Our Privacy policy | Norelco oy

Norelco Oy

Privacy policy

Privacy notice

Customer and Business Partner Register and General Use of the Website.

This Privacy Notice applies to the customer and business partner register of Norelco Oy and to the processing of personal data related to the general use of Norelco Oy’s website.

The processing of personal data related to recruitment is governed by a separate Privacy Notice for the recruitment system (Laura). The use of cookies and similar technologies is described in a separate Cookie Policy.

 

1. Data Controller

Norelco Oy
PO Box 28
FI-57201 Savonlinna
Finland

2. Contact Person for Data Protection Matters

Olli Malinen
PO Box 28
FI-57201 Savonlinna
Finland

Email: olli.malinen@norelco.fi
Telephone: +358 50 525 5009

 

3. Categories of Personal Data Processed

The register may contain, for example, the following information:

- Basic information (name, job title, company, Business ID, contact person, Norelco Oy contact person)
- Contact details (email address, telephone number, postal address)
- Customer and business partner relationship information (contract details, quotation information, project descriptions)
- Communication-related information (emails, enquiries, feedback, survey responses, newsletter subscriptions)
- Technical website information (IP address, browser and device information, and other technical log data)
- Personal data is always processed only to the extent necessary for the purposes described in this Privacy Notice.

 

4. Purposes of Processing Personal Data

Personal data is processed for the following purposes:

- Establishing, maintaining and developing customer and business partner relationships
- Communication regarding customer and business partner matters
- Customer and stakeholder communications, including information about products, services and events
- Collecting customer feedback and conducting surveys
- Developing sales and business operations
- Ensuring business continuity in exceptional situations or crisis circumstances
- Ensuring information security


5. Legal Basis for Processing

Depending on the purpose of processing, personal data is processed based on the following legal grounds:

Legitimate Interests

Primarily, processing is based on the data controller’s legitimate interests (maintenance of customer relationships, communication, business development, stakeholder communications, and ensuring business continuity and information security) in accordance with Article 6(1)(f) of the General Data Protection Regulation (GDPR).

The legitimate interest arises from a relevant and appropriate relationship between Norelco Oy and its customers or business partners, where the processing of personal data is necessary for communication, the management of contractual relationships, business development and related communications.

Performance of a Contract

Processing may also be necessary for the performance of a contract or for taking steps prior to entering into a contract, such as customer and business partner relationships, requests for quotations and project implementation.

Consent

In certain cases, processing is based on the data subject’s consent, for example for specific communications from which the recipient may opt out.

 

6. Provision of Personal Data and Consequences of Not Providing Data

The personal data provided by the data subject is generally required for establishing, managing and maintaining customer and business partner relationships.

If personal data is not provided, Norelco Oy may be unable to:

- Enter into a customer, business partner or other contractual relationship
- Respond to enquiries
- Fulfil obligations related to customer or business partner relationships appropriately


7. Sources of Personal Data

Personal data is collected primarily from:

- The data subjects themselves
- Information generated during customer and business partner relationships
- Public sources relating to the organisation represented by the data subject


8. Recipients and Processors of Personal Data

Personal data is processed by employees of Norelco Oy who require access to the data as part of their duties (for example, sales personnel, customer service staff and business management).

Personal data is processed within systems and services used by Norelco Oy for purposes such as customer relationship management, communications, document management, enterprise resource planning and reporting. These may include ERP systems, CRM systems and communication and collaboration platforms. Norelco Oy primarily uses its own ERP system, the servers of which are located on the company’s premises.

In addition, limited cloud-based services may be used to support customer and business partner relationship management (for example, communications, document management and backup services). Such service providers act as processors on behalf of Norelco Oy, and data processing agreements compliant with applicable data protection legislation have been concluded with them.

Norelco Oy maintains a separate systems appendix that provides more detailed information about the systems, service providers and data locations used for personal data processing.

Service providers may also engage sub-processors. Information regarding sub-processors is described in Norelco Oy’s systems appendix.

 

9. Transfers of Personal Data Outside the EU/EEA

Personal data is primarily processed within the European Union (EU) or the European Economic Area (EEA).

However, in connection with certain services used by Norelco Oy, personal data may be processed or transferred outside the EU/EEA. In such cases, Norelco Oy ensures that appropriate safeguards are in place in accordance with applicable data protection legislation, including the use of Standard Contractual Clauses approved by the European Commission or other legally recognised transfer mechanisms.

 

10. Retention Periods

Personal data is retained only for as long as necessary to fulfil the purposes described in this Privacy Notice.

As a general rule, personal data is retained for the duration of the customer or business partner relationship and thereafter only for as long as:

- Retention is justified for legitimate business purposes
- Necessary for potential legal claims
- Required to fulfil contractual obligations
- Necessary to ensure information security
- Required by applicable legislation


11. Data Subjects’ Rights

The data subject has the right to:

- Access their personal data
- Request the rectification of inaccurate or incomplete personal data
- Request the erasure of personal data where there is no lawful basis for processing
- Object to processing based on legitimate interests
- Request restriction of processing in certain circumstances
- Withdraw consent where processing is based on consent
- Receive personal data concerning them in a structured, commonly used and machine-readable format and transmit that data to another controller, where processing is based on consent or a contract and carried out by automated means


12. Exercising Data Subject Rights

A data subject may exercise their rights by contacting the data controller by email at olli.malinen@norelco.fi or in writing using the contact details provided in Section 2 of this Privacy Notice.

The data controller may request additional information where necessary to verify the identity of the data subject. Identity verification will be carried out on a risk-based basis and only to the extent necessary for processing the request.

 

13. Right to Lodge a Complaint

The data subject has the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data violates applicable data protection legislation.

 

14. Profiling and Automated Decision-Making

Personal data is not used for automated decision-making or profiling within the meaning of the GDPR.

 

15. General Use of the Website

In connection with the general use of Norelco Oy’s website, a limited amount of personal data may be processed. The purposes of such processing include:

- Ensuring the technical functionality of the website
- Maintaining information security and preventing misuse
- Handling website-related enquiries
- The information processed may include, for example, IP addresses, browser and device information, other technical log data, and information provided when contacting Norelco Oy through the website.

The website is built on the WordPress publishing platform and is hosted on servers located within the EU/EEA. Personal data is processed in accordance with applicable data protection legislation and appropriate technical and organisational security measures.

Further information on the use of cookies and other similar technologies, as well as the choices available to users, is provided in Norelco Oy’s separate Cookie Policy.

Updated 7.7.2026.