Privacy Policy for Uponor Corporation’s Corporate Announcement Subscription Service Register

Controller
Uponor Corporation
Äyritie 20
FI-01511 Vantaa
Finland

Telephone: +358 (0)20 129 211

Contact person
Tiina Koivisto
Äyritie 20
FI-01511 Vantaa
Finland

Telephone: +358 (0)20 1292 854
E-mail: tiina.koivisto@uponor.com

Name of personal data register
Uponor Corporation’s Corporate Announcement Subscription Service Register

Group of data subjects
Persons registered as subscribers of Uponor Corporation’s Corporate Announcement Subscription Service.

Purpose and legal basis of processing personal data
The purpose of this personal data register is to send Uponor Corporation’s Corporate Announcements to data subjects who have subscribed it.

The processing of personal data for the abovementioned purpose is based on data subject’s subscription to receive Uponor Corporation’s Corporate Announcements. Data subject’s subscription provides Uponor with a legitimate interest to process such personal data.

Personal data may be retained as long as necessary for the purpose for which it was collected. The data subject may cancel the registration and remove his/her personal data from the register at any time by informing of it on internet at https://investors.uponor.com/news-downloads/subscription-services or by contacting the register’s contact person mentioned above.

Content of the personal data register
In the personal data register, Uponor may process especially the name and email address of the data subjects.

Regular sources of information
The data is primarily collected from each data subject him/herself. Uponor informs each data subject of the data processing in accordance with applicable legislation.

The data is entered into the personal data register directly by the data subject or by Uponor Group’s personnel upon request of the data subject.

Disclosure and transfer of personal data outside the EU/EEA area
Uponor may disclose personal data to authorised third parties to the extent they participate in the processing of personal data for the purposes stated in this data register and in accordance with and subject to the limitations imposed by applicable legislation. Uponor does not transfer personal data outside EU/EEA. For technical reasons and for reasons related to the use of data, the personal data may be stored on servers of external service providers who may process the data on behalf of Uponor.

Rights of data subjects
Unless any limitations apply, each data subject has the right to access all personal data Uponor have on him/her. Each data subject also has the right to request that Uponor corrects, erases or stops using any erroneous, unnecessary, incomplete or obsolete personal data. Each data subject may also withdraw any consent previously provided by him/her, and object to all direct marketing.

Any requests should be sent to the contact person mentioned in Section 2 above. Uponor processes all requests as soon as possible. If dissatisfied with the decision or actions of Uponor, each data subject has the right to lodge a complaint with his/her country's data protection authority.

Principles of securing personal data – technical and organisational controls
Uponor shall ensure that sufficient technical and organisational personal data protection measures are implemented and maintained throughout its own organisation. Further, Uponor shall ensure that any transfer or disclosure of personal data described in this data register to any third party is subject to Uponor having ensured an adequate level of data protection by agreements or by other means required by law.

Technical controls:
Physical material is stored in locked spaces with restricted access. Any IT systems are secured by means of the operating system’s protection software. Access to the systems requires entering a username and a password and data transfers happen via high encryption channels.

Organisational controls:
Within the organisation of the controller and its affiliates, the use of the personal data is instructed, and access to IT systems including personal data is limited to such persons who are entitled to access them on the basis of their work assignments or role and who are subject to confidentiality obligations regarding the personal data.

Back