Privacy Notice for Partners

Read more below.

HKScan Oyj, 0111425-3, and/or any affiliate entity owned or controlled by HKScan Oyj (“HKScan”, “we”, “us”) is the data controller in relation to the processing of your personal data as our business partner or as a contact person for our business partner (for the purposes of this privacy notice, the term “business partner or “you” shall encompass our suppliers, service providers and customers operating under legal entity as well as suppliers and service providers operating as a sole trader or similar).

On this page, we describe how we collect, process and share the personal data that we receive, collect and store. Personal data means any information which may be used to identify an individual. Information relating to a sole trader, involving one or more individuals, is considered personal data. Information relating to a legal entity is not personal data, but information related to such entity’s representative or contact person is regarded as personal data.

It is important to us that you feel safe with how we handle your personal data. We take measures to ensure that your personal data is protected and that the processing of your personal data is carried out in accordance with applicable data protection regulations and our internal policies and procedures. In order to obtain more specific information of the retention periods of personal data, please see your local language version of this privacy notice.

Please see the table below to get more information on HKScan entities that may process personal data, in accordance with the purposes set out in this privacy notice, as a data controller. The relevant data controller for the processing of your personal data is primarily the HKScan entity with whom your organisation has concluded agreement.

Data controller

HKScan Oyj

HKScan Finland Oy

Paimion Teurastamo Oy

HKScan Sweden AB

HKScan Denmark A/S

AS HKScan Estonia

AS Rakvere Farmid

AS HKScan Latvia

HKScan Poland Sp. zo.o

We may collect your personal data in the following ways:

Personal data that you give to us, e.g. when filling in forms on our website or other forms that we may ask you to complete, or corresponding with us by telephone, email or otherwise.

Personal data that we collect or generate automatically, e.g. when you visit our website, we will automatically collect personal data about you and your visit, including the internet protocol (IP) address used to connect your device to the internet (read more about processing of your personal data on our websites here), or when you visit our premises, we may collect your personal data through video devices (read more about the processing of your personal data through video surveillance here).

Personal data that we collect from other sources, e.g. when we have a business relationship, your colleagues or other business contacts may give us personal data about you such as your contact details or details of your role in the relationship, or if we collect information from third party data providers or publicly available sources for anti-money-laundering, background checking and similar purposes.

We process your personal data for the following purposes:

Manage business relationship

We process your personal data for the purpose of managing business relationship, e.g. when registering your contact information in our database, archiving agreements, managing invoices, performing background checks (to protect our business from fraud, money-laundering, breach of confidence and other financial or business crimes), and managing orders and their deliveries.  

Categories of personal data

Legal basis

  • Identity details
  • Contact details
  • Organizational details
  • Financial information
  • Background check data
  • Purchase/sales data

Legitimate interest (legal entities). The processing is necessary in order to fulfil our legitimate interest of managing the business relationship.

Performance of a contract (sole traders). We are required to process your personal data in order to fulfil the agreement concluded with you.

Storage period: Your personal data is stored during the business relationship and thereafter for a period of 10 years in order for us to fulfil our legitimate interest of handling and meeting any legal requirements. We store only accurate and up-to-date personal data. In case you are no longer the relevant contact person for this purpose, we will delete your personal data and update the required personal data with accurate data.

On the other hand, background check data is stored only for a period necessary in order to assess business partner’s reliability.

 

Facilitate communication for business reasons

We process your personal data in connection with facilitating business communication, for example, when managing contact details and when we correspond with you by email.

Categories of personal data

Legal basis

  • Identity details
  • Contact details
  • Your communication

Legitimate interest. Processing is necessary in order to fulfil our legitimate interest of facilitating communication for business reasons.

Storage period: Personal data relating to our communication with business partners is retained for a period of 10 years from the most recent communication in each conversation in order for us to fulfil our legitimate interest in handling and meeting any legal requirements.

 

Answer your questions and handle feedbacks or reclamations

If you contact us to provide feedback, reclamation or to ask questions, we will process your personal data for the purposes of answering your questions and handling feedback or reclamation from you. You may provide feedback or reclamation to us via different channels, e.g. by filling and submitting forms on our website or by communicating with us by calling our customer service.

Categories of personal data

Legal basis

  • Identity details
  • Contact details
  • Organizational details
  • Your communication

Legitimate interests (legal entities). The processing is necessary in order to fulfil our legitimate interests in answering your questions and handling feedbacks or reclamations.

Performance of a contract (sole traders). We are required to process your personal data in order to fulfil the agreement concluded with you.

Storage period: Personal data processed in connection with handling feedback is stored for as long as is required to satisfy the purpose for which it was collected and thereafter if it is necessary for the purposes of establishing, exercising or defending legal claims.

Personal data processed in connection with handling reclamations is stored as long as is required to satisfy the purpose for which it was collected and thereafter in order for us to fulfil our legitimate interest in handling and meeting any legal requirements.

