Last Updated 22.05.2018
We respect the privacy of our customers, users and employees. However, we are a business providing enterprise communications platforms, so we need to collect, store and use data relating to our customers and our customers also use our platform for storing and using their own personal data, for instance relating to their employees. So privacy is a matter of high priority to us.
Universe Company Oy
Privacy contact, Data Protection Officer: Antero Hanhirova
For what purposes is personal data collected and used and what is the legal basis for processing personal data?
We collect, store and process personal data only for predefined purposes. We also always make sure that there is at least one legal basis for processing personal data. The main purposes and the applicable legal basis for processing personal data are:
To provide our services. Personal data is collected and used for managing the entire customer relationship as well as performing our obligations and invoicing the services. The legal basis for this processing is a contract between Happeo and the customer.
Sales and marketing. We also collect and use personal data for marketing purposes, including direct marketing and contacting potential customers. We may also use personal data to target or retarget advertising in digital media platforms, such as social media and search engines. The legal basis for this processing is especially our legitimate interest. A person can however at any point prohibit direct marketing by sending email to firstname.lastname@example.org. We do not sell or rent personal data to third parties for marketing purposes.
Customer communications. We also collect and use personal data for customer communication purposes, including handling of support requests and customer feedback as well as notifying users about the service. The legal basis for this processing is fulfilling contractual obligations as well as our legitimate interest.
Analytics and business development. We also use the personal data as well as the anonymized data generated from the use of our service to develop our own digital service. The legal basis for this processing is mainly our legitimate interest.
HR and recruiting. Personal data relating to employees and job applicants are mainly collected and used for human resources management purposes, payment of salaries, fulfilling other rights and obligations relating to employment contracts, meeting legal requirements relating to employment as well as evaluating and selecting candidates for open positions. The legal basis for this processing may be fulfilling a contract between Happeo and the employee, consent (job applicants) as well as fulfilling legal obligations relating to employment.
What personal data is collected and from which sources?
The personal data we store relate mainly to the following groups of data subjects: potential and existing customers, potential and existing employees as well as various other roles within a customer organization, such as project team members and contract contact person.
The personal data we collect and use is largely provided by the person herself. Some data is also created and generated during the use of our service. For both job candidates and potential customers we also receive personal data from external or public sources, as we constantly search both new employees and also new customers. These include companies or services such as LeedFeader, Fonecta, Dista Oy, Discover.org, and contact lists generated by virtual assistants UpWork.
Regarding potential employees, we could also get information from public sources, such as LinkedIn, Monster, StackOverflow and CV boards. However, regarding job applicants and people we are interviewing we only use information provided by the applicant herself or at her consent from other sources, such as references.
We also collect website use and visitor information with Google Analytics and HubSpot for analyzing our website use, develop it further and for targeting relevant marketing content for our customers and website visitors.
When you visit the Website, you are not required to provide any personal information. However, when you contact us via the chat function in the Website, when you sign up to receive information from us, or when you sign up to receive and use the Services, you are required to provide some Personal Information about yourself, and we may collect some Navigational Information, in accordance with our Cookies Policy.
“Personal Information” refers to any information that you choose to submit to us that identifies you personally. This includes, for example, your name, email address, company name, address, phone number, and other information about you and/or your business. This can also include information about you that is publically available, information that is available about you online via sites like Facebook, LinkedIn, Twitter, and Google.
- Improve your browsing experience by personalizing the Website;
- Send you information we think may be of interest to you by email or other means;
- Link the analytics information we store to Personal Information you submit to us; and
- Contact you for marketing purposes related to our business, which we think may be of interest to you.
This refers to information about your computer, device, visits to the Website, and logins to the Services, including your IP address, geographical location, browser type, referral source, length of visits, pages viewed, and heat mapping. We use Navigation Information to operate and improve the Website and Services, and may also use it to provide you with personalised information about Happeo Due to the nature of what is being collected, it is possible that Navigation Information may include Personal Information.
The Website and Services integrate some services provided by third parties. We may share some of your information with these service providers in order for them to provide their services, including removing repetitive information from prospect lists, analyzing data, providing marketing assistance, conducting customer and/or user profiling, and providing customer service. As such, the terms and privacy policies of these service providers may apply to you as well, in particular: Google Analytics, Hubspot, Intercom, Perfect Audience, Google Optimize, Google Adwords, Google Tag Manager, Google Recaptcha, Hotjar, Buffer and Segment. Acceptance of these service provider terms is required to access the Website and Services. Further information is set out in our Cookies Policy.
Customer Testimonials & Quotes
We may publish customer testimonials and quotes on the Website, which may contain some Personal Information. Happeo obtains consent from each customer and the featured individual prior to posting their name and testimonial.
Data we collect and process relating to our customers:
- Company name
- Contact person’s name
- End user profile information as provided by the customer or the user
- Work email and work phone
- Invoicing details
- Marketing opt-in’s / opt-out’s
- Email address for marketing messages
- Contact details for support issues
- Contact details for invoicing and executing contracts
- and similar data.
