LamorReel Data Protection Notice
According to the EU General Data Protection Regulation (2016/679), the personal data controller of a register is obligated to inform the register’s data subjects in a clear manner. This notice is issued by Oy CDQ Solutions Ltd (Presentor) and fulfils its informing obligations in its capacity as an independent data controller for the purposes described in this notice.
1. Data controller and data processor
Oy CDQ Solutions Ltd (“Supplier” / “Presentor”) acts as a data processor on behalf of the Client for the processing of personal data carried out in connection with providing the LamorReel (“Software”). In addition, Presentor acts as an independent data controller for its own strictly limited purposes as described in Sections 3 and 4 of this notice.
Oy CDQ Solutions Ltd
Konepajankuja 1
00510 Helsinki, Finland
contact@presentor.fi
The Client company Lamor Corporation (“Client”) acts as the primary data controller in accordance with the EU General Data Protection Regulation (2016/679). The Client determines the purposes and means of processing user data in connection with the Software and is responsible for its own transparency obligations toward data subjects. Data subjects wishing to exercise rights in relation to the Client’s processing should contact the Client directly.
2. Data subjects
Users of the Software. These may include the Client’s employees, partners or agents or other persons to whom access rights to the Software have been granted.
Data subjects may also include recipients of presentation content or other materials shared via the Software, such as persons who receive access links to presentations or other content (“shared links”), regardless of whether such recipients have a registered user account in the Software.
3. Purpose of use of personal data
Personal data processed in connection with the Software is used for the following purposes:
Processing on behalf of the Client (Presentor as processor): The Client uses the data for monitoring and developing the Client’s presentation material and its use, and for managing user access rights. The legal basis and further details of this processing are determined by the Client as the primary controller.
Processing by Presentor as independent controller (narrow reserved role): Presentor uses personal data independently and solely for the following strictly defined purposes: (a) aggregate statistical analysis of Software usage for the development, improvement, and maintenance of the Software; and (b) monitoring and ensuring the technical performance, availability, and security of the Software. Personal data is not used for direct marketing under this role.
Personal data may also be used to:
- enable secure sharing of presentation content via personalised or non-personalised access links
- verify that shared content has been delivered and accessed
- analyse the use and effectiveness of shared presentation material
- improve the usability, relevance, and performance of presentation content
- ensure information security and prevent misuse of shared content
Processing is limited to information necessary for providing the service and improving presentation effectiveness.
4. Categories of personal data processed
The information in the user register includes the user’s email address, as well as information about the devices on which the application is installed, their operating systems, the version numbers of the application, the use of presentation material, and when the application has been used. The primary directly identifying personal data processed is the user’s email address which serves as a username.
In connection with shared links or other shared content, the information processed may include:
- link access timestamps
- information about whether shared material has been opened
- viewed pages or sections of presentation material
- number of visits or interactions with shared material
- approximate device and browser information
Shared links may be personalised in order to enable access control and to allow the sender to understand whether shared material has been accessed.
Legal basis for registered Software users:
Processing carried out by Presentor in its independent controller role is based on the user’s consent given during installation of the Software. Processing carried out on behalf of the Client is based on the legal basis determined by the Client as primary controller.
Legal basis for shared link recipients: Processing of data relating to recipients of shared links is based on the legitimate interest of the controller in providing secure content sharing, ensuring service functionality, and improving presentation effectiveness in a business context.
5. The data subject’s rights
The data subject has the following rights in relation to processing carried out by Presentor in its independent controller role. Requests should be sent to Oy CDQ Solutions Ltd at contact@presentor.fi. For rights relating to the Client’s processing as primary controller, data subjects should contact the Client directly.
Right to access data
The data subject may check the data that has been recorded.
Right to rectification
The data subject may request the rectification of inaccurate or incomplete personal data.
Right to object
Where processing is based on legitimate interests, the data subject may object to such processing. We will cease processing unless we can demonstrate compelling legitimate grounds that override the data subject’s interests, rights, and freedoms
Right to forbid direct marketing
The data subject has the right to forbid the use of personal data for direct marketing.
Right to deletion
The data subject has the right to request the deletion of data if personal data processing is not necessary. We will handle the request for deletion and proceed to either delete the data or state a justified reason for not being able to delete the data.
It should be noted that the controller may have legal or other rights to not delete the requested data.
Right to restriction of processing
The data subject has the right to request restriction of processing while a dispute about accuracy or lawfulness is being resolved.
Withdrawing consent
If the processing of personal data is based solely on the data subject’s consent, the data subject may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Right to complain
The data subject has the right to complain to the Data Protection Supervisor if the data subject feels that we are violating the effective data protection regulation when processing personal data.
Contact information of the data protection supervisor: www.tietosuoja.fi/en/index/yhteystiedot.html
6. Regular information sources
User data is regularly obtained from the use of the Software. Data may also be obtained when recipients access presentation materials via shared links or other authorised access methods.
7. Access to the personal data register
The Client, as the primary data controller, is provided with access to the user register through designated admin users. The Client accesses the data in its capacity as data controller for its own purposes. Access to the personal data register is only available to designated admin users on the Client side. The Client will disclose processed personal data to its personnel only to the extent strictly necessary. Persons entitled to process personal data are bound by an obligation of professional secrecy or are subject to an appropriate legal obligation of secrecy.
The terms governing the Client’s access to and use of the personal data register are set out in the Personal Data Processing Agreement between the parties.
We disclose information to the Client, who acts as an independent data controller and has committed to complying with the requirements of the data protection regulation. The transfer to the Client is governed by EU Standard Contractual Clauses (European Commission Decision of 4 June 2021). On request, the data subject has the right to obtain a copy of these clauses.
8. Duration of processing
Personal data will be retained only for as long as necessary for analytics, security, contractual obligations, and operation of the service. When a user account is deactivated, access to the account is disabled, but certain data may be retained for analytics, reporting, and service improvement purposes. When a user account is permanently deleted, personal data relating to that account is removed from the register or irreversibly anonymised, unless retention is required to fulfil legal obligations. Information related to shared links or other shared content usage is retained only for as long as necessary for analytics, security, and operation of the service.
9. Transferring data outside the EU/EEA
Personal data may be made accessible to the Client, which is located in Switzerland. Switzerland benefits from an adequacy decision by the European Commission, meaning that transfers of personal data from Finland to Switzerland provide an adequate level of protection equivalent to that within the EU/EEA. No standard contractual clauses or additional transfer safeguards are therefore required for this transfer.
Personal data is not transferred to any other recipients outside the EU/EEA.
10. Automated decision-making and profiling
User data is not used for automatic decision-making or profiling.