Privacy policy

Granny in the snow Oy handles your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

This privacy policy explains which data we collect and what we use them for. It also explains how and for what purpose this is done. Personal data are data which can be used to identify you personally. 

 

Responsibility for data processing

The controller responsible for the processing of data on this website under Art. 4 No. 7 GDPR is Emma Mieskonen.

Please see contact details in the Team page.

 

Data recording on this website

We receive, collect and store any information you enter on our website or provide us in any other way. In addition, we collect the Internet protocol (IP) address used to connect your computer to the Internet; e-mail address; computer and connection information and purchase history. We may use software tools to measure and collect session information, including page response times, length of visits to certain pages, page interaction information, and methods used to browse away from the page. We also collect personally identifiable information (including name, email, communications); payment details (including credit card information), comments, feedback, product reviews, recommendations, and personal profile.

Purpose of data processing

We collect Non-personal and Personal Information for the following purposes:

  • To provide and operate our Services;

  • To provide our Users with ongoing customer assistance and technical support;

  • To be able to contact our Visitors and Users with general or personalized service-related notices and promotional messages;

  • To create aggregated statistical data and other aggregated and/or inferred Non-personal Information, which we may use to provide and improve our respective services; 

  • To comply with any applicable laws and regulations.

 

When you conduct a transaction on our website, as part of the process, we collect personal information you give us such as your name and email address. Your personal information will be used for the specific reasons stated above only.

The collection of data to provide the website and saving the data in log files is essential for operating the website and for providing our services to customers. 

Storing your data

Our company is hosted on the Wix.com platform. Wix.com provides us with the online platform that allows us to sell our products and services to you. Your data may be stored through Wix.com’s data storage, databases and the general Wix.com applications. They store your data on secure servers behind a firewall.  

All direct payment gateways offered by Wix.com and used by our company adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.

Legal basis

The basis for the data processing is Art. 6 (1) lit. f GDPR. The temporary storage of the IP address is required to enable the website to be delivered to the user’s computer. The user’s IP address must be saved for the duration of the session for this purpose. Log files are saved to ensure the functionality of the website and the security of our information technology systems.

Duration of storage

The data will be erased as soon as they are no longer required to achieve the purpose for which they were collected. For collecting the data to provide the website, this is when the session is ended.

Right to object and deletion option

Due to the fact that the data required for providing the website and the saving of the data in log files is essential for operating the website, users have no right to object to the data being processed.

Cookies

Cookies are small text files which are placed on your computer and are saved by your browser. They are used to make the website more user-friendly, effective and secure. Cookies do not cause any damage to your computer and do not contain viruses.

The website uses various essential cookies to ensure that it functions correctly and to make it easier to navigate for users, as well as cookies which are not essential for the technical functioning of the website, but enable us to carry out various tasks, particularly analyses.

As the user, when you open our website you are notified of the use of essential cookies and of other non-essential cookies. Your consent to process the personal data used in this respect (relating to the non-essential cookies) is both requested and obtained via a pop-up notification. This notification also includes information about this privacy policy.

The following links explain how to access cookie settings in various browsers:

 

To opt out of being tracked by Google Analytics across all websites, visit this link: http://tools.google.com/dlpage/gaoptout.

Legal basis

The legal basis for processing personal data using technically essential cookies is Art. 6 (1) lit. f GDPR. Our legitimate interest is the provision of the website.

Duration of storage, right to object and deletion option

Cookies are saved on the user’s computer and sent from the computer to our site. Therefore, as the user, you have full control over the use of cookies. By changing the settings in your Internet browser, you can disable or restrict the transfer of cookies. Cookies that have already been saved can be deleted at any time. This can also be done automatically. If cookies for our website are disabled, it is possible that you will be unable to use all the features of this website.

Furthermore, we’d like to draw your attention to the consent tool on our website in which you can select your choice relating to settings for all non-essential cookies.

Email and form contact

On our website, it is possible to contact us using the provided email address. In this case, your personal data submitted with the email will be saved. The data will not be forwarded to third parties.

