1. Data Controller
Maveron Oy, 3568375-3, Pajatie 8, 06150 Porvoo FINLAND
2. Contact Person for Register Matters
Lasse Laiho, lasse.laiho(at)maveron.fi
3. Purpose and Legal Basis for Processing Personal Data
We collect and process personal data for the following purposes:
- Customer Relationship Management: Ensuring order fulfillment, invoicing, and communication.
- Marketing: Communication and information sharing with customers.
- Developing Online Services: Analysing the use of our website to improve our operations.
The legal basis for processing is primarily the customer contract, the legitimate interest of the data controller (maintaining the customer relationship, direct marketing), or the data subject's consent (e.g., subscribing to a newsletter).
4. Personal Data Processed
We primarily process the following data:
- Contact Information: Name, address, email address, phone number.
- Customer Relationship Data: Order history, invoicing information, customer feedback.
- Website Usage: Data collected via cookies (see evästekäytäntö).
5. Data Disclosure and Transfer
We do not disclose data to external parties without the data subject's consent, except:
- Statutory Obligations: Requirements by authorities.
- Subcontractors: We use trusted partners (e.g., accounting, IT services) who process data on our behalf.
Data is generally not transferred outside the EU/EEA area. If transfers occur, we ensure legal protection (e.g., EU Standard Contractual Clauses).
6. Data Retention Period
We retain personal data only for as long as necessary to fulfil the purposes mentioned in section 3 or to meet statutory obligations (e.g., accounting).
7. Rights of the Data Subject
You have the right to:
- Check your personal data (right of access).
- Demand the rectification of inaccurate data.
- Demand the deletion of your data (right to be forgotten).
- Withdraw your given consent (e.g., marketing permission).
- Lodge a complaint with a supervisory authority (Data Protection Ombudsman).
8. Data Security
The data is protected by appropriate technical and organisational measures, such as firewalls, the use of passwords, and restricted access rights.