Laatukoru Oy marketing and customer register
Data Protection Declaration in accordance with the Data Protection Act (1050/2018) and the EU GDPR Regulation.
Business ID 0836992-9
Contact person responsible for registry matters
We are a registered business in Finland, so we comply with the EU regulation on the storage of personal data - this is summarised in the six points below:
The information we store about you is lawful, reasonable and transparent in terms of the processing. This means that you can access your data at any time.
Data is purpose-bound - for example, the information we collect about individuals is only tied to a specific purpose. We will not disclose your data to third parties unless there is a good reason to do so.
We minimise the information we store - we only store what is necessary.
We aim to keep our data accurate.
We limit the retention of data - data has a defined lifetime, after which it is either automatically or routinely deleted unless there is a legal reason to keep it.
We store intact and reliable data, for example, backed up by backups.
The register will only be used Laatukoru Oy and the customer for the maintenance of the customer relationship. Placing an order does not require registration in the customer register.
Data content of the register
Basic customer information: customer number, surname, first name, postal address, postal code, postal town, mobile phone number, e-mail address, order history and delivery tracking information. In addition, IP address information, data collected through cookies and data collected through social media channels.
Permission to send marketing communications will be recorded in the register if the customer has given their consent.
Regular sources of information
Contact information is stored when the customer registers. Other information is stored when the customer makes a purchase in the online store.
Regular data disclosures and transfers of data outside the EU or the European Economic Area
We transfer limited personal data to other parties - in practice this means the following:
We use email marketing tools. We use our email marketing tools to market our products and services.
We use a CRM tool to manage customer relationships and purchase transactions, where we store a minimum of the following: name, address, contact details and order history.
The controller's information system and files are protected by the technical security measures normally used. Access to the register requires a personal username and password, which are only granted to the controller's staff members whose position and tasks are related to the said access. The password is not known by Laatukoru. The data will be stored in accordance with the legislation in force at the time.
Right of access
The data subject has the right to check the data stored in the register concerning him/her. Any communication concerning the right of access must be made in writing, signed and addressed to the Controller at the address mentioned in point 1.
Right to request rectification or erasure of data
If there are errors in the data registered, the data subject may send a request for correction or deletion of the data to the address given in point 1.
Other rights relating to the processing of personal data
Without prejudice to the provisions on confidentiality, any person has the right to know what data relating to him or her have been recorded in the register of personal data or that no data relating to him or her are recorded in the register, provided that he or she has indicated the facts necessary for the search. At the same time, the controller shall inform the data subject of the regular sources of data in the register and of the purposes for which the data in the register are used and regularly disclosed.