If you use a form on our website, the data you enter in the input mask will be sent to us and saved when you send them. The following data will be saved:

  • Your email address

  • Your name

  • The information which you enter into the fields

 

We may contact you to notify you regarding your account, to troubleshoot problems with your account, to resolve a dispute, to collect fees or monies owed, to poll your opinions through surveys or questionnaires, to send updates about our company, or as otherwise necessary to contact you to enforce our User Agreement, applicable national laws, and any agreement we may have with you. For these purposes we may contact you via email.

Legal basis and purpose for data processing

The legal basis for processing the data if the user’s consent has been obtained is Art. 6 (1) lit. a of the GDPR. The legal basis for processing the data sent in an email is Art. 6 (1) lit. f GDPR. If the purpose of the email contact is to conclude a contract, the additional legal basis for processing the data is Art. 5 (1) lit. b GDPR.

Duration of storage, right to object and erasure option

The data will be erased when they are no longer required to achieve the purpose for which they were collected, in other words when the conversation with you, the user, is ended or the matter has been fully clarified or two months following the delivery of your order. 

You have the opportunity at any time to revoke your consent for processing the personal data.
 

Your rights

 

Information, restriction of processing, erasure

Under the current statutory regulations set out in Art. 15 of the GDPR, you have the right at any time to be provided with free of charge information about the personal data, their origin and recipients stored on you, the purpose of the data processing and, if applicable, under Art. 16 of the GDPR, the right to demand the rectification, restriction of processing (Art. 18 GDPR) or erasure of these data (Art. 17 GDPR). For this purpose and if you have any other questions relating to personal data, you can contact us at any time.

Right to data transferability

You have the right to have any data, which we process automatically on the basis of your consent or to fulfil a contract, to be sent to you or a third party in a commonly used, machine-readable format (Art. 20 GDPR). If you request that the data are sent direct to a different controller, this will only be done if it is technically feasible.

Right to complain to the relevant supervisory authority

In the event of breaches of data protection law, the data subject has the right to complain to the relevant supervisory authority. The relevant supervisory authority in data protection matters is the data protection officer of Finland in which our company is located.

Revocation of consent declarations

There are data processing procedures which are only possible with your express consent. You can revoke any consent you have already given at any time. You only need to send an informal notification to us by email for this purpose. The legality of any data processing operations, which have been performed before the revocation, will not be affected by this revocation.

 

Your right to object under Art. 21 GDPR

You have the right, for reasons resulting from your specific situation, to object at any time to us on an informal basis against the processing of your personal data taking place on the basis of Art. 6 (1) lit. e GDPR (data processing in the public interest) and Art. 6 (1) lit. f GDPR (data processing on the basis of a legitimate interest). If you submit an objection, we shall cease to process your personal data unless we can provide evidence that there are compelling grounds, which merit protection, for processing the data which outweigh your interests, rights and freedoms, or the data processing is taking place for the purpose of lodging, exercising or defending legal claims.

 

Analysis and advertising tools used

We use Wix.com to help us understand how our customers use our website.

Legal basis for data processing

The basis for the use of Wix.com is Art. 6 (1) sentence 1 letter f GDPR. Our legitimate interest for its use is that we can improve our website using the statistics acquired through Wix.com  and make our website more interesting for you, the user.

Duration of storage

The data will be erased as soon as they are no longer required for our recording purposes, but at the latest after one year. 

 

Social media

Social media links

If you use any social media icons on our website, your personal data will not automatically be forwarded. To prevent automatic data transfers to the service providers of social media, these services are included on our website by means of Internet links. We have no joint data protection responsibility if your data are processed by these service providers for purposes defined by them.

Our social media sites are part of our public relations work. Our aim is to inform appropriate target groups and exchange information with them.

 

If you would like to: access, correct, amend or delete any personal information we have about you, you are invited to contact us at emma@grannyinthesnow.com.

We reserve the right to modify this privacy policy at any time. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.