PRIVACY STATEMENT

This Privacy Statement has been updated on 06.05.2020.

The

1. The controller

Piece Of Jeans Oy

Business ID: 3134446-3

Established 1/2019

Company address: Atomikatu 1 E 40, 33720 TAMPERE

The

2. Contact person responsible for the register

Moona Kansanen

pieceofjeans@outlook.com

Atomikatu 1 E 40, 33720 TAMPERE

+358 400 159 594

The

3. Name of the register

Piece Of Jeans Oy's customer register.

 

4. Purpose of the processing of personal data

We always process personal information only for pre-defined purposes, such as customer relationship management, product delivery and invoicing, online service implementation, communications and marketing.

The

5. Information content of the register

The register contains persons' contact information, customer relationship information, material produced by the registrant himself, information on the use of online services and contact information. The register does not contain information classified as sensitive.

The

6. Regular sources of information

Mainly personal data is obtained from the data subject himself, e.g. Messages sent via web forms, e-mail, telephone, via social media services, contracts, customer meetings and other situations in which the customer discloses their information. In addition, the use of the online service is obtained through cookies.

7. Description of the recipients of the personal data

The information will not be passed on to third parties for their own purposes, but only for the implementation of Piece Of Jeans services, such as the delivery of products. A data processing agreement has been entered into with each partner, in which the partner undertakes to process the data in accordance with data protection legislation and the Piece Of Jeans guidelines, and with due regard for data security. Partners agree to use only subcontractors who follow the same practices.

The

List of partner companies that receive Piece Of Jeans Oy's customer information:

    Checkout Finland Oy: Our e-commerce orders Online payments are operated in Checkout, where the customer enters their name and online payment information when paying. Online payment information (such as credit card information) is not stored in the Piece Of Jeans customer register. Checkout is a PCI DSS certified operator. Checkout Finland Oy is responsible for data processing.

    The Rocket Science Group / MailChimp: Newsletter Tool With MailChimp, we send newsletters and promotional messages to subscribers and potential subscribers. We provide MailChimp with people's first and last name and e-mail address, as well as any information required to place a customer's order, such as the size of the jeans to be ordered. MailChimp collects user-specific information about receiving newsletters and marketing messages, opening a message, and clicking on links. The Piece Of Jeans marketing manager is responsible for data processing, but in the event of system problems, MailChimp may have to process personal data in connection with the resolution of the problem.

    SurveyMonkey: Survey Tool SurveyMonkey is used to create feedback forms for our website. The website addresses of the feedback forms are integrated into our website, so the feedback form opens in a new window on the website. We provide MailChimp with contact information at the beginning of the feedback, such as a name and email address. The Piece Of Jeans Marketing Manager is responsible for data processing, but in the event of a system problem, SurveyMonkey may need to process personal information in connection with the resolution of the problem.

Posti Group Oyj: In connection with the shipment of products, we deliver to Posti our customers' name, address, telephone number and e-mail for package arrival notifications.

    Oy Matkahuolto Ab: In connection with the shipment of products, we provide Matkahuolto with our customers' names, addresses and telephone numbers for package arrival notifications.

    Google Inc / Google Analytics, Google Ads, and Web-Stat: Companies that provide web analytics services to Google Analytics and Web-Stat collect the IP addresses of our web users as well as information about web behavior (e.g. duration of visits, pages visited, frequency of visits). We examine analytics data at a general level, analyzing the behavior of visitor flows - not the behavior of an individual visitor.

    Shopify: The e-commerce platform receives customer information about product orders placed in our e-shop. Shopify collects and archives information filled out on customers ’order forms, such as name, address, phone number and email, and any approval for email marketing.

    Facebook Inc & Instagram: Facebook, a company that provides online user analytics services, collects the IP addresses of our network users as well as information about network behavior (e.g. duration of visits, pages visited, frequency of visits). We examine analytics data at a general level, analyzing the behavior of visitor flows - not the behavior of an individual visitor.

    Hotjar: Hotjar, a company that provides online user analytics services, collects the IP addresses of our network users as well as information about network behavior (e.g. duration of visits, pages visited). We examine analytics data at a general level, analyzing the behavior of visitor flows - not the behavior of an individual visitor.

The

8. Regular transfers of data and transfers of data outside the EU or the EEA

As a general rule, personal data will not be transferred outside the EU or the EEA.

Data will not be regularly transferred outside the EU or the European Economic Area unless it is necessary for the delivery of the product or for any other reason. In this case, the controller shall ensure an adequate level of data protection through contractual arrangements as required by law.

Exceptions are our partners Google, Shopify, Facebook, Instagram, MailChimp, whose servers are located outside the EU or the EEA.

9. Registry Security Principles

The register shall be handled with due care and the information processed by the information systems shall be adequately protected. When registry information is stored on Internet servers, the physical and digital security of their hardware is adequately addressed. The controller shall ensure that the data stored, as well as the access rights to the servers and other information critical to the security of personal data, are treated confidentially and only by the employees whose job description it includes.

The

10. Right of inspection and right to request correction of information

Every person in the register has the right to check the information stored in the register and to request the correction of any incorrect information or the completion of incomplete information. If a person wishes to check the data stored about him or to request a correction, the request must be sent in writing to the data controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).

The

11. Other rights related to the processing of personal data

A person in the register has the right to request the removal of his or her personal data from the register ("the right to be forgotten"). Data subjects also have other rights under the EU's general data protection regulation, such as restrictions on the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the controller may ask the applicant to prove his or her identity. The controller will respond to the customer within the timeframe set out in the EU Data Protection Regulation (generally within one month).

The

12. Can this privacy statement be amended?

The data controller may update this privacy statement due to changes in legislation, the technologies it utilizes or its business. The data controller shall endeavor to inform data subjects in the manner required by their significance. If required by applicable data protection law, the controller may request the data subject to accept significant changes to the privacy statement.