Sympa Privacy Notice
Sympa Privacy Notice
The Purpose and Scope of this Privacy Notice
Sympa Oy (later “Sympa” or “We”) is committed to ensuring data protection and the confidentiality of personal data at its possession. This privacy notice describes our data processing practices and purposes concerning processing of personal data within the scope of the privacy notice. Should you have any questions related to our personal data processing, please contact our data protection officer (dpo@sympa.com).
We may update this privacy notice from time to time, for example due to changes in applicable legislation. We will use reasonable efforts to inform you of any possible changes and their effects in due time beforehand. Therefore, we advise you to review this privacy notice always after becoming aware of any changes. This privacy notice was last updated on 23 March 2024.
Data Controller
Name: Sympa Oy
Address: Teknobulevardi 7, 01530 Vantaa, Finland
Business ID: 1938597-5
Data Protection Officer (DPO team): dpo@sympa.com
Whose Personal Data Do We Collect?
Sympa processes the personal data of the following data subjects (see section 2 what categories of personal data are processed):
Customer contact persons and customer prospects
We process the personal data of contact persons and representatives of Sympa’s customers and prospective customers.
Website visitors, subscribers and competition participants
We process the personal data of persons who visit our website, submit their contact information to us when subscribing to our newsletters, downloading material, fill out surveys, or participate in competitions.
Customer contact persons as project participants and users of support services
We process the personal data of Sympa customer’s persons in connection with implementation project management and provision of versatile support services. Those project management tools are not part of Sympa HR SaaS service and do not process Customer’s actual employee data which is processed with Sympa HR service. Project tools used are the following: for project management; Asana, and Surveypal and for support services; Hubspot. Livestorm for video training sessions. In all cases personal data is hosted within EU/EEA. The mentioned project tools do not process Customer’s actual employee data which is processed with Sympa HR service.
Other stakeholders
This group of data subjects includes persons who interact with us, such as current shareholders, analysts, potential investors, and former, current and prospective suppliers and other business partners, as well as event participants (e.g., seminars and webinars).
What Categories of Personal Data Do We Process?
We process different categories of personal data depending on your relation with Sympa. Please find more information about processed personal data below.
Customer contact persons and customer prospects
If you are a contact person or representative of Sympa’s current or prospect customer, We may process the following categories of personal data about you:
- Basic contact information, such as your name, profession, title, your employer or the organization you represent, your industry, as well as your contact details such as postal address, phone number and email address;
- Information on the business relationship, such as products and services you are interested in;
- Information relating to your use of our digital services, such as registration data for a user account, information about the service use, information collected using cookies and other similar methods. This can include the type of web browser or device you use, your browsing history on our website, your IP address, links you have clicked in an email or on our website, materials you have downloaded or the website from which you have arrived at our website;
- Information related to contacts and meetings, such as feedback and contact requests, digital forms, targeted marketing efforts, or meetings and events you have participated in;
- Classification data, such as marketing segments derived from the data described above.
Website visitors, subscribers and competition participants:
If you are a website visitor, subscriber or competition participant, We may process the following categories of personal data about you:
- Basic contact information, such as your name, profession, title, your employer or the organization you represent, your industry, as well as your contact details such as postal address, phone number and email address;
- Information about your interests, such as products and services you are interested in;
- Information relating to your use of our digital services, such as information collected using cookies and other similar methods. This can include the type of web browser or device you use, your browsing history on our website, your IP address, links you have clicked in an email or on our website, materials you have downloaded or the website from which you have arrived at our website;
- Information related to your contact with us, such as feedback and contact requests, digital forms, targeted marketing efforts, and events or competitions you have participated in;
- Classification data, such as marketing segments derived from the data described above
Customer contact persons as implementation project participants and users of support services
- Basic contact information, such as your name, profession, title, your employer or the organization you represent, your industry, as well as your contact details such as postal address, phone number and email address;
- Basic user account information, such user number, username, password, IP address;
- Support requests via Sympa support portal.
Other stakeholders
If you are a current shareholder, potential investor, analyst, former, current or prospective supplier, business partner or event participant, We may process the following categories of personal data about you:
- Basic contact information, such as your name, profession, title, your employer or the organization you represent, your industry, as well as your contact details such as postal address, phone number and email address;
- Information on the business relationship, such as products and services you are interested in;
- Information relating to your use of our digital services, such as registration data for a user account, information about the service use, information collected using cookies and other similar methods. This can include the type of web browser or device you use, your browsing history on our website, your IP address, links you have clicked in an email or on our website, materials you have downloaded or the website from which you have arrived at our website;
- Information related to contacts and meetings, such as feedback and contact requests, digital forms, targeted marketing efforts, or meetings and events you have participated in;
- Classification data, such as marketing segments derived from the data described above.
Which Sources Do We Use to Collect Personal Data?
The personal data that We process about you are:
- Given to us by you (e.g. when using our website, registering as a user of our services, sending a request for information, filling out a form, purchasing, ordering or offering products and services, participating in our events, or otherwise interacting with us by phone or digitally);
- Given to us by your employer or the organization you represent in connection with the business or other relationship between us and your employer/organization;
- Collected automatically by using digital technologies, including cookies (e.g. when you use our website);
- Collected from other legitimate sources, e.g., public and private company and business registers, public authorities, postal operators, public telephone directories, direct marketing companies, and other similar public and private registers.
