Privacy Policy

  1. Introduction

Data protection refers to the exercise of the rights of the data subjects whose personal data is processed. The purpose of data protection is to indicate when, and under what conditions, personal data can be processed. Personal data, on the other hand, refers to information linked to an identified or identifiable natural person.

In this policy, “we” refers to the following companies of the Biolan Group that process personal data: Biolan Oy, Novarbo Oy, Biolan Ekoasuminen Oy, Favorit Tuote Oy, Kiertoravinne Oy (Biolan Group, Finland). The policy applies to the Group and the controller is Biolan Oy and/or the Group company you are dealing with.

Processing of personal data is necessary for our operations. We follow procedures and processes to safeguard personal data in accordance with the requirements of data protection legislation. This privacy policy sets out the grounds for data collection and the purposes for the collected data. Use of our services is an example of an applied situation. The privacy policy also applies to the processing of personal data of our employees, job applicants and other personnel of our partners.

  1. Why do we process personal data and on what basis?

The purposes for processing data

We collect and process personal data in order to:

  • market and communicate our services to potential customers and existing customers, or the services of selected third parties, for example, through communications, newsletters, various marketing campaigns or event invitations.
  • fulfil our contractual obligations towards customers, partners and, for example, our employees.
  • develop our services and improve the user experience thereof.
  • manage our services.
  • prevent and, in certain situations, investigate possible misconduct.

Legal grounds for processing personal data

In certain situations, we will ask for your consent to process your personal data. These situations include, for example, consent to electronic direct marketing or the processing of certain special categories of data. The consent request contains information on the processing of such data. If you have consented to the processing of personal data, you also have the right to withdraw said consent.

When we market our services or products to individuals in marketing target groups, potential customers or existing customers, we process personal data on the basis of a legitimate interest. We have a legitimate interest to market our services and products in different ways. We want to provide the most interesting information and marketing to the target groups, such as on our website and in our social media channels. In addition, we may market our services or those of a third party through newsletters or event invitations, among other things. We may use social media tools in our marketing, such as different target groups. We analyse our email campaigns and the activity on our website and social media channels. This allows us to assess, for example, the effectiveness of our marketing campaigns. This information forms the basis for our business development and future marketing activities.

We also have a legitimate interest to develop our products and services. The development of processes and systems related to our business may be based on the processing of personal data. This may also involve the processing of personal data to prevent and investigate abuses.

When we perform our contractual obligations, we process personal data on the basis of a contract, such as a service, employment or assignment contract. In addition, we process personal data to fulfil our legal obligations, such as accounting and tax legislation.

  1. What data do we collect?

We collect data that is necessary for the purposes defined in this privacy policy:

A. Information you provide to us

For example, our websites and services ask for your contact information when you subscribe to a newsletter, register for an event, submit feedback or send a contact request. When you create an account, you provide us with at least your login details and information necessary for the service to function, such as your name, address, phone number and email address. In addition, we process your order data. In some cases, processing the personal identity number may be necessary, for example, to identify the customer in debt collection.

B. Information we receive from others

We may receive information about you from our partners, such as on the success of our advertising campaign when our advertising is published on their platforms, for example.

C. Technical data observed and derived from the use of the services:

We use various technologies (including cookies) to collect and store information about users and visitors of the site and its services. More information about the cookies used on our website is available in our Cookie Policy, and cookies can be managed with a consent tool.

D. Data collected from other sources

In certain cases, we collect personal data from publicly available sources, such as registers maintained by public authorities (e.g. population register, tax administration registers) and commercial data brokers.

  1. How long will user data be retained?

We will only retain personal data for as long as it is needed to provide the service or for the maximum period permitted by law.

  1. Who can we share your information with?

Service Providers

We only transfer personal data to the extent that third parties need access to the processed personal data to provide our services for the purposes set out in this privacy policy. In this case, these service providers process the data on our behalf.

For legal reasons

Your personal data may be disclosed, for example, in accordance with the requirements set out by the competent authority and the conditions based on law.

  1. Automated decision making and profiling

Automated decision making means making decisions based on automated processing, which produces legal effects for a person or significantly affects a person in a similar manner. We do not use automated decision-making in our operations.

Profiling refers to the automatic processing of personal data, which involves, for example, the assessment or prediction of a person’s interests or behaviour. We may use profiling in our marketing to target the most suitable and interesting products and services to each customer.

  1. International data transfers

We strive to implement the services and process personal data using operators and services located in the EU or EEA.

However, in some cases, the services may also be implemented using operators, services and servers located elsewhere. In such a case, personal data may be transferred between different countries. These transfers may include transfers of personal data outside the EU or EEA to countries whose legislation on the processing of personal data differs from the requirements of Finnish law. In this case, we will ensure an adequate level of personal data protection, for example, by making an agreement with the personal data processor.

  1. Data security

Data security is ensured by appropriate administrative, technical and physical security measures.

  1. Minors

The service we provide is not aimed at minors and we do not collect personal data from minors in particular. We ask minors to obtain parental consent before disclosing their personal data. We recommend that guardians regularly monitor their dependants’ use of the Internet and our website.

  1. Third-party services

This privacy policy applies only to the service provided by us and we are not responsible for the privacy policies of other sites. We recommend that users check the privacy policies of the websites they use.

  1. Amendments to the privacy policy

We reserve the right to amend this privacy policy. If any changes are made to the privacy policy, we will always inform you of these changes herein.

  1. Your rights

Right of inspection

You have the right to inspect what information about you is processed.

Right to rectification

You have the right to demand that incorrect, inaccurate, incomplete, outdated or unnecessary information be corrected or supplemented.

Right to request deletion of data

You can ask us to delete your personal data from our systems. We will take steps to comply with your request, unless we have a legitimate reason to not delete the data. Data may not be immediately deleted from all of our backup or other similar systems.

Right to restrict processing

You can ask us to restrict the processing of certain parts of your personal data. A request to restrict the processing of data may result in more limited access to our websites and services.

Right to object to data processing

You may also request restrictions on the processing of your personal data if your data is processed for purposes other than the performance of our services or to comply with a legal obligation. Objection to the processing of personal data may result in more limited access to our website.

Right to portability

You have the right to receive your personal data from us in a structured and commonly used format so that you can transmit the data to another controller.

Right to withdraw consent

If the processing of your data is based on consent, you have the right to withdraw your consent at any time.

You have the right to object to electronic direct marketing by following the instructions included in all marketing communications by us.

  1. Exercising your rights

You can exercise your rights by contacting customer service. We may ask you for additional information to verify your identity. Please also note that our operations are subject to legal obligations, for example in relation to data retention, and therefore we may be obliged to process your personal data even if you wish to restrict the processing or deletion of your data.

If you feel that the processing of your personal data to be in conflict with applicable legislation, you may lodge a complaint with your local data protection supervisory authority.

  1. Who can I contact?

You can contact us in matters concerning data protection by sending an email to