 

Ensure quality of and improve our customer service

When you contact us by telephone, we will automatically record calls received. In this connection, we may process your personal data for the purposes of ensuring quality and improving our customer service. For instance, we may use call records to ensure that you have received good service from us or to improve the quality of our customer service through internal trainings.  

Categories of personal data

Legal basis

  • Call records

Legitimate interest. The processing is necessary in order to ensure quality of and improve our customer services.

Storage period: Call records are stored for as long as is required to satisfy the purpose for which they were collected and thereafter if itis necessary for the purposes of establishing, exercising or defending legal claims.

 

Communicate business related information or marketing content

If you sign up to subscribe newsletters, catalogues, press releases or similar information regarding HKScan and its business, we will process your personal data for the purposes of providing the requested subscription or information to you.

Categories of personal data

Legal basis

  • Identity details
  • Contact details
  • Professional information

 

Legitimate interest. Where the communication provided to you may not be regarded as electronic direct marketing, for instance when you subscribe to one off content, the processing is necessary in order to fulfil our legitimate interest of providing you with the information you have requested.

Consent. Where the communication provided to you may be regarded as electronic direct marketing, for instance when you subscribe to our newsletter, the processing is necessary in order to provide you with the subscription and information you have requested.

Storage period: Your personal data is stored for this purpose until you unsubscribe from the information requested. After you have unsubscribed from communication from us, we will erase personal data processed for this purpose.

 

Carry out events and other activities

We process your personal data if you participate to an event organized by us. In this regard, we process your personal data for the purposes of carrying out events, e.g. when we receive and register your participation as well as when we communicate with you in connection with events.

Categories of personal data

Legal basis

  • Participant data
  • Identity details
  • Contact details
  • Food preferences
  • Organizational details

Legitimate interest Processing is necessary in order to fulfil our legitimate interest of carrying out events.

The data subject has given explicit consent to the processing (Article 9 (2) (a) GDPR). We may process relevant special categories of personal data such as health data only if you submit such data to us voluntarily, thus with your express consent.

Storage period: Your personal data will be retained for this purpose prior to and during the event and thereafter in order for us to fulfil our legitimate interest in evaluating the event and following up on event participation, as well as to plan any future events.

 

Manage and protect IT systems and services

In order to manage and protect our website, services and related IT systems, e.g. upon logging, troubleshooting, backup, change and problem management in systems and in connection with potential IT incidents, we process, to the extent necessary, your personal data.

Categories of personal data

Legal basis

  • Identity details
  • Contact details
  • Organizational details
  • Online identifiers
  • Login data

Legitimate interest. The processing is necessary in order to fulfil our legitimate interest of managing and protecting our website, services and related IT systems.

Storage period: Your personal data is stored during the same period stated in relation to each purpose of the processing of your personal data above. Personal data in logs are stored for as long as necessary for troubleshooting and incident handling. Data contained in backup can be stored for longer periods in order to properly protect IT systems in accordance with backup and disaster recovery procedures.

 

Comply with legal obligations

We process your personal data in order to fulfil legal obligations, e.g. accounting or tax related obligations.

Categories of personal data

Legal basis

All categories of personal data that have been col­lected and which are necessary in order to fulfill each legal obligation.

Legal obligation. The processing is necessary in order to fulfill our legal obligations.

Storage period: Your personal data is stored for such period that is necessary in relation to each legal obliga­tion.

 

Establish, exercise and defend legal claims

We process your personal data, to the extent it is necessary, to handle and defend legal claims, e.g. in case of a dispute or litigation.

Categories of personal data

Legal basis

All categories of personal data that have been col­lected and which are necessary in order to establish, exercise and defend legal claims.

Legitimate interest. The processing is necessary in order to fulfil our legitimate interest of handling and defending legal claims.

Storage period: Your personal data is stored for such period that is necessary for this purpose.

Where necessary, we share your personal data with others. The recipient is the data controller for the processing of your personal data, unless we have stated otherwise.

We share your personal data with:

Service providers

In order to fulfil the purposes of the processing of your personal data, we share personal data with service providers that we have engaged. These service providers provide IT (such as operation, technical support and maintenance of IT systems), consulting, invoicing and marketing services to us. The service providers may only process your personal data for these purposes and in accordance with our instructions and not for their own purposes. We are the data controller for the processing of personal data that the service providers carry out on our behalf.

Other recipients

In certain cases we share, if necessary, your personal data with other recipients for certain purposes (e.g. to fulfill legal obligations and to handle and defend legal claims).

Recipient

Purpose

Legal basis for the transfer

HKScan Group companies

We may share necessary personal data with other HKScan Group companies for internal administrative purposes, e.g. in connection with managing the business relationship.

Legitimate interest (legal entities). The processing is necessary in order to fulfill our legitimate interests relating to internal administration purposes.

Public authorities

>We share necessary personal data with public authorities if we are obligated under law to disclose the information.

Legal obligation. The processing is necessary in order to fulfill legal obligations.

