Privacy Policy

Registrar

Spinea Oy
Kytkintie 25
00770 Helsinki
spinea.fi

Person responsible for the register

Toni Välisalo, toni.valisalo (at) spinea.fi

Name of the register

Customer / Marketing Register of Spinea Oy

Legal basis and purpose of processing personal data

The legal basis for processing personal data under the EU General Data Protection Regulation is the customer relationship of the online store.

The purpose of processing personal data is to maintain the online store’s customer register as well as to manage and process orders. The data may also be used for business development and statistical purposes.

Contents of the register

The information stored in the register includes:

  • Name
  • Address
  • Phone number
  • Email
  • Order details
  • Order tracking codes
  • Comments
  • Messages sent via the contact form

Regular sources of information

The information stored in the register is obtained from the customer, for example in connection with orders or through the website’s form fields.

Cookies

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

Embedded content from other websites

Articles on this website may include embedded content (for example videos, images, articles, etc.). Opening embedded content from other websites is comparable to the visitor accessing the third-party website directly.

These websites may collect data about you, use cookies, embed third-party tracking cookies, and monitor your interaction with the embedded content, including tracking your interaction if and when you are logged in to the website as a user.

Regular disclosures of data and transfer of data outside the EU or EEA

Data will not be disclosed to third parties except as necessary for the technical administration of the online store (e.g., server or e-commerce platform management). Visitor comments may be checked through an automated spam detection service.

Principles of register protection

Due care is observed in processing the register, and data processed through information systems is appropriately protected. When register data is stored on Internet servers, the physical and digital security of the hardware is ensured appropriately. The data controller ensures that stored data, server access rights, and other information critical to the security of personal data are handled confidentially and only by employees whose job duties require it.

Right of access and right to request correction of data

Every person included in the register has the right to review the data stored about them and to request correction of any incorrect information or completion of incomplete information. If a person wishes to review the data stored about them or request rectification, the request must be submitted in writing to the data controller. If necessary, the data controller may request the person making the request to verify their identity. The data controller will respond to the customer within the time specified in the EU General Data Protection Regulation (generally within one month).

The right to have one’s data erased does not apply to personal data that we are required to retain for administrative, legal, or information security reasons.

Other rights related to the processing of personal data

A person included in the register has the right to request the deletion of personal data concerning them from the register (“right to be forgotten”). Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations.

Requests must be submitted in writing to the data controller. If necessary, the data controller may request the person making the request to verify their identity. The data controller will respond to the customer within the time specified in the EU General Data Protection Regulation (generally within one month).

For more information about data protection, please contact our customer service at spinea@spinea.fi