Privacy Policy

Intro

This privacy policy ("Privacy Policy") is effective as of 4 February 2021 and describes how Puroa Goods (hereinafter also referred to as "we") collects and processes personal data of:

  • the users of our website www.puroagoods.com, Facebook or Instagram pages ("Sites") and our online store users,

  • our customers in connection with their subscription of our newsletter, feedback, and other contact requests, and

  • our customers and the contact persons of our corporate customers in connection with the orders (hereinafter jointly referred to as "you").

We respect your privacy and are committed to processing your personal data in accordance with this Privacy Policy and applicable laws including the General Data Protection Regulation (2016/679; the "GDPR"). As a data controller, we carry the ultimate responsibility for the processing of your personal data.

In this Privacy Policy, we will tell you, how we collect and use your personal data and what rights you have in relation to the processing of your personal data. We kindly ask you to read this Privacy Policy carefully in order to understand how we process your personal data.

We have separate privacy policies for the employee and recruitment data.

1.     What personal data we process and where we collect it from?

We collect your personal data whenever you interact with us, when you use our Sites or online store, or place orders with us. The personal data we process is mainly collected directly from you, the data subject. The personal data we collect from you may include the following data:

  • Contact and other general information: when you visit our Sites or online store, we may collect your personal data such as your name, email address, telephone number, postal address, date of birth, Facebook or Instagram profile information, and credit card or payment method information (if applicable). If you act on behalf of a company, we may collect contact information of the company such as a company address and your position in the company.

  •  Customer feedback and other contact requests: when you interact with us by providing customer feedback, posting anything on our Sites, or requesting us to contact you by any means, we will process the information that you provide us with. If your request is made in connection with a particular transaction, we may ask you to provide information about your credit card, or other payment methods (if applicable) in order to respond to your request. When you make an inquiry on our Sites, we use that information to contact you so that we may respond to your inquiry.

  • Customer order history information: when you place orders with us, we process information related to invoicing and debt collection.

  • Information related to your marketing preferences: we process information such as data related to your preferences to be contacted by us and your possible consent or prohibition to receive newsletters or other marketing material from us.

2.     Cookies

When you visit our Sites, we may also collect personal data from you automatically using cookies or similar technologies. We may automatically collect information such as information on your device (e.g. device type, IP address, operating system) and your usage information (e.g. the time and date you visited our Sites, the parts in our Sites you visited, the content you viewed, the website that referred you to our Site) when you access our Sites. We use cookies to improve your user experience when visiting our Sites and to target relevant content to the visitors of our Sites. You can learn more about the cookies we use in our Cookie Policy.

3.     What is the purpose and legal basis for the processing of your personal data?

We process your personal data only for the purposes described in this Privacy Policy. Our such purposes, of which one or more may apply depending on the case at hand, are:

  • To provide you with the services you have requested: we process your personal data primarily to offer you the opportunity to use our services and to deliver your product order. We process your personal data to send you questionnaires to measure your satisfaction with our services. We also process your personal data for the purposes of managing the contractual relationship between us. The legal basis for processing your personal data is the fulfillment of an agreement.

  • To maintain and develop our Sites and services: we process your personal data to continuously develop our Sites and services to ensure the high-quality of your customer experience by e.g. presenting content in the most efficient and effective manner. The legal basis for processing your personal data is our legitimate interests.

  • To communicate with you regarding your requests: in the event, you make an inquiry, we will use the provided information to answer your questions or solve possible issues. The legal basis for processing your personal data is our legitimate interests.

  • For general customer communications, marketing, and development: we process your personal data for the purposes of maintaining our customer relationships as well as for marketing and advertising our products and services. We want to let you know about our new products, special offers, employment opportunities and any updates on our services by for example sending you our newsletter. The legal basis for processing your personal data is your consent.

    To be allowed to send electronic direct marketing (e.g. utilizing email or text messages), your consent of the electronic direct marketing is collected (opt-in) where required by applicable laws. Such consent request may take place in certain parts of our services. You may withdraw your consent (opt-out) at any time by contacting us.

