Cropcorn Customer Register Registry and Privacy Statement
This is the Privacy Statement of the Cropcorn Customer Register in accordance with the EU General Data Protection Regulation, which is used to inform data subjects about the processing of personal data. Prepared on June 1st, 2022, last modified June 1st, 2020.
1. Registry Administrator
2. The name of the registry
Cropcorn’s customer and user register
3. Purpose of the processing of personal data
The legal basis for the processing of personal data under the EU General Data Protection Regulation is the consent of the individual and is intended to enable the marketing of companies, events and products on Cropcorn.app, as well as the communication and maintenance of customer relationships.
User profile likes are stored so that we can send information about the liked company events and announcements, and reminders of events the user has liked in the Cropcorn.app web app. The location of the user is saved to be able to recommend nearby businesses, events and products.
With separate consent, we will also send emails about Cropcorn.app news, as well as information about upcoming events or products.
4. Information content of the register
The information stored in the register is:
- The email address of the user accoun
- User account password
- Name of the company
- Company tax ID
- Business address
- Company phone number
- Company photo
- Company description
In addition, any photos and information from the company’s event and product listings will be stored so that the company can easily repost them without having to recreate the advertisement.
In the user profiles, information about the likes of companies and events, as well as reviews is stored. If the user account is deleted, all information is deleted.
Personal information is processed during the customer relationship until the user account is deleted. The company's name and business ID will be kept for archival purposes for 5 years after the end of the customer relationship in order to identify customer accounts.
The IP addresses of the visitors of the website and the cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to ensure data security and to collect statistics about visitors to the site in cases where they may be considered personal data.
5. Regular sources of information
The register is created from information received from customers. The information stored in the register is obtained from the customer e.g. the information stored on the Cropcorn.app page, as well as through the contact form on the Cropcorn website, email, telephone or social media services, as well as agreements, customer meetings and other situations in which the customer discloses their information.
Contact information for companies and other organizations can also be collected from public sources such as websites, directory services, and other companies.
6. Disclosures and Recipients
The information is not regularly disclosed to other parties. The information may be published to the extent necessary to provide the service.
For user accounts, Cropcorn.app displays company likes and ratings anonymously, meaning that the person who liked or rated the company is not identifiable to other users of the site.
For company profiles, the information displayed on Cropcorn.app is:
- Name of the company
- Company Address
- Company Opening Hours
- Company phone number
- Company Photos
- Description of the company, product, or event
- The name and time of the product or event reported by the company
The Company account can be deactivated if, in which case the Company account and its information will remain, but will not appear on the site.
With regard to the processing of personal data, the data controller may also transfer data outside the EU or the EEA to entities (eg cloud services) that have undertaken to comply with the general data protection regulation in ways that ensure adequate data protection for the processing of personal data.
7. Registry Security Principles
The register is handled with care and the data processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical digital security of their hardware is adequately addressed. The data controller ensures that the data stored, as well as the access rights to the servers and other data relevant to the security of personal data and critical information, are treated confidentially and only by the employees whose job description it belongs to.
8. Right of inspection and right to request rectification of information
Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check or correct the data stored about him or her, the request must be sent by e-mail to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
9. Other rights related to the processing of personal data
A person in the register has the right to request the removal of his or her personal data from the register ("right to be forgotten"). The stored information may be deleted from the Cropcorn user account settings by using the “Delete Account Permanently”. Data subjects also have other rights under the EU's general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests can be sent to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (generally within one month).
A cookie is a small text file that is stored on a user's device by an Internet browser. Cookies are set on the user's terminal only with the site the user invites. Only the server that sent the cookie can later read and use the cookie. Cookies or other technologies do not damage the user's terminal or files, and cannot be used to access programs or spread malware. The user cannot be identified by cookies alone.
Cookies are divided into subcategories: mandatory cookies, functional cookies, product development and business reporting, advertising reporting, and advertising targeting. Mandatory cookies cannot be blocked. They are related to security and enabling the site. Mandatory cookies do not contain personally identifiable information.
We reserve the right to update our cookie policies, for example, due to service developments or mandatory legislation.