Privacy statement

Privacy statement

According to the General Data Protection Regulation, the personal data controller of a register is obligated to inform the register’s data subjects in a clear manner. This statement fulfils this informing obligation.

1. Personal data controller

Company name:
Pieni Suklaatehdas Porvoo Oy

Contact information:
Teollisuustie 15
06150 Porvoo
Finland

Contact information in matters related to personal data files:

Pieni Suklaatehdas Porvoo Oy – Peter Westerlund
Teollisuustie 15
06150 Porvoo
Finland
+358 40 480 8035
pieni@suklaatehdas.com

If necessary, contact information of the data protection officer:

Data protection officer
Pieni Suklaatehdas Porvoo Oy – Peter Westerlund
Teollisuustie 15
06150 Porvoo
Finland
+358 40 480 8035
pieni@suklaatehdas.com

2. Data subjects

In the customer register are people who have bought from the online store and registered there.

3. Purpose of use of personal data

Grounds for keeping the register:

  • personal data is being processed based on an existing customer relationship

Purpose for the register and the processing of personal data

Personal data is only being processed for predetermined purposes, which are:

  • customer relationship management
  • informing about services

4. Personal data recorded in the register

The customer register contains the following information:

Contact information

  • name
  • address
  • e-mail
  • phone

Customer information

  • Information on products/services bought

5. The data subject’s rights

The data subject has the following rights, and requests for their use should be sent to

Right to access data

The data subject may check the data we have recorded.

Right to rectification

The data subject may request the rectification of inaccurate or incomplete personal data.

The data subject may complain of the decision to the Data Protection Supervisor

The data subject has the right to demand us to restrict the processing of controversial data until the matter is solved.

Right to object

The data subject may object to the processing of personal data if the data subject feels that personal data has been processed unlawfully.

Right to forbid direct marketing

The data subject has the right to forbid the use of personal data for direct marketing.

Right to deletion

The data subject has the right to request the deletion of data if personal data processing is not necessary. We will handle the request for deletion and proceed to either delete the data or state a justified reason for not being able to delete the data.

It should be noted that the controller may have legal or other rights to not delete the requested data. The controller is obligated to preserve accounting materials for the duration (10 years) set out in the Accounting Act (Chapter 2, Section 10). For this reason, materials related to accounting cannot be deleted before that term has expired.

Oikeus siirtää tiedot järjestelmästä toiseen

Rekisteröidyllä on oikeus saada rekisterinpitäjälle toimittamansa henkilötiedot jäsennellyssä, yleisesti käytetyssä ja koneellisesti luettavassa muodossa sekä halutessaan siirtää kyseiset tiedot toiselle rekisterinpitäjälle.

Withdrawing consent

If the processing of personal data is only based on the data subject’s consent and not for instance on a customer relationship or membership, the data subject may withdraw consent.

Right to complain

The data subject has the right to complain to the Data Protection Supervisor if the data subject feels that we are violating the effective data protection regulation when processing personal data.

Contact information of the data protection supervisor: www.tietosuoja.fi/en/index/yhteystiedot.html

6. Regular information sources

Customer information is regularly obtained from:

  • the customer as the customer relationship is born

7. Regular disclosure of data

The data is not generally disclosed for marketing purposes outside Pieni Suklaatehdas Porvoo Oy.

8. Duration of processing

  • Personal data is usually processed for as long as the customer relationship exists.
  • The data subject may unsubscribe from our marketing list by clicking the link on each of our marketing e-mails.

9. Personal data processors

The controller and its employees process personal data.

10. Transferring data outside the EU

Personal data is not transferred outside the EU or the EEA.

11. Automatic decision-making and profiling

We are not using the data for automatic decision-making or profiling.

12. Security of payment service provider

Paytrail Oyj is our webshop’s payment service provider. Read Paytrail’s data privacy notice page.