Open Badge Factory Oy
Kalasuolantie 11, 90220 Oulu
(hereafter ”we” or ”Open Badge Factory”)
2. Contact person for register matters
3. Name of register
CUSTOMER REGISTER FOR OPEN BADGE FACTORY SERVICE
4. What is the legal basis for and purpose of the processing of personal data?
The basis of processing personal data is Open Badge Factory’s legitimate interest on the basis of a customer relationship. Note that this privacy notice concerns the processing of personal data related to the customer’s Open Badge Factory user account (not the Open Badge Factory website) as well as open badge recipients’ personal data that the customer applies to grant the badges.
The purpose of processing personal data is:
- the delivery and development of our Open Badge Factory Service (“Service”),
- fulfilling our contractual and other promises and obligations,
- taking care of the customer relationship
5. What data do we process?
We process the following personal data regarding the customer’s user account (data subject):
- Basic information of the data subject such as *name, display *name, *password;
- Contact information of the data subject *e-mail address;
- Information of the service relationship and the contract such as details of the user profile, correspondence with the data subject and other references, cookies and data related to use of them;
Regarding the customer’s badge recipients we process the following personal data:
- Contact information of the badge recipient: *e-mail address, *name
- Information submitted by badge recipients in badge application forms created by the customer
6. From where do we receive data?
We receive personal data primarily from the data subject him/herself, as the data is entered into the Service by the data subject as well as from badge recipients who have applied for a badge by a badge application.
For the purposes described in this privacy notice, personal data may also be collected and updated from publicly available sources and based on information received from authorities or other third parties within the limits of the applicable laws and regulations. Data updating of this kind is performed manually or by automated means.
7. To whom do we disclose data and do we transfer data outside of the EU or EEA?
Only the data subject’s admin display name which the admin can define him/herself is displayed to other users in the Service.
We process information ourselves and use subcontractors that process personal data on behalf of and for us. We have outsourced the IT management to an external service provider, to whose server the data is stored. The server is protected and managed by the external service provider.
Data may be disclosed to authorities under compelling provisions. We don’t disclose information about the register to external quarters. We do not transfer personal data outside of the EU/EEA.
8. How do we protect the data and how long do we store them?
The personal data is collected into databases that are protected by firewalls, passwords and other technical measures. The databases and the backup copies of them are in locked premises and can be accessed only by certain pre-designated persons, i.e. only those of our employees, who on behalf of their work are entitled to process customer data. These persons include the Service Provider’s customer service personnel and the technical administrators of the Service. Each user has a personal username and password to the system.
The data subject may at any time add, change and remove all data from the Service as well as delete the account entirely.
We store the data as long as it is necessary for the purpose of processing the data. We estimate regularly the need for data storage taking into account the applicable legislation. In addition, we take care of such reasonable actions of which purpose is to ensure that no incompatible, outdated or inaccurate personal data is stored in the register taking into account the purpose of the processing.
9. What are your rights as a data subject?
As a data subject, you have a right to inspect the personal data concerning yourself, which is stored in the register, and a right to require rectification or erasure of the data. This may be done by accessing, modifying and/or deleting your personal data stored in the Service by logging into the Service. If you need assistance, please contact the person mentioned in Section 2 above.
As a data subject, you have the right to object processing at any time free of charge, including profiling in so far as it relates to direct marketing.
You have the right to object or to demand restriction of the processing of your data and to lodge a complaint with the supervisory authority.
On grounds relating to your particular situation you also have the right to object to other processing activities when the legal basis of the processing is a legitimate interest. In connection with your request, you shall identify the specific situation, based on which you object to the processing. We can refuse the request of objection only on legal grounds.
10. Who can you be in contact with?
All contacts and requests concerning this privacy notice shall be submitted in writing or in-person to the person mentioned in section two (2).
Badge recipients can access personal data used by badge issuers to deliver them badges at: https://openbadgefactory.com/en/personal-data-request/ and can request that badge issuers delete their personal data.
11. Changes in the Privacy Notice
Should we make amendments to this privacy protection statement, we will place the amended statement on our website, with an indication of the amendment date. If the amendments are significant, we may also inform you about this by other means, for example by sending an email or placing a bulletin on our homepage. We recommend that you review these privacy protection principles from time to time to ensure you are aware of any amendments made.