Data we collect and store relating to our employees:
- Name and contact details
- Social security number
- Details required for payment of salaries and withholding taxes
- Health data and trade union membership data only for furthering the legal obligations relating to employment
Data we collect and store relating to our job applicants:
- Basic contact details
- Application and CV
- With consent data from other sources, e.g. LinkedIn, references and previous colleagues or supervisors
Data entered by the users
Our customers and people within their organizations may use the enterprise communication platform for storing and processing personal data where they are considered the data controller, in these situations we operate as their data processor based on a contract. In these situation we process personal data only on behalf of the specific customer based on their instructions and only as long as we have a valid contract. More details about this processing can be found from the privacy policies our customers maintain. As a data controller, the customer has full control (and also responsibility) on what personal data it decides to enter in the platform and under what legal basis it has the right to process it and transfer to Happeo, including acquiring necessary consents, if required. Happeo does not review the data entered by the customer to the platform. For more information about under which terms Happeo processes its customer’s personal data, refer to Happeo DPA terms and conditions.
Who processes personal data and is it transferred to anyone?
Personal data is mainly stored in electronic format and only authorized personnel within our organization have access to the data. The more sensitive the data, the less people have access to it (e.g. health data related to employees).
We may also use third party services providers for data storage (e.g. cloud storage), digital marketing, processing of payments and other processing of personal data. In these situations, we make sure we have a written contract with the services provider with minimum data processing provisions and also otherwise that the confidentiality of personal data is secured and data is otherwise processed and transferred lawfully. Some of these services providers include at the date of writing this policy Mailchimp, HubSpot, Google and Stripe.
We may also disclose or transfer personal data to fulfil legal obligations or when a legal authority requires a disclosure. We may also disclose personal data if we are a party of a business sale, such as a merger or an acquisition.
If any of our services providers or data transferees are located outside the EU, we make sure that the transfer of data fulfils all legal requirements.
Is personal data transferred outside the EU?
By default, personal data is not transferred outside the EU. However, in various situations data may be transferred outside the EU if our services provider is located there.
If personal data is transferred outside the EU, we make sure that (1) the transferee is located in a country with adequate safeguards (as decided by the EU commission from time to time), the (2) transferee is Privacy Shield certified (if a US-based company) or (3) the transfer occurs by using model clauses published by the EU commission.
How long is data stored?
We will not store personal data for a longer period than is necessary for its purpose or required by contract or law. The retention periods for personal data may vary based on its purpose and the situation. The retention periods may also be based on applicable laws (e.g. accounting, tax laws, employment contracts act). We may also update data from time to time. Regarding content that our customers enter into a platform we have provided, it is their responsibility to plan the data retention periods.
How is data stored and kept secure?
Personal data is stored and secured in accordance with general industry standards and practices. We consider and keep personal data confidential. Subcontractors that we use for processing personal data are selected also based on their data security measures. For our own systems and data storage, we use only well established services providers and robust software tools. Access to personal data is also protected with user-specific logins, passwords and user rights. Our premises are also safe and secure.
Is it mandatory to provide personal data? What happens if you don’t provide it?
We need to collect and process some amount of personal data in order to provide the service and to ensure that an authorized person concludes a contract on behalf of our customer, to deliver and provide the agreed services as well as to identify the registered users of our platform. Relating to employment we also need to process at least the minimum personal data required to fulfil employment contracts and legal obligations relating to employment.
In recruitment situations it is not mandatory to provide us information. Everything happens on a voluntary basis. However, if you don’t provide necessary information, we may not be able to process your application.
What rights does a person have relating to her personal data?
Access to data
You have the right to have confirmed if we are processing your personal data and also to know what data we have about you. In addition, you have right to some supplemental information described in the law about the processing activities. For access requests, please contact us as instructed in the next section.
Withdraw your consent
If we process personal data based on your consent, you can at anytime withdraw your consent by notifying us by sending email to email@example.com.
Right to have errors corrected
You have the right to request that we correct any inaccurate or outdated personal data we have about you.
Right to prohibit direct marketing
You have the right to request that your personal data is not processed for direct marketing purposes by sending us email to firstname.lastname@example.org.
Unsubscribe marketing communications
You may unsubscribe from receiving our marketing communications at any time by clicking on the "unsubscribe" link located on the bottom of our emails, contacting us by email at email@example.com
Right to object processing
If we process your personal data based on public interest or our legitimate interest, you have the right to object processing of your data, to the extent that there is no such significant other reason that would override your rights or the processing is not necessary for handling legal claims. Please notice that in this situation we may not be able to serve you anymore.
Right to restrict processing
In certain situations you have the right to require that we restrict processing of your personal data.
Right to data portability
If we process your personal data based on your consent or fulfilling of a contract, you have the right to require transfer of the data you have provided to us to another services provider in a commonly used electronic format.
How can a person use her rights?
You can execute and use your rights by contacting us by sending email to firstname.lastname@example.org. In such case, we ask you to provide us your name, contact details, phone number as well as something that we can use to verify your identity, such as written and signed (and scanned) request, or a copy of your personal ID, but without social security number and other such information that we don’t need. If you consider that the processing of your personal data is not lawful, you can always also make a notification to a supervisory authority (in Finland tietosuojavaltuutetun toimisto).