Banks

We share your personal data with relevant banks for the purposes of managing the producer relationship, e.g. in connection with issuing payments in accordance with our contractual obligations.

Legitimate interest (legal entities). The processing is necessary in order to fulfill our legitimate interest of managing the business relationship.

Performance of a contract (sole traders). We are required to process your personal data in order to fulfil the agreement concluded with you.

External advisors

We share necessary information with external advisors, e.g. audit firms, and law firms if we are obligated under law to share the information or in order to manage and defend legal claims.

Legal obligation and legitimate interest. The processing is neces­sary in order to fulfill legal obli­gations or, alternatively, to fulfil our legitimate interest of managing and defending legal claims.

Courts, counterparties etc.

In order to manage and defend legal claims we share personal data to other parties.

Legitimate interest. The pro­cessing is necessary in order to fulfil our legitimate interest of managing and defending legal claims.

Law enforcement authorities, e.g. police

We share personal data with law en­forcement authorities, e.g. the police if we are obligated under law to disclose information.

Legal obligation. The processing is necessary in order to fulfill legal obligations.

Potential buyers and sellers

We share personal data with potential buyers and sellers in case of an acquisi­tion of the business or a merger.

Legitimate interest. The pro­cessing is necessary in order to fulfil our legitimate interest of carrying out the acquisition or the merger.

We always strive to store and process personal data within the EU/EEA. However, some of our service providers are located outside the EU/EEA and in such a case personal data will be processed outside the EU/EEA. In order to ensure that the personal data is protected we make sure that appropriate safeguards are in place in relation to the service providers which handle your personal outside the EU/EEA, e.g. by way of data transfer agreements (which include standard data protection clauses adopted by the EU Commission). If you have questions regarding to which countries your personal data is transferred and which safeguards we take to protect your personal data, or to request a copy of such safeguards and information, respectively, where they are available, please contact us at privacy@hkscan.com.

Under data protection regulations, you have certain rights in relation to the processing of your personal data. We process your personal data to the extent necessary in order to fulfill your rights. Please submit requests for exercising your rights through our data privacy website or by contacting us at privacy@hkscan.com.

You have the right to:

Access your personal data

You have the right to access personal data we process about you. You may request a copy of your personal data through our data privacy website, which can be found here. We will provide you with it unless we have lawful reasons not to share this data or if sharing the data would adversely affect the rights and freedoms of others.

Update your personal data

Furthermore, you have the right to request that incorrect or incomplete personal data is corrected or completed.

Withdraw consent

To the extent we rely on your consent to process personal data you have the right to me with­draw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Object to the processing of personal data

You have the right to object to the processing of your personal data based on a legitimate interest for reasons which concerns your particular situation. In such a situation, we will stop using your personal data where the processing is based on a legitimate interest, unless we can show that the interest over­rides your privacy interest or that the use of your personal data is necessary in order to manage or defend legal claims.

Delete your personal data

Under certain circumstances you have the right to request that your personal data is deleted. However, we cannot delete your personal data if we for example are obligated under law to keep the data.

Restrict the use of your personal data

You have the right under certain circumstances to request that the processing of your personal data is restricted. If the processing of your personal data has been restricted we may only, besides storing the data, process your personal data with your consent, or in order to establish, exercise or defend legal claims or to defend rights of others.

Transfer your personal data (data portability)

Finally, you have the right to request a copy of the personal data that we store about you in a struc­tured, commonly used and machine-readable format (data portability). The right to data portability, compared to the right to access, only comprises such personal data you yourself have provided and which we process based on certain legal grounds, e.g. your consent.

We may occasionally update this information, e.g. if we would process personal data for new pur­poses, collect additional categories of personal data or share personal data with other recipients. In such a case we will notify you in an appropriate way. The latest version of the information is always published on this page.

If you have any questions regarding the processing of your personal data, please do not hesitate to contact us. See below for contact details. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority within your jurisdiction.

HKScan Oyj
Company registration number: 0111425-3
Lemminkäisenkatu 48, 20520 Turku
E-mail: privacy@hkscan.com

Please see the table below for further information regarding the categories of personal data that we process.

Category

Examples of Personal Data

Identity details

  • First name, last name
  • User identity
  • Personal identity number
  • Signature

Contact details

  • Address
  • Email address
  • Telephone number

Organizational details

  • Trade name
  • Representatives
  • Geographical placement
  • Customer type and number
  • Supplier type and number
  • Service provider type and number

Financial information

  • Bank account
  • Information on relevant financial interests
  • Information on ownerships

Background check data

  • Trade name and other identity details
  • Persons holding responsible positions
  • Credit rating / status
  • Other information from public or governmental registers

Purchase/sales data

  • Purchase amounts
  • Sales amounts

Participant data

  • Activity
  • Date

Food preferences

  • Food allergies

Your communication

 

Call records

 

Online identifiers

  • IP address
  • Device and browser information

Login data

  • Time stamp
  • Log entry