1. General information
The information we collect may be divided into information provided by the user and information derived from the use of online services.
We use the information to:
To provide a secure and easy-to-use service
To provide you with a safe and secure service and to provide you with a good customer experience.
To provide product recommendations and marketing development
To provide good customer service and support for our products and services
2.The controller of the personal data processed is:
Piruetti Oy (business ID: 2328597-7)
For further information on data protection and processing of personal data, please contact: email@example.com
3. What information can be collected about me?
Information provided by the user or personally identifiable information
Identifying information, such as name
Contact information, such as address, e-mail address and telephone number
Order and payment information in accordance with accounting legislation
Data observed and derived from the use of services through analytics
Purchase history, including products ordered and their prices
Delivery information, such as the delivery method chosen and delivery address
E-commerce usage and browsing data and terminal identification data
The provision of identification, connection and payment information is mandatory when you make a purchase from Piruetti’s online shop.
The main source of this information is the user himself, but we may also receive additional information from our partners, such as a credit service provider. We will inform you of any personal data we receive from third parties in accordance with the provisions of the GDPR at the first contact with the customer or within one month of receiving the personal data at the latest.
4. What will my personal data be used for?
Personal data will be used
– To maintain the customer relationship
– For the delivery, processing and archiving of orders
To develop Piruetti’s operations and services
To improve the customer experience
For analytical and statistical purposes
To provide more personalised targeted content and marketing e.g. Newsletter
To prevent misuse
To provide better customer service
The processing of data is based on the customer relationship between the customer and Piruetti, a contract, the use of the website, the customer’s separate explicit consent or legal obligations.
5. How is my data stored and protected?
All personal data is protected against unauthorised access and against accidental or unlawful destruction, alteration, disclosure, transmission or other unlawful forms of processing.
Piruetti stores customer data in Finland. The data centres and the technical and process security of the trading systems are of a high standard.
We follow good data protection practices in the processing of personal data and in our technical solutions. The processing of personal data takes into account the requirements of the EU General Data Protection Regulation applicable from 25 May 2018.
All access to personal data is controlled in accordance with good practices.
6. Who processes my personal data?
Only Piruetti’s own employees have access to customer data and our staff are instructed to use it in a secure and ethical manner. Each of our staff only sees customer data to the extent necessary for the performance of their duties.
We use trusted contractors, which allows for the transfer of information to third parties.
The company responsible for processing the data:
Piruetti Oy (Business ID: 2328597-7)
7. How long will my data be stored?
We will keep your personal data only for the time necessary to fulfil the purposes of use described in this notice. In addition, some data may be kept longer to the extent necessary to fulfil and demonstrate compliance with legal obligations, such as accounting and consumer responsibilities.
At the customer’s request, personal data concerning him/her may be deleted or made anonymous from Piruetti’s systems.
For some data, the law imposes obligations to store the data for longer periods of time, including for the following purposes:
The Accounting Act prescribes longer retention periods for data, regardless of whether or not the data contains personal data.
The purpose of this provision is to ensure compliance with consumer protection obligations, in particular with regard to the protection of personal data.
Log data from systems are collected and stored as required by law to provide a lawful and secure online experience for our customers.
Taking adequate backups of store databases and systems to safeguard data, correct errors, and ensure security and continuity
8. What rights do I have?
As a customer, you have the right to:
Access or obtain access to personal data concerning you, including the right to obtain a copy of the personal data concerning you.
Request the rectification or erasure of personal data concerning you, including access to your personal data.
You can make a request to exercise your rights by contacting our Customer Service. The request must be sufficiently specific to enable our customer service to verify your identity. We will inform you if we are unable to comply with some aspects of your request, such as deleting any data that we are legally obliged (e.g. credit data) or entitled to keep.
If you become aware that our processing is incomplete or unlawful, you have the right to lodge a complaint with a data protection authority.
9. How can I access the information stored about me?
You can request the data stored in Piruetti’s systems for yourself by contacting us by e-mail: firstname.lastname@example.org
10. How can I influence the use of my data?
Piruetti is committed to providing its customers with opportunities to influence the processing of their data.
You have the right to decide on the marketing targeted at you and to opt in or opt out of various marketing messages. We are constantly developing our service, so functions can be added, changed or removed.
You may also terminate your account at any time and request that Piruetti delete your personal data by contacting Piruetti (email@example.com).
Note! In some cases, not all information can be deleted and legislation may require us to retain some of the information relating to the customer.
11. Will my personal data be transferred to third parties?
We may disclose some necessary information to third parties to ensure delivery and for marketing purposes.
We also use customer information with third parties for analytics and personalisation purposes. We share purchase behaviour and browsing data with partners to better provide you with products and offers that may be of interest to you in the future. Data used for analytics and personalisation purposes is anonymised or pseudonymised wherever possible. Only we are able to associate the pseudonymised data used with your name.
If necessary, we will also disclose the data to the authorities. We will also always inform the customer of any requests for information, where this is legally permissible.
We transmit data to the following third parties:
Analytical and statistical partners
Analytical, analytical and personalisation partners
Email marketing partners, if the customer has consented to newsletter, browsing history-based communications
SMS partners, where SMS messaging is allowed
To the carrier, if the delivery method chosen is delivery to a pick-up point, nearest post office or to the destination
To the payment intermediary when paying by payment card
To the credit issuer, if the customer chooses to pay by credit company invoice or instalment
To the invoicing operator, when the payment method chosen is Piruett1’s own invoice
To the product supplier when ordering direct delivery products
Customs, when buying products tax-free
to the collection agency, when invoices are due and are passed on for collection
Piruetti will ensure a high level of security and protection of data when transferring and processing data in accordance with the EU Data Protection Regulation.
12. Are cookies used on the shop’s website and what are they?
Personalisation of the user experience allows us to offer more product recommendations that are of interest to our customers.
Data used for analytics and marketing targeting is anonymised wherever possible. Otherwise, we treat data as personalised to the extent that the identifier contains customer targeting information, such as an IP address. Tags that are linked to the customer in some way are also treated as personal data. Tags used for analytics and marketing targeting have a validity period of 30s to 24 months.
We use Google Analytics for analytics related to our website usage, popular products, trends and sales, among other things. The information sent to Google is anonymised
Other technologies used for analytics and marketing targeting, such as pixel tags, help us to better understand our customers’ behaviour and tell us which products our customers are interested in and which features and services are most useful to our customers. You can opt-out of the use of tags by our analytics and marketing partners by enabling the Do Not Track function in your browser and setting your browser to reject third-party cookies.
14. Where can I contact you?