Privacy Policy

Valid from 10.8.2020


Protecting your privacy is very important for Lifestyle Atelier Oy (Malla). Lifestyle Atelier Oy is committed to processing personal information in accordance with applicable data protection legislation in Finland, any guidance provided by supervisory authorities and good data protecting practice. Along with Lifestyle Atelier Oy, personal information can be collected and processed also by joint controllers.

This Privacy Policy explains how we collect, use and share information and how you can exercise your privacy rights. Furthermore, this Privacy Policy explains how we use cookies on our website www.mallashop.com


1. Data Controller

Lifestyle Atelier Oy (Business-ID: 3120148-9)

Address: Laippatie 5, 00880 Helsinki, Finland

Phone: +358 443 587 119

Email: info@mallashop.com


2. Contact Person

Katri Korpinen, Lifestyle Atelier Oy / Malla

Laippatie 5, 00880 Helsinki, Finland

info@mallashop.com


3. Name of the register

Malla web store customer register.


4. The purpose for processing the personal data

We use the information we collect for the following purposes:

  • To manage, take care and maintain customer relationships and to inform customers
  • Delivering ordered products and to produce and execute services to customers
  • Analyzing and compiling aggregate statistics of our Websites
  • Bookkeeping and other similar statutory legal provisions
  • For direct marketing, sales promotions, distance selling, market research, marketing communications and for other addressed deliveries.
  • To invoice services and to charge and collect payments.

The legal basis for the processing of personal data is an agreement, consent, or legitimate interest.

The requirements set by the EU Data Protection Regulation, which will apply from 25 May 2018, have been considered in the processing of personal data.


5. Content of the register

We only collect and process information about our customers that are necessary to fulfill the purposes described in this Privacy Policy. The data to be collected can be divided into three groups. These include information provided by the user, i.e. the customer himself, information collected from the use of the website, and information derived from analytics.

The register may contain the following personal data:


Person’s name, email address, mobile and/or other phone number, postal address, gender, date of birth, language, username, and password as well as optional delivery addresses of the Customer, other information provided by the customer, and direct marketing permissions. In case of non-private customers, the register includes the name of the organization, VAT or business ID number of the organization and the address information for the organization.

In addition, we collect the order information provided by the customer in connection with the order, such as the product content of the order, the method of payment and the method of delivery. The Company does not collect bank or credit card information of customer.


6. Regular sources of information

Data is collected based on notifications received from the Customer and on the basis of purchase and customer communication data in the Lifestyle Atelier Oy Data System.


7. Disclosure of data or transfer of data outside of the European Union or the European Economic Area 

The personal data contained in the Customer Registers is not disclosed outside Lifestyle Atelier Oy, unless so required by applicable laws or to such subcontractors who participate e.g. in organizing direct or other marketing, administration of information systems of the Company or in the processing of purchase orders, such as mailing of products or payment processes.

If our operations so require, we may transfer personal data to external third parties and/or outside the EU/ETA. In such case, we will ensure that the personal data is appropriately protected and that privacy legislation in force from time to time is applied. Only the information necessary for the implementation of the service is sent to each party. These service providers do not have the right to use your information for any purpose other than to implement the service. All data transmission takes place via encrypted connections


8. Principles for protecting the registers and retention of personal data

Personal data contained in Malla’s Customer Registers are confidential. The Registers are held in electronic form and are appropriately protected with technical and organizational measures designated to protect information we process. A manually processed information is held locked and protected from unauthorized access. Only named employees have access to the use and maintaining of the password protected Registers. The operators of the Registers are bound by confidentiality obligations.

Should despite of our security measures a security breach occur that is likely to result in a risk to the data privacy of our customers, we will inform the respective customers and other affected parties of  the security breach as well as relevant authorities when required by applicable data protection regulation as soon as reasonably possible.


How long will you store my personal information?

We store personal data for the necessary time considering the purpose for which it was collected as well as applicable legislation. We take reasonable measures to ensure that inaccurate and outdated information will be corrected or erased as soon as possible.


We apply the following retention times:

  • Bookkeeping material at least six (6) years from the end of the financial year
  • Information related to customer relationship (e.g. purchase history, account information) at least six (6) years from the last order
  • Information related to customer service at least three (3) years
  • Information related to contests and draws for prizes until the winners are reached

We retain log files and backups from our Websites and services to detect and fix security threats as well as to ensure that our services are continuously working as intended.

 

9. Rights of data subjects

As a customer you have the following data protection rights:

  • To inspect your information and to obtain confirmation on whether information concerning you is being processed
  • To know who is processing your information, where your information is shared and how your information is used
  • To request updating or correction of your information
  • To object to the processing of your information and ask us to restrict processing of your information e.g. for direct marketing purposes
  • To request deletion of your information when Lifestyle Atelier Oy has no obligation e.g. by law to retain your personal information.
  • To request the information, which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit information to another controller.

All the records are regularly checked for outdated information, and data subject may request to know the information (e.g. first name, last name, address, business ID) Lifestyle Atelier Oy has on them. However, personal data can only be disclosed within one month of the original request, and if the data subject can personally verify their identity to the Lifestyle Atelier Oy representative.

Lifestyle Atelier Oy may ask you to give us some additional information that we will use to verify your identity. In certain circumstances, as set out in the applicable regulation, we may refuse to execute your request, e.g. in cases when Lifestyle Atelier Oy has the right retain information. Lifestyle Atelier Oy will comply with the requests in accordance with applicable legislation and by observing any mandatory provisions of law restricting the scope of such rights. If you are not satisfied with our response or actions when you exercise your rights, you have the right to lodge a complaint with a relevant supervisory authority.

Any requests relating to the rights of customers mentioned above can be delivered in writing to contact person mentioned in section 2. Requests cannot be made over the phone.

Direct marketing can be canceled according to the instructions provided with each newsletter.


For any enquiries regarding personal data collected by Lifestyle Atelier Oy, one can contact info@mallashop.com


10. Cookies

Our web shop www.mallashop.com uses cookies. Cookies are small data files, which transfer from the server to the computer of the customer. You can choose in your internet browser whether you accept the use of cookies. Please note that disabling cookies significantly reduces the functionality of our web sites and services. The use of cookies must e.g. be allowed in the internet browser to complete web shop purchases. We use cookies to facilitate easier use of our web shop and to analyze how we can enhance our web shop processes. The use of cookies is not visible during your purchase session and does not harm your computer.


Below you will find a list of our partners and other third-parties’ cookies which we use on our Websites:

Google, Facebook and MailChimp.

 

11. Changes and updates to this Privacy Policy

We reserve the right to amend this Privacy Policy at any time for any reason. We recommend that you review this Privacy Policy from time to time. If the amendments are significant, we inform our registered customers by sending email and in any case on our Websites.