This is a combined Registry Statement and Information Document for HumanClub customers, potential customers and website users in accordance with Articles 12 and 13 of the EU General Data Protection Regulation (679/2016).

NAME AND CONTACT DETAILS OF THE REGISTRAR

HumanLab Oy (HumanClub's parent company)
Kappelitie 6 B, 02200 Espoo
+358 400 173 924
info@humanlabacademy.com

Person in charge of the register: Partner Hilkka-Maija Katajisto
Contact person for the register: Information Systems Specialist Tomi Hakala, +358 40 7652534, info@humanlabacademy.com

PURPOSE AND PURPOSE OF THE PROCESSING OF PERSONAL DATA (PURPOSE OF THE REGISTER)

Personal information stored in the Register of HumanLab Online Services is used to maintain and develop customer relationships, for marketing purposes, for statistics, and to provide and provide services. Personal data is processed within the limits permitted and required by the Personal Data Act.

Personal data is being processed on the basis of one or more of the following:

Contract:
The processing of personal data is based on the execution of a service contract.

Legitimate interest:
As regards HumanLab’s customers, the data controller has a legitimate interest in processing personal data in order to enable customer service and maintain customer relationships. As regards Workplace Nordic’s potential customers and website users, the data controller has a legitimate interest in processing personal data delivered via the website in order to handle contact requests, newsletter subscriptions and event enrollments.

Consent:
Processing may also be based on the consent of the data subject to the extent required by law. The data subject always has the right to withdraw his/her consent. Exercise of the right does not affect the lawfulness of the processing carried out prior to the withdrawal of consent.

CONTENT OF THE REGISTER

Data is collected in the register as follows:

HumanLab Academy newsletter and potential customers:
– Email address
– Phone number
– Usage data
– Other information the person may have supplied

Enrollment information to events organized by HumanLab:
– Name
– Email address
– Usage data
– Other information the person may have supplied

HumanLab Academy -Digital learning platform
-Name
-Email address
– Usage data
-Answers to questionnaires

Personality profiling with the WorkPlace Big Five Profile™ tool for the customers for whom Workplace Nordic conducts personality profiling:
– Name
– Email address
– Demographic background information: optional information such as age, gender, nationality, place of residence, job title
– Profiling: selectable answers to multiple choice questions mapping personality
– This personality profiling can also be done using a cover name. In that case no name, email or any other identifiable information is saved in the system.

REGULAR SOURCES OF INFORMATION

The registrar will only register information that you provide with your consent when using the HumanLab website and services or either face-to-face, by phone, email or other online tools.

PROTECTION OF THE REGISTER AND TRANSFER AND TRANSFER OF DATA OUTSIDE THE EU OR THE EUROPEAN ECONOMIC AREA

The information is collected in databases that are protected by firewalls, passwords and other technical means. The databases are located in locked and guarded premises and can only be accessed by certain pre-defined individuals. Confidentiality is binding on employees who process register data.

HumanLab does not disclose registry information to third parties. We have ensured that all our service providers involved in the processing of personal data (MailChimp https://mailchimp.com/legal/privacy/, Google https://policies.google.com/privacy?hl=en, Accountor Finago Oy https://finago.com/en/terms of use /, Paradigm Personality Labs, LLC https://paradigmpersonality.com/privacy-policy/, Multi-Health Systems, Inc. (MHS) https://www.mhs.com/Privacy-Policy, Digital Agency ACQUA Tmi https://acqua.fi/tietosuojaseloste/ HubSpot https://legal.hubspot.com/privacy-policy Leadpages https://www.leadpages.com/privacy SurveyHero https://www.surveyhero.com/privacy, Paytrail Oyj https://www.paytrail.com/tietosuojaselosteet and Accounting Rocks Oy) comply with data protection legislation.

We use a U.S.-based MailChimp email service for sending newsletters and for event enrollments, which means that personal data is transferred outside the European Union. Personal data is, however, protected in compliance with the Personal Data Act. We have incorporated the EU's Standard Contractual Clauses in our Data Processing Addendum with Mailchimp. MailChimp has also joined the EU-U.S. Privacy Shield Framework (https://www.privacyshield.gov/list), the purpose of which is to ensure data protection when processing EU citizens’ data in the United States. Read more about MailChimp’s privacy protection: https://mailchimp.com/legal/privacy/. Personal data on a registered user is erased upon the user’s request. The request may be emailed to info(at)workplacenordic.com, or the user can opt out of the mailing list. A link to do this is included in every newsletter.

WorkPlace Big Five Profile™ personality profiling is conducted using the My Paradigm Dashboard, which is the property of Paradigm Personality Labs, LLC. Paradigm Personality Labs is a U.S.-based company, which means that personal data is transferred outside the European Union. Personal data is, however, protected in compliance with the Personal Data Act. We have incorporated the EU's Standard Contractual Clauses in our Data Processing Addendum with Paradigm Personality Labs. Paradigm Personality Labs has also joined the EU-U.S. Privacy Shield Framework (https://www.privacyshield.gov/list), the purpose of which is to ensure data protection when processing EU citizens’ data in the United States. Read more about the privacy protection in the MyParadigm System: (http://paradigmpersonality.com/privacy-policy/). Personal data (name and email address) is erased from the MyParadigm System upon request. The request may be emailed to: info@humanlabacademy.com. This personality profiling can also be done anonymously, in which case no personal data will be stored.