  • To fulfill our legal obligations: we process your personal data to fulfill our reporting or other legal obligations towards authorities. The legal basis for processing your personal data is to comply with our legal obligations.

  • For potential claims handling and legal processes: we may process your personal data in relation to claims handling, debt collection, and legal processes. We may also process your personal data for the prevention of misuse of our services and for data, system, and network security. In these situations, the legal basis for processing your personal data is our legitimate interests.

When choosing to process your personal data on the basis of our legitimate interests, we weigh our own interests against your right to privacy. We also use pseudonymized or non-personally identifiable data when possible.

4.     Are your personal data disclosed or transferred to third parties?

We only share your personal data within our organization, if and as far as reasonably necessary, in accordance with this Privacy Policy. We will not disclose your personal data with third parties outside of our organization unless we are required to do so under applicable laws or to perform services requested by you.

We primarily process personal data on servers located in the EU/EEA. However, we may need to transfer your personal data outside the EU/EEA. Where this is the case, we and our third-party processors will always take the necessary steps to implement appropriate technical and organizational measures under the GDPR to ensure that your personal data remains always secure.

5.     What are the principles of data security?

We will only process your personal data for the purposes of this Privacy Policy as set out above. Processing your personal data in a secure way is important to us and we have implemented appropriate technical and organizational measures to keep your personal data secure. We maintain a report of the personal data on a separate, limited-access server, and access to such personal data is limited to only those employees for whom they are necessary to perform their work. Viewing of personal data requires an individual, protected user ID, and password. We will keep your personal data confidential and not disclose it to any other entities than those set out in this Privacy Policy unless you clearly authorize us to do so or such and authorization results from applicable laws.

6.     For how long we process your personal data?

We store your personal data only for as long as and to the extent that it is necessary for the purposes for which the personal data was collected as set out in this Privacy Policy unless a longer retention period is required or permitted by the applicable laws.

7.     What are your rights as the data subject?

You may at any time exercise your rights as a data subject in relation to your personal data that we process. Your rights include the following:

  • Right to access and rectification: You have the right to request access to your personal data we process. This includes e.g. the right to be informed whether or not we process personal data relating to you, what personal data is being processed, and the purpose for the processing. You also have the right to request inaccurate or incomplete personal data about you to be corrected.

  • Right to object: You have the right to object to certain processing of your personal data including e.g. processing of your personal data for marketing purposes or when we otherwise base our processing of your personal data on a legitimate interest of ours or a third party.

  • Right to erasure: You have the right to request your personal data be erased if, for example, the personal data is no longer necessary for the purposes for which it was collected, the processing is unlawful, or the personal data has to be erased to enable us to comply with our statutory obligations.

  • Right to data portability: If your personal data that you yourself have provided is being processed automatically with your consent or in accordance with a contract between you and us, you may request the personal data to be provided to you in a structured, commonly used and machine-readable format and the personal data to be transmitted to another controller if this is technically possible.

  • Right to withdraw your consent: In cases where the processing is based on your consent, e.g. for marketing purposes, you have the right to withdraw your consent to such processing at any time.

You may exercise any of the above-mentioned rights by contacting us by email at hello@puroagoods.com.

8.     Lodging a complaint

Our aim is always to solve disagreements relating to the processing of your personal data directly with you. However, if you wish to file a complaint with a competent data protection authority regarding our processing of your personal data, you may do so by contacting the Data Protection Ombudsman (tietosuoja@om.fi, 029 56 16670, www.tietosuoja.fi).

9.     Our contact details

Puroa Goods is the controller of your personal data for the purposes described in this Privacy Policy. If you have any questions about this Privacy Policy or concerns about how we process your personal data or would like to receive additional information, please contact us at any time by email at hello@puroagoods.com

10.  Changes to Privacy Policy

We are constantly improving our services and privacy measures, and we, therefore, reserve the right to modify this Privacy Policy by notifying about it on our website. Changes in this Privacy Policy may also be based on changes in the applicable laws. Thus, we kindly recommend you to read this Privacy Policy regularly.