Privacy policy

This is MuotoWorks' privacy policy statement in accordance with the EU General Data Protection Regulation (GDPR), prepared on January 26, 2024.

Registrar

Muoto Works / Ahaa Products (2645248-6)
Aurinkotuulenkatu 17 A 14
00990 Helsinki

More information about the register and data processing can be obtained from the address: info@muotoworks.fi

Registry name

MuotoWorks customer register

Purpose of personal data processing

Personal data is processed for managing, administering, and developing customer relationships, providing and delivering services, and handling complaints. It is also used in communications like news updates and marketing, including direct and electronic marketing. Customers have the right to opt out of direct marketing. The data controller processes the information directly and uses subcontractors for data processing on its behalf.

Legal basis for processing

The legal bases for processing personal data are as follows, in accordance with the EU's General Data Protection Regulation (GDPR):

  • the data subject has given his consent to the processing of his personal data for one or more specific purposes (GDPR 6 art. 1.a);
  • the processing is necessary for the implementation of an agreement to which the data subject is a party, or for the implementation of pre-contractual measures at the request of the data subject (GDPR 6 art. 1.b);
  • the processing is necessary to fulfill the legitimate interests of the controller or a third party (GDPR 6 art. 1.f).

The above-mentioned legitimate interest of the data controller is based on a meaningful and appropriate relationship between the data subject and the data controller, which is a consequence of the fact that the data subject is a customer of the data controller, and when the processing takes place for purposes that the data subject could reasonably expect at the time of the collection of personal data and in connection with the relevant relationship.

Data content of the register

The information to be recorded in the register is:

person's name, company/organization, contact information (phone number, e-mail address, address), payment information, customer consent to e-mail or telephone marketing, IP address of the network connection

Information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services.

IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to take care of information security and for the collection of statistical data of website visitors in those cases when they can be considered as personal data. If necessary, consent is requested separately for third-party cookies.

Regular sources of information

Personal data is collected from the registered person himself.

Personal data is also collected and updated within the limits of the applicable legislation from generally available sources, which are related to the implementation of the customer relationship between the data controller and the registered person and with which the data controller fulfills its obligations related to maintaining customer relationships.

Personal data retention period

The information collected in the register is kept only for as long and to the extent necessary in relation to the original or compatible purposes for which the personal information was collected.

The need to retain personal data is evaluated every five years, and in any case, the data concerning the registered person is removed from the register 10 years after the customer relationship of the registered person with the controller has ended, and the obligations and measures related to the customer relationship have been completed. For example, accounting documents are kept for five years after the end of the accounting period.

In addition, the controller takes all possible reasonable measures to ensure that personal information that is inaccurate, incorrect or outdated in relation to the purposes of the processing is deleted or corrected without delay.

Regular transfers of data and transfer of data outside the EU or EEA

Information is not regularly disclosed to other parties. Information can be published to the extent agreed with the customer.

Personal data included in the register will not be transferred outside the EU or EEA.

Principles of registry protection

Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly.

Access to databases and systems is only possible with separately issued personal user IDs and passwords. The registrar has limited access rights and authorizations to information systems and other storage platforms in such a way that the data can be viewed and processed only by the persons necessary for their legal processing. In addition, the usage events of databases and systems are registered in the log data of the controller's IT system.

The employees and other persons of the registrar are committed to observe the obligation of confidentiality and to keep secret the information they receive in connection with the processing of personal data.

The right of inspection and the right to demand correction or deletion of information

Every person in the register has the right to check their information stored in the register and to demand the correction of any incorrect information or the completion of incomplete information.

A person in the register has the right to request the removal of personal data about him/her from the register ("the right to be forgotten"). Those registered also have other rights according to the EU's General Data Protection Regulation, such as limiting the processing of personal data in certain situations.

If a person wants to check the information stored about him or to demand correction or deletion, the request must be sent in writing to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

Network analytics

The following services collect anonymized information about website visits without personal information: Google Analytics.

Gift card