Purposes and Basis of Processing Your Personal Data
We process your personal data for the following purposes:
- Delivery or purchase of products and services;
- Managing customer, supplier, shareholder or other cooperation relationships;
- Providing customer support and communication;
- Marketing and development of our products and services;
- Providing you information you have requested from us;
- Facilitating communication between you and us and collecting feedback from customers, suppliers and other cooperation partners;
- Maintaining and developing our website;
- Organizing and managing events and competitions;
- Managing work, tasks and schedules in implementation projects that Customer contact persons participate in;
- Analysis, reporting, segmentation, and statistics for the purposes explained above;
- Fulfilling statutory obligations.
The basis for processing of your personal data conducted by Sympa is one of the following:
Legitimate interest
We process your personal data based on our legitimate interest to deliver and purchase products and services, to manage business relationships, to provide customer support and communication, to market and develop our products and services, to facilitate communication and to provide any requested information. It is Sympa’s legitimate interest also to maintain and develop our website, to organize events and competitions, and to carry our analysis, reporting and statistics for our business purposes.
Consent
We process your personal data based on your consent when you have subscribed to receiving marketing emails from us. Please note that you may unsubscribe from our newsletter and other marketing emails by using the ‘unsubscribe’ -link in such emails.
Legal obligation
Whenever there is a statutory requirement for Sympa to process your personal data the basis for processing is our legal obligation
Contract
The implementation of a contract between Sympa and supplier or other partner organization, as well as the execution of the steps prior to entering into such contract.
Transfers and Disclosures of Your Personal Data to Third Parties
We use trusted service providers and subcontractors to operate our business efficiently. These kinds of parties are e.g., IT, marketing, technology and other similar service providers hosting and maintaining our data, as well as possible providers of other professional services.
Our subcontractors and business partners are contractually obliged to process personal data only for purposes defined by Sympa. We require that all our subcontractors and business partners keep the personal data we provide them confidential and adequately secured. They are also required to comply with the applicable data protection laws, and the relevant service agreement.
In limited circumstances, Sympa may also disclose your personal data to other third parties, such as authorities or Sympa group companies, when required by law or if we have a legitimate interest to do so.
Transfers of Your Personal Data outside the EU or European Economic Area
The physical location of the personal data is within the EU/EEA area. Sympa may transfer (for example grant access) the personal data outside the EU or EEA in accordance with the applicable data protection regulation with European Union. In such cases, We ensure that your personal data is always protected with appropriate safeguards
We contractually require recipients of personal data to only use the data for the intended purpose of the transfer and to destroy or return it when it is no longer needed.
Principles for the Retention of Your Personal Data
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, however not more than for period of 4 years or as required by applicable legislation. If you have subscribed to our newsletter or other releases, we will process your personal data until you unsubscribe from our mailing list.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure of the data, the purposes for which the data were collected originally, the time limits on legal claims and the applicable legal requirements.
Rights of a Data Subject in Relation to the Processing of Personal Data
As a data subject you have the following rights:
- Right of access: You may request to obtain access to your personal data, obtain information on the processing of your personal data, and to review your personal data we process.
- Right to rectification: You may request us to rectify and/or to complete inaccurate or incomplete personal data.
- Right to erasure: You may request us to have your personal data erased.
- Right to restriction: You may request that we restrict processing of your personal data under certain circumstances.
- Right to object to processing: You may object to processing of your personal data based on your particular situation and to the extent that your personal data are being processed on the basis of Sympa’s legitimate interest.
- Right to data portability: You may receive your personal data in a machine-readable format and transmit those data to another controller (provided that you have delivered us such personal data yourself, We process such personal data based on an agreement and the processing of personal data is carried out by automated means).
You should present your request for exercising any of the aforementioned rights in the manner de-scribed in the ‘Contacts’ Section of this privacy notice. We may need to request additional information from you to help us confirm your identity and ensure your right to exercise any of your other rights. This is an appropriate security measure to ensure that personal data are not disclosed to any person who has no right to receive it.
In cases where the processing of your personal data is based on your consent, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact us via the contact details provided in the ‘Contacts’ Section of this privacy notice. Once We have received notification that you have withdrawn your consent, We will no longer process your data for that specific purpose, unless We have another legal basis for doing so. Please note that you may unsubscribe from our newsletter and other marketing emails by using the ‘unsubscribe’ -link in such emails.
You do not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request.
You also have the right to lodge a complaint with the supervisory authority concerned or with the supervisory authority of the EU member state of your habitual residence or place of work if you consider that we have not processed your personal data in accordance with applicable data protection legislation.
Contacts
All requests concerning the use of data subjects’ rights, questions about this privacy notice and other contacts should be made by e-mail to our data protection officer’s team: address dpo@sympa.com. You may also contact us through the contact function on our website, in person in our offices or in writing:
Teknobulevardi 7
01530 Vantaa, Finland
Sympa OY