WE SHIP TO ALL EU COUNTRIES

Privacy

This is Bolumo's registration and data protection statement in accordance with the EU General Data Protection Regulation (GDPR). Prepared by 31.10.2021 . Latest Change 31.10.2021

1. Registrar

Bolumo

Päitsitie 5

00750 Helsinki

0505387350

info@bolumo.fi

Legal basis and purpose of personal data processing

According to the EU's General Data Protection Regulation, the legal basis for processing personal data is

- consent of the person (documented, voluntary, individualized, informed and unambiguous)

- an agreement to which the data subject is a party

- law (which)

- performing a public task (based on), or

- the controller's legitimate interest (e.g. customer relationship before the contract, employment relationship, membership).

The purpose of processing personal data is to communicate with customers, maintain customer relations, marketing, etc.

The information is not used for automated decision-making or profiling.

What information we collect

The information to be recorded in the register is:

  • The name of the person
  • contact information
  • the IP address of the network connection
  • information about ordered services and their changes
  • billing information
  • other information related to the customer relationship and ordered services.

In addition, we use the Google Analytics service, which stores information about our website's visitor data. This information is used to develop the website and target relevant marketing.

IP addresses of website visitors and cookies necessary for the functions of the service are processed on the basis of a legitimate interest, e.g. to take care of information security and for the collection of statistical data of website visitors in those cases when they can be considered as personal data. If necessary, consent is requested separately for third-party cookies.

Who collects data

Only Bolumo's personnel have access to the online store's customer data, who are committed to using it only in the manner required for the implementation of the service, in accordance with the requirements set by the EU data protection regulation.

How long the data is kept

We keep personal data for at least as long as it is necessary to implement the customer's service or until the customer himself requests to delete the personal data he has provided. We can also keep data for longer despite the customer's request, if legislation or unpaid debts oblige us to do so.

Regular sources of information

The information to be saved in the register is obtained from the customer, e.g. From messages sent via web forms, by e-mail, by phone, via social media services, contracts, customer meetings and other situations where the customer gives out their information.

Regular transfers of data and transfer of data outside the EU or EEA

Information is not regularly disclosed to other parties. Information can be published to the extent agreed with the customer.

Data can also be transferred by the controller outside the EU or EEA. Data will not be transferred to the United States without the express consent of the data subjects.

Principles of registry protection

Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.

The right of inspection and the right to demand correction of information

Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

Other rights related to the processing of personal data

A person in the register has the right to request the removal of personal data about him from the register. Those registered also have other rights according to the EU's General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

The contact person responsible for the register

Mari Ruohonen

Päitsitie 5

00750 Helsinki

0505387350

info@bolumo.fi

Gift card