Data protection

Privacy statement
Paints and Friends' Privacy Statement contains information on how we process and store personal data. The data protection statement was last updated on April 28, 2020.

Registrar
Paints and Friends
Social security number: 2973680-4
Address: Torkelinkatu 1, 00500 Helsinki

Contact person for the register
Name: Iisa Mönttinen
Tel: 050 542 3311
Email: paintsandfriends@gmail.com

Purpose of the register
We collect personal data for managing and maintaining the customer relationship. The basis for the processing of personal data is a legitimate interest and statutory obligations. We also collect personal data for marketing purposes, and the legal basis for processing personal data is consent. We do not profile users or make automatic decisions.

Collection of personal data
The information stored in the register is: the person's name, contact information (phone number, e-mail address, address), IP address of the network connection, information about ordered services and products, billing information, other information related to the customer relationship and ordered services.

Regular sources of information
The information to be saved in the register is obtained from the customer, e.g. From messages sent via web forms, by e-mail, by phone, through social media services, orders and other situations where the customer gives out their information.

The recipients of your personal data

- yourself
- our company and its employees
- the company responsible for the operation of our website: our website is built on the Shopify online store platform. Read more about how Shopify handles personal data: https://www.shopify.com/legal/privacy
- the payment intermediary that receives the payment from you. Our payment intermediary is Checkout Finland: https://www.checkout.fi/tietosuoja
- the transport company that transports the goods to you

We store your personal data
– in the email archive for seven years
- in the accounting material for seven years

Principles of registry protection

Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.

The right of inspection and the right to demand correction of information
Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

Please note that you only have the "right to be forgotten" if we have no legal obligations to continue processing your personal data.