Privacy Policy – POK Group Oy (Updated: [13.4.2026])
1. Data Controller and Contact Information
POK Group Oy [Lukkosalmentie 3] [70420 Kuopio] Phone: [+358(0)10 572 7501] Email: [etunimi.sukunimi@pok.fi]
Websites: http://www.pok.fi and https://pokkari.pok.fi
2. Purpose of the Privacy Policy
In this privacy policy, we explain how POK Group Oy (“we”) collects, processes, and protects the personal data of our customers, potential customers, and website users in accordance with the EU General Data Protection Regulation (GDPR).
3. What Data Do We Collect and for What Purpose?
We process personal data in three main contexts:
A. Website Use and Forms (www.pok.fi)
- Transport stand return form: When you request the pickup of transport stands used for product delivery, we collect your name, company, pickup address, and contact information (phone/email).
- Purpose and legal basis: Organizing the pickup and communication. The processing is based on the performance of a contract or the fulfillment of a service request.
- Website analytics: Our website uses Google Analytics to track visitor traffic. We collect anonymized IP address data, browser type information, and time spent on the pages.
- Purpose and legal basis: Improving website functionality and user experience. The processing is based on consent (cookies) and our legitimate interest in developing our services.
B. Extranet Customer Portal (pokkari.pok.fi)
- Login and order data: When a customer uses the portal, we process login information (username/email) as well as order information entered and viewed by the customer.
- Purpose and legal basis: Displaying the customer’s order history, receiving new order information, and customer service. The processing is based on the performance of a customer contract.
C. Customer Relationship Management (ERP System)
- Customer register: We create and maintain information about customer companies and their contact persons (name, contact information, role, billing details, order history) in our enterprise resource planning (ERP) system.
- Purpose and legal basis: Managing the customer relationship, delivering orders, billing, and fulfilling statutory accounting obligations. The processing is based on a contract, legitimate interest, and statutory obligations.
4. Regular Sources of Information
Personal data is primarily collected from the data subjects themselves via website forms, the use of the Extranet portal, email, or telephone conversations. In addition, customer data is saved in the ERP system in connection with sales and delivery processes.
5. Data Disclosures and Transfers Outside the EU/EEA
We do not sell or regularly disclose personal data to external parties, except when necessary to provide a service (e.g., to transport companies for the pickup of transport stands) or at the request of authorities.
In producing our services, we utilize reliable IT service providers (e.g., server space providers and the ERP system supplier) who process data on our behalf. Because we use Google Analytics, analytics data may be transferred outside the EU/EEA, such as to the United States. In such cases, the transfer is protected by EU-approved safeguards, such as standard contractual clauses or data privacy frameworks (Data Privacy Framework).
6. Data Retention Period
We retain personal data only for as long as necessary to fulfill the purposes defined in this privacy policy. For example:
- Data from the transport stand return form is retained until the pickup and related measures have been completed.
- Customer and order-related data (ERP and Extranet) is retained for the duration of the customer relationship and thereafter for the period required by the Accounting Act (typically 6 years).
7. Cookies
We use cookies on our websites. Some cookies are necessary for the functionality of the site (e.g., Extranet login), and some are related to analytics (Google Analytics). You can manage your cookie settings through your browser settings or via the cookie notice on our website. The use of analytics cookies is always based on your consent.
8. Rights of the Data Subject
You have the right to:
- Access the data we have stored about you.
- Demand the correction of inaccurate data or the completion of incomplete data.
- Request the deletion of your data (“right to be forgotten”), unless we have a statutory obligation to retain it.
- Object to or restrict the processing of your data in certain situations.
- Withdraw your consent at any time (e.g., regarding cookies).
You can exercise your rights by contacting us using the contact information mentioned in Section 1. If you feel that we process your personal data in violation of data protection legislation, you have the right to lodge a complaint with the Data Protection Ombudsman (www.tietosuoja.fi).
9. Updating the Policy
We continuously develop our services and reserve the right to amend this privacy policy. Updated versions will be published on this website.