1. Data Controller
Phone: +358 (0) 40 550 4645
2. Group of data subject
Persons signed-up for the M.GUMMERUS’ mailing list and customers of M.GUMMERUS’ physical stores and webshop.
3. The purpose of processing personal data
Data protection law in European Union requires a lawful basis for collecting and retaining personal data from citizens or residents of the European Economic Area. These lawful bases include:
- Performing a contract between M.GUMMERUS and customer
- Legal compliance with laws and regulations
- Legitimate interests ie for running a business, in a way that does not materially impact our customer’s right, freedom or interest.
Personal data stored at M.GUMMERUS is used for managing the relationships with customers. The collected data may be used for digital marketing purposes and possible future customer satisfaction surveys pursuant to applicable laws.
4. Information Collected
The following data may be processed by M.GUMMERUS:
a) customer name, date of birth, gender, e-mail address(es), telephone number(s) and mailing address(es).
b) information related to the customer relationship, such as date of becoming a M.GUMMERUS web shop customer or mailing list subscriber, as well as direct marketing permissions and prohibitions
c) information related to purchases and other communication, services and campaigns directed at and offered to the customer, other communication, and measures related to the customer relationship as well as purchases made in M.GUMMERUS stores (ie. dates of the purchases and products purchased, number and price of the products purchased and the total sum of purchases).
5. Regular sources of information
Most of the basic information is collected from the data subjects themselves at the beginning of and during the customer relationship. Any possible updates done to information is done by the request of the data subject themselves.
Additional data (ie.purchase history) may be added to the register later by M.GUMMERUS’ customer register administrator.
6. Protection of data during transfer
M.GUMMERUS may disclose personal data within the limitations imposed by effective legislation as follows:
a) on the basis of a data subject’s consent
b) to authorized third parties to the extent they participate in the fulfilling of the agreement between M.GUMMERUS and the customer. M.GUMMERUS obliges third parties to keep confidential all personal data disclosed to them and to secure such personal data in an adequate manner
c) on the basis of mandatory legislation.
Disclosures and transfers outside of the European Economic Area:
a) M.GUMMERUS may transfer personal data outside of the European Economic Area
b) for the purpose of fulfilling its obligations, M.GUMMERUS may transfer customer personal data to internal or external recipients who may be in countries offering different levels of personal data protection
For technical and practical reasons relating to usage, data may be stored on servers of third-party service providers used by M.GUMMERUS, or such third-party service providers may process data on behalf of M.GUMMERUS.
7. Rights of the data subjects
Data subjects are, within the limitations imposed by applicable law, entitled to
a) check what data M.GUMMERUS has collected of him/her
b) require that any incorrect, useless, incomplete or outdated information be corrected or removed
c) prohibit M.GUMMERUS from processing his/her personal data for the purposes of direct marketing, market research and opinion polls
d) request a downloadable copy of his/her personal data
e) request deletion of customer account – M.GUMMERUS may retain certain information as required by law or as necessary for legitimate business purposes
Data subjects may use their above rights by contacting M.GUMMERUS at the addresses stated at the beginning of this policy.
Tangible material (paper registration forms) is disposed of after the data has been saved into the register. Before the disposal, the material will be saved in a locked space. Use of the data within the Data Controller’s organisation has been instructed, and access to the personal data file is restricted so that access to the information stored in the system and the right to use that information is only vested in those employees of the Data Controller who have such right on the basis of their work assignments. The data processing system is protected by data protection software for the operating system. Access to the system requires that each user of the register enters a user ID and password.
M.GUMMERUS will retain customer information as long as customer account is active, as necessary to provide the customer with the services or otherwise set forth in this Policy. M.GUMMERUS will also retain and use this information as necessary for the purposes set out in this Policy and to the extent necessary to comply with our legal obligations, resolve disputes, enforce our agreements and protect M.GUMMERUS’ rights.
There are four main types of cookies in use:
a) site functionality cookies that allow the customer to navigate the site and use its features
b) site analytics cookies which allow measuring and analyzing how customers use the site, to improve both its functionality and customer shopping experience
c) customer preference cookies which remember customer preferences and make the experience of using the site personal and seamless as possible
d) targeting or advertising cookies which deliver relevant ads to the consumer, limit the number of times an ad is shown to the consumer and helps M.GUMMERUS to measure the effectiveness of marketing campaigns.
By using M.GUMMERUS site customer agrees that these types of cookies are placed on their device and these are accessed in the future while visiting the site. The customer can delete the cookies. However, deleting or disabling cookies may affect the user experience and customer may not be able to take advantage of certain functions of the site.
10. Links to other websites and services
11. Data Protection Authority
Subject to applicable law, if customer is a citizen or resident of the European Economic Area, he/she also has the right to
a) object to M.GUMMERUS’ use of his/her personal information, and
b) lodge a complaint with his/her local data protection authority or the European Union Information Commissioner’s Office.