Thank you for your interest in our online shop. The protection of your privacy is very important to us. We as a data controller, are committed to protecting the privacy of our customers and the persons visiting our websites and we comply with and act in accordance with the applicable data protection legislation, including amongst other the General Data Protection Regulation (EU 2016/679 “GDPR”), every time we process personal data. In the following we inform you in detail about the processing of your personal data.
Nordic By Nature Oy (“Nordic By Nature” or “we”)
Lönnrotinkatu 5
00120 Helsinki
Finland
+358504096906
gdpr@aavalabs.com
We process your personal data in connection with your purchases from our store, when you contact us (e.g. via contact form or e-mail), when you subscribe to our newsletter, or when you open a customer account. Mandatory fields are marked as such, because in these cases we need the data to process your order or to open a customer account or otherwise process your request.
The legal basis with respect to the processing of personal data for the above mentioned purposes is the performance of a contract to which the customer is a party or in order to take steps at the request of the customer to enter into a contract (as stipulated in the GDPR Article 6(1)(b)). In relation to newsletters and other marketing activities, the legal basis for processing personal data is our legitimate interest (as stipulated in the GDPR article 6.1(f)) to develop our existing customer relationships as well as to acquire new customers. In case you have provided your personal data via our website in order to receive our newsletters and we do not rely on any other legal basis to process the personal data, the legal basis for processing is consent (as stipulated in the GDPR article 6.1(a)) and you may withdraw your consent any time. For further information about your rights, please see below the Section 6.
When you purchase something from our store, subscribe to a newsletter, open a customer account, send us a contact form, send us an email atteam@aavalabs.com, subscribe to a product page or fill out a feedback survey, we process the personal information you give us such as your name, address and email address.
We will store the personal data for no longer than what is reasonably necessary for the purposes for which the personal data is processed. We will remove the personal data that we have collected when the personal data is no longer needed for the purposes described above in this Privacy Policy. Some of the personal data that we collect, and process may be subject to minimum retention periods set by for instance accounting and tax legislation.
We collect personal data mostly directly from our customers. In addition, personal data may be collected from publicly available sources.
As a general principle, we will not disclose personal data to third parties, unless required by the applicable legislation, authorities, or the performance of the customer relationship. However, we may use external data processors or subprocessors, in which case personal data will be disclosed to such third parties. In case we appoint an external data processor or subprocessor, we will enter into a data protection agreement with the data processor in order to secure safe and adequate data processing.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
In general, we will not transfer personal data outside the EU/EEA region. If the transfer of personal data outside the EU/EEA region is necessary, such transfer will be performed subject to appropriate safeguards required by applicable data protection laws such as EU Commission’s Standard Contractual Clauses.
According to the General Data Protection Regulation (2016/679), you have the following rights regarding your personal data:
You have the right to lodge a complaint with a supervisory authority, if you consider that your rights based on the GDPR, or national data protection legislation have been infringed. You have the right to lodge a complaint with a supervisory authority of your habitual residence. In Finland, the supervisory authority is the Finnish Office of the Data Protection Ombudsman (www.tietosuoja.fi/en).
If you have any questions regarding the collection, processing or use of your personal data, or if you would like to access, correct, amend or delete any personal data we have about you, please contact directly our Privacy Compliance Officers at gdpr@aavalabs.com.
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
When you visit our website aavalabs.com, you may manage your cookie preferences on our website under the button “Preferences”. If cookies are not accepted, the functionality of our website may be restricted. You can change your preferences via a button called “COOKIE PREFERENCES” at the bottom of this Privacy Policy.
Each time a website is accessed, the web server only automatically saves a so-called server log file, which contains the name of the requested file, your IP address, date and time of access, transferred data volume and the requesting provider (access data) and documents the access.
This access data is evaluated exclusively for the purpose of ensuring trouble-free operation of the site and improving our services. All access data will be deleted at the latest seven days after the end of your page visit.
In order to make visiting our website attractive and to enable the use of certain functions, to display suitable products or for market research, we use so-called cookies on various pages. Cookies are small text files that are automatically stored on your terminal device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognize your browser the next time you visit (persistent cookies).
Here is a list of cookies that we use. We have listed them here so that you can choose if you want to opt-out of cookies or not.
Strictly Required Cookies: These cookies are required for the website to run and cannot be switched off.
Reporting And Analytics: These cookies are to measure the traffic and its sources by collecting information in data sets, and learning about the most popular products and activities on the store.
Marketing And Retargeting: These cookies are used for behavioral targeting and advertising. They are served by third-party companies and track a user across websites.
Functional cookies: These cookies enable the possibility to offer additional functions and settings. They can be set by our store or third-party providers.
For web page analysis we use Google Analytics, a web analysis service of Google LLC (www.google.de). Google Analytics uses methods that enable the analysis of your use of the website, such as cookies. The automatically collected information about your use of this website is generally transmitted to a Google server in the USA and stored there. By activating IP anonymisation on this website, the IP address is shortened before transmission within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. The anonymous IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. The data collected in this context will be deleted after the purpose and end of the use of Google Analytics by us.
We reserve the right to update this Privacy Policy at any time in order to reflect the changing level of requirements and the changing practices of Nordic By Nature. Unless otherwise provided in mandatory applicable legislation, changes and clarifications will take effect immediately upon their posting on the website and we may not directly inform any individual of such changes and clarifications. Therefore, we kindly ask you to review this Privacy Policy from time to time for possible updates.
-----
In order to change your cookie preferences, please click the button below.