Following the EU General Data Protection Regulation with regard to the processing of personal data, we take your privacy and security and your personal information very seriously, and we understand our responsibility in collecting and storing your data. We take the best possible measures to take care of all of the data that we collect, receive or store.
We also find it important to provide our customers with the opportunity to access their own data and the right to request that Mavaja erase your personal data, under certain conditions.
Data controller of Mavaja.fi customer register
For questions or concerns regarding the data registry, please contact:
We register all e-commerce customers of Mavaja and the contact persons provided by the customer, as well as potential customers who have been contacted in connection with ordering of Mavaja services.
The purpose of processing of individual’s personal data and data retention time
Personal data register serves the management of the business relations with our customers, the communication with our customers and the invoicing of orders. Additionally the data is used for statistical purposes, processing of services and deliveries of products and customers’ notifications.
Subject to customer’s acceptance, the data can be used for supplying the customer with our bulletins and newsletters, for marketing, advertising and direct marketing purposes. Upon customer’s wish, the direct marketing will be excluded from marketing operations.
Customer’s personal data are retained as long as the customer is regarded as our customer. Additionally, according to the legal regulations, we are obliged to retain the particular customer’s data. For instance the bookkeeping documents of the expired fiscal year are to be retained within further six years.
The data of potential customers are retained as long as needed for further development of future cooperation. The deprecated personal data are deleted from our customer register files.
Data content of the register
The register may include the following data:
- Customer’s name, phone number, contact information, e-mail address and physical address, closest Post pick-up point / delivery method.
- In case of business company customer: Company name, company ID, contact details, type of business.
- Position in the organization
- Information related to customer care and communication (such as possible billing methods, additional information provided by customers, purchased products and services, invoiced or billed work)
- Information about the services and products ordered by the customer and their delivery
- Marketing and promotional information of payment and invoicing
- Technical data, as well as cookies sent to the registered customer’s browser and related information
- Registrant’s inquiries, comments and other reactions to the online store
- User-submitted material (for instance photo), customer feedback, permits, consents, and prohibitions
- Technically collected information about the use of the online service, for instance IP address and country or city of location
- The registrar may collect information about the use of the services on its website using Cookies.
Rights of the registered person
The registered customer has the right to restrict our use of his/her personal data for direct marketing purposes. You restrict the direct marketing by clicking cancel at the end of our customer newsletter or marketing letter.
In accordance with the Data Protection Law, the registered customer has the right to access his/her personal data stored by us. The information can be obtained from the register upon customer’s written request. After processing the request, the information will be provided to the customer in a separately agreed manner. If you notice any inaccuracies or omissions in the information, you can ask us to correct, up-date or supplement the information by contacting firstname.lastname@example.org.
Registered customer has also the following rights:
- to receive information on our processing of personal data
- to access his/her data stored by us and in case of need to request us to correct/up-date/supplement the data accordingly
- to request the deletion of personal data (in certain circumstances)
- to withdraw consent and to object the processing of personal data
- to lodge a complaint with the Data Protection Officer when feeling that we are in breach of existing data protection law when processing personal data
- to restrict the processing of personal data (in certain circumstances)
Right of inspection
As a general rule, everyone has the right to inspect his/her personal data stored in the personal register. Request for verification should be placed by the registered person and addressed to Mavaja Data Controller. The written and signed request should be delivered by post or e-mail.
Right to request rectification and erasure of information
Everyone has the right to demand the correction or removal of inaccurate data stored in the personal register. The request should be written and signed by the registered person and addressed to and sent by post or e-mail to the controller of our register. If necessary, the controller may ask the applicant to prove his or her identity. Please note that you have the right to delete all your personal information only if we have no legal obligation to continue the processing of your personal data. The controller will respond to the customer within the time limit set by the EU Data Protection Regulation (i.e. not later than one month).
Other rights related to the processing of personal data
The registered person has the right:
- To request the electronical transfer of his/her data to another service provider.
- To withdraw his/her consent to the processing of personal data.
- To prohibit the use of his/her data for direct advertising, distance selling and other direct marketing, as well as for market and opinion research.
The a/m requests should be written and signed by the registered person and addressed to and sent by post or e-mail to the controller of our register.
The information is stored in our marketing register for the time being. The controller of Mavaja register shall retain other personal data in accordance with the legislation being in force at the time, and only for as long as it is necessary for the purposes described in this data protection statement. Due to accounting or other mandatory legislation, the data may be retained in accordance with the provisions of that law even after the termination of the customer relationship or other basis for the processing of personal data.
When visiting our Website, the Visitor may clear or block cookies and other monitoring of browser or device settings, but this may impair the user’s experience or cause dysfunctions in the use of the Website. Clearing cookies does not completely stop data collection.
Regular sources of information
Information about the registered person is regularly obtained from the data he/she personally supplied into the system, delivered by e-mail, telephone, form, content of own website, or other similar means.
Regular disclosures of data
If the customer’s personal data is disclosed to a third party, such as a subcontractor or supplier, the customer will be notified orally or in writing separately. The customer’s personal data will not be disclosed outside the EU without the customer’s separate oral or written consent.
Who will be processing your personal information:
- our company and its employees
- the company responsible for the operation of our website (Sininen Härkä Oy)
- the company responsible for passing orders to accounting program (Flashnode Oy)
- the payment intermediary who receives a payment from you (Paytrail Oyj)
- the transport company that transports the goods to you (Posti Group Oyj, Oy Matkahuolto Ab, Shipit Oy Ab)
- the accounting company that records the orders in our bookkeeping files (Taitotalous Oy)
- the accounting program provider (Netvisor / Visma Solutions Oy)
Mavaja will keep the customer’s personal data confidential and ensure that all persons handling the customer’s personal data are bound by confidentiality or are subject to applicable legal professional secrecy. Your personal information is protected by online anti-virus and anti-spyware software. It is not physically possible to access the premises of the website service provider and thus the personal data of Mavaja’s customer without a person on the service provider’s payroll being physically present in the same space. This ensures that data is not accessed by unauthorized parties. The premises are protected by electrically locked doors as well as a surveillance camera and computers are separately protected with personal passwords.
Manually handled material
The manual material is stored in a locked room on the company’s premises and destroyed once it has been processed into electronic form.
Cookies and Mavaja
Google Analytics are used for tracking, for instance of site traffic and visitor traffic. However, this data cannot be linked to anyone personally. Information from Google can also be used to target ads.
The shopping cart collects the products selected by the customer from the online store so that they can all be found in the same place at the end of the selection of products. The shopping cart also collects, for example a selection of product sizes and keeps them reserved for a while, because the stock balances are small.
If you stay on a waiting list, your e-mail address will be automatically stored in the registry. The program will automatically create a username and password for you and you will receive an e-mail from us. As soon as the product arrives our stock, the program will automatically send an e-mail to each person being on the waiting list for that product.
My account stores the information provided by the customer. My account stores purchased products.
Also the contact forms on the site collect cookies. In these connections the user’s personal information is also stored, but it is never passed on to a third party and all information is well secured in an environment protected by firewalls and strong passwords.