operator's registration for consideration in accordance with applicable EU legislation.
10.4. This personal data processing policy and the relationship between the data subject and the service provider are subject to applicable EU legislation.
11. Additional Terms
11.1. The Operator reserves the right to make changes to this personal data processing policy without the consent of the data subjects.
11.2. The new version of the personal data processing policy takes effect immediately upon publication on the Site, unless otherwise specified in the new version of the privacy policy.
11.3. Suggestions and comments for changing the personal data processing policy should be sent to: info@koiraolo.fi.
11.4. The invalidity of certain provisions of this policy, if recognized by the decision of a court or other authorized state body, does not imply its invalidity as a whole.
11.5. When processing personal data, the Operator does not separately verify the existence of a special system for processing personal data in the legislation of those countries whose jurisdiction includes individual recipients of the Operator's services or individuals who have provided their information on the order form on the Site. If the data subject resides in a state with a specific personal data protection system, the Operator takes all reasonable measures to ensure compliance with the requirements of personal data protection legislation set by that state or group of states. For this purpose, the data subject is obliged to inform the Operator of the existence of a special arrangement for the protection of their personal data by contacting the support service at info@koiraolo.fi.
12. Operator's Information
Olga Mironova
Yhteyspuhelin: +358442973287
Yhteyssähköposti: info@koiraolo.fi