EQ-i 2.0® emotional intelligence measuring is conducted using the MHS Talent Assessment Portal, which is the property of Multi-Health Systems, Inc. (MHS). MHS is a Canada-based company, which means that personal data is transferred outside the European Union. Personal data is, however, protected in compliance with the Personal Data Act, as firstly the European Commission has recognized Canada (commercial organizations) as providing an adequate level of data protection and secondly, as when the data in connection with measuring emotional intelligence is being transmitted and stored on private servers in the United States, MHS’s cloud-service provider Rackspace US, Inc. is commited to handling your personal data according to EU comission approved standard contractual clauses (SCC) and it has also joined the EU-U.S. Privacy Shield Framework (https://www.privacyshield.gov/list), the purpose of which is to ensure data protection when processing EU citizens’ data in the United States and is commited to. Read more about the MHS privacy protection: https://www.mhs.com/Privacy-Policy and https://www.mhs.com/Security-policy. Personal data (name and email address) is erased from the MHS Talent Assessment Portal upon request. The request may be emailed to: info@humanlabacademy.com. This emotional intelligence measuring can also be done anonymously, in which case no personal data will be stored.

Workplace Nordic 360° assessment uses the SurveyHero platform to collect responses, provided by enuvo GmbH. enuvo GmbH is a Swiss company, which means that personal data is transferred outside the European Union. However, the personal data is protected as required by the Personal Data Protection Act. The EU Commission has recognised the level of data protection in Switzerland as adequate and we are also contractually committed to ensuring that the processing and transfer of our users' data is in compliance with the EU General Data Protection Regulation. Read more about SurveyHero's privacy policy: (https://www.surveyhero.com/privacy). Requests to amend or delete personal data can be sent to info@humanlabacademy.com.

On July 16, 2020, Europe's highest court (the CJEU) invalidated the EU-US Privacy Shield but stated that the Standard Contractual Clauses remains a valid data export mechanism. We commit contractually to transfer and process all of our users’ data in compliance with the Standard Contractual Clauses.

If manual material is printed from a register stored in databases, the material will be kept in a locked state and the registrar will only have access to the material. When manual material is no longer needed, it will be destroyed.

DURATION OF DATA PROCESSING

Personal data will be processed for as long as is necessary to handle the customer relationship (current or potential), event marketing, personality profiling, emotional intelligence or other specified use for which the data is stored. We will enter the information in the register as we receive it from the registrant himself and it will be corrected and deleted according to what the registrant informs the registrar. You can unsubscribe from the newsletter mailing list yourself via the unsubscribe link in each newsletter we send you.

RIGHTS OF THE DATA SUBJECT

The registrant has the following rights, for which requests must be made to: info@humanlabacademy.com

Right of inspection
A person in the register has the right to inspect and obtain copies of personal data stored in the register about himself or herself. If there are any inaccuracies or omissions in the information, please send a request to HumanLab to correct or complete the information.

Right of objection
A person in the register has the right to object to the processing of personal data if he or she feels that they have been processed unlawfully.

Prohibition of direct marketing
The data subject has the right to prohibit the use of the data for direct marketing. We never sell or otherwise disclose personal information to others so that they can send direct marketing to the data subject.

Right of removal
The data subject has the right to request the deletion of his or her data if he or she does not consider the processing of the data necessary. We will process the deletion request, after which we will either delete the data or provide a valid reason why the data cannot be deleted.

You can remove yourself from the newsletter mailing list from the link that accompanies each newsletter.

The registrar is obliged to keep the accounting material in accordance with the period (10 years) specified in the Accounting Act (Chapter 2, Section 10). Therefore, the accounting material cannot be deleted before the deadline.

The data subject may appeal against the decision to the Data Protection Officer: instructions for making an appeal.

The data subject has the right to demand that we therefore limit the processing of the disputed data until the matter is resolved.

Right of appeal
A person in the register also has the right to lodge a complaint with the Data Protection Officer if he or she feels that we are in breach of the applicable data protection legislation when processing personal data.

USE OF COOKIES

A cookie is a small text file that is stored on a user’s device by an Internet browser. Cookies are set on the user’s terminal only with the site the user invites. Only the server that sent the cookie can later read and use the cookie. Cookies or other technologies do not damage the user’s terminal or files, and cannot be used to access programs or spread malware. The user cannot be identified by cookies alone.

We store the following types of essential cookies when a user visits a website:

  • Cookies to improve security
  • Cookies necessary for the operation of the website

We store the following types of cookies if the user has accepted the use of cookies (by pressing the I accept cookies button):

  • Your language choices
  • Functional cookies for better shopping experience
  • Functional cookies for better learning experience

Change your cookie-settings: