EU Data Protection Regulation (GDPR) Privacy Statement
Date of preparation 10 May 2018
Saurum Oy (hereinafter referred to as ”Saurum”)
Business ID: 0298672-3
PERSON IN CHARGE OF FILING SYSTEM
Phone: +358 40 3040 212
NAME OF FILING SYSTEM
The customer register of the Lumoava online shop of Saurum Oy
PURPOSE OF FILING SYSTEM
The filing system is used for the purpose of managing customer relations, contacting customers, and marketing. The data in the filing system are used for Saurum’s own direct marketing unless the customer has explicitly prohibited direct marketing. The data in the customer register are used for planning the company’s product range, targeting and developing its products, and for statistical purposes.
Saurum may use its partners for maintaining client and service relationships. Some of the register data may be transferred to the partner’s servers due to technical requirements.
Personal data shall be processed within the limits allowed and required by the Data Protection Act.
CONTENTS OF FILING SYSTEM
The personal data filing system includes the following data:
The person’s first and last name
Information about processed orders
Delivery tracking data from Posti Finland
Information about marketing permissions and prohibitions
SOURCES OF DATA FOR THE FILING SYSTEM
Data personally provided by the customer and the orders placed by customers in the online shop.
DISCLOSURE OF DATA
Saurum may disclose the data in the customer register to communities that have entered into a partnership agreement with Saurum for the purpose of the delivery of orders by customers. Saurum’s partners do not use the data for any other purposes or transfer the data to third parties. Saurum may disclose customer data to the authorities within the limits allowed and required under valid legislation.
The data shall not be transferred outside the European Union or European Economic Area.
THE PRINCIPLES OF SECURING THE FILING SYSTEM
Saurum Oy’s personnel is bound by confidentiality obligations in relation to all customer register data. Only specially appointed Saurum Oy employees or other agents authorised to operate for Saurum Oy in connection with the data filing system may process the manually stored customer data.
Due to the technical implementation of data processing, some of the data may be physically located on the servers or equipment of third-party subcontractors, in which case a technical access is used to process the data.
Protection of the filing system and storage of data
Saurum Oy takes generally accepted measures to ensure the data security of the filing system and uses appropriate technical solutions to prevent the access of unauthorised persons to its data systems. Customer data can only be accessed with a user ID and password. Only specially appointed Saurum Oy employees and employees of companies authorised by Saurum for this specific purpose may use the data filing system application. Each person processing the register have user authorisation granted by Saurum Oy.
RIGHT OF ACCESS, RECTIFICATION, AND OBJECTION
The customer has the right to verify which of their personal data have been stored in the register. The request for verification must be in writing and signed by the customer and sent to:
PO Box 1512 (Hopeakatu 3)
Saurum shall respond to the requests in writing.
If there are errors in the customer’s data, he or she has the right to obtain from the controller the rectification of inaccurate personal data.
The customer has the right to object to the processing of his or her personal data for direct marketing purposes by contacting the customer services of Saurum Oy’s Lumoava online shop by telephone at +358 40 3040 226, in a letter sent to the person in charge of the filing system, or by email at lumoavashop(a)lumoava.fi.