Privacy statement
Privacy statement
According to the General Data Protection Regulation, the personal data controller of a register is obligated to inform the register’s data subjects in a clear manner. This statement fulfils this informing obligation.
1. Personal data controller
Company name:
Pieni Suklaatehdas Porvoo Oy
Contact information:
Teollisuustie 15
06150 Porvoo
Finland
Contact information in matters related to personal data files:
Pieni Suklaatehdas Porvoo Oy – Peter Westerlund
Teollisuustie 15
06150 Porvoo
Finland
+358 40 480 8035
pieni@suklaatehdas.com
If necessary, contact information of the data protection officer:
Data protection officer
Pieni Suklaatehdas Porvoo Oy – Peter Westerlund
Teollisuustie 15
06150 Porvoo
Finland
+358 40 480 8035
pieni@suklaatehdas.com
2. Data subjects
In the customer register are people who have bought from the online store and registered there.
3. Purpose of use of personal data
Grounds for keeping the register:
- personal data is being processed based on an existing customer relationship
Purpose for the register and the processing of personal data
Personal data is only being processed for predetermined purposes, which are:
- customer relationship management
- informing about services
4. Personal data recorded in the register
The customer register contains the following information:
Contact information
- name
- address
- phone
Customer information
- Information on products/services bought
5. The data subject’s rights
The data subject has the following rights, and requests for their use should be sent to
Right to access data
The data subject may check the data we have recorded.
Right to rectification
The data subject may request the rectification of inaccurate or incomplete personal data.
The data subject may complain of the decision to the Data Protection Supervisor
The data subject has the right to demand us to restrict the processing of controversial data until the matter is solved.
Right to object
The data subject may object to the processing of personal data if the data subject feels that personal data has been processed unlawfully.
Right to forbid direct marketing
The data subject has the right to forbid the use of personal data for direct marketing.
Right to deletion
The data subject has the right to request the deletion of data if personal data processing is not necessary. We will handle the request for deletion and proceed to either delete the data or state a justified reason for not being able to delete the data.
It should be noted that the controller may have legal or other rights to not delete the requested data. The controller is obligated to preserve accounting materials for the duration (10 years) set out in the Accounting Act (Chapter 2, Section 10). For this reason, materials related to accounting cannot be deleted before that term has expired.
Oikeus siirtää tiedot järjestelmästä toiseen
Rekisteröidyllä on oikeus saada rekisterinpitäjälle toimittamansa henkilötiedot jäsennellyssä, yleisesti käytetyssä ja koneellisesti luettavassa muodossa sekä halutessaan siirtää kyseiset tiedot toiselle rekisterinpitäjälle.
Withdrawing consent
If the processing of personal data is only based on the data subject’s consent and not for instance on a customer relationship or membership, the data subject may withdraw consent.
Right to complain
The data subject has the right to complain to the Data Protection Supervisor if the data subject feels that we are violating the effective data protection regulation when processing personal data.
Contact information of the data protection supervisor: www.tietosuoja.fi/en/index/yhteystiedot.html
6. Regular information sources
Customer information is regularly obtained from:
- the customer as the customer relationship is born
7. Regular disclosure of data
The data is not generally disclosed for marketing purposes outside Pieni Suklaatehdas Porvoo Oy.
8. Duration of processing
- Personal data is usually processed for as long as the customer relationship exists.
- The data subject may unsubscribe from our marketing list by clicking the link on each of our marketing e-mails.
9. Personal data processors
The controller and its employees process personal data.
10. Transferring data outside the EU
Personal data is not transferred outside the EU or the EEA.
11. Automatic decision-making and profiling
We are not using the data for automatic decision-making or profiling.
12. Security of payment service provider
Paytrail Oyj is our webshop’s payment service provider. Read Paytrail’s data privacy notice page.