Data protection refers to the exercise of the rights of the data subjects whose personal data is processed. The purpose of data protection is to indicate when, and under what conditions, personal data can be processed. Personal data, on the other hand, refers to information linked to an identified or identifiable natural person.
In this policy, “we” refers to the following companies of the Biolan Group that process personal data: Biolan Oy, Novarbo Oy, Biolan Ekoasuminen Oy, Favorit Tuote Oy, Kiertoravinne Oy (Biolan Group, Finland). The policy applies to the Group and the controller is Biolan Oy and/or the Group company you are dealing with.
The purposes for processing data
We collect and process personal data in order to:
Legal grounds for processing personal data
In certain situations, we will ask for your consent to process your personal data. These situations include, for example, consent to electronic direct marketing or the processing of certain special categories of data. The consent request contains information on the processing of such data. If you have consented to the processing of personal data, you also have the right to withdraw said consent.
When we market our services or products to individuals in marketing target groups, potential customers or existing customers, we process personal data on the basis of a legitimate interest. We have a legitimate interest to market our services and products in different ways. We want to provide the most interesting information and marketing to the target groups, such as on our website and in our social media channels. In addition, we may market our services or those of a third party through newsletters or event invitations, among other things. We may use social media tools in our marketing, such as different target groups. We analyse our email campaigns and the activity on our website and social media channels. This allows us to assess, for example, the effectiveness of our marketing campaigns. This information forms the basis for our business development and future marketing activities.
We also have a legitimate interest to develop our products and services. The development of processes and systems related to our business may be based on the processing of personal data. This may also involve the processing of personal data to prevent and investigate abuses.
When we perform our contractual obligations, we process personal data on the basis of a contract, such as a service, employment or assignment contract. In addition, we process personal data to fulfil our legal obligations, such as accounting and tax legislation.
For example, our websites and services ask for your contact information when you subscribe to a newsletter, register for an event, submit feedback or send a contact request. When you create an account, you provide us with at least your login details and information necessary for the service to function, such as your name, address, phone number and email address. In addition, we process your order data. In some cases, processing the personal identity number may be necessary, for example, to identify the customer in debt collection.
We may receive information about you from our partners, such as on the success of our advertising campaign when our advertising is published on their platforms, for example.
In certain cases, we collect personal data from publicly available sources, such as registers maintained by public authorities (e.g. population register, tax administration registers) and commercial data brokers.
We will only retain personal data for as long as it is needed to provide the service or for the maximum period permitted by law.
For legal reasons
Your personal data may be disclosed, for example, in accordance with the requirements set out by the competent authority and the conditions based on law.
Automated decision making means making decisions based on automated processing, which produces legal effects for a person or significantly affects a person in a similar manner. We do not use automated decision-making in our operations.
Profiling refers to the automatic processing of personal data, which involves, for example, the assessment or prediction of a person’s interests or behaviour. We may use profiling in our marketing to target the most suitable and interesting products and services to each customer.
We strive to implement the services and process personal data using operators and services located in the EU or EEA.
However, in some cases, the services may also be implemented using operators, services and servers located elsewhere. In such a case, personal data may be transferred between different countries. These transfers may include transfers of personal data outside the EU or EEA to countries whose legislation on the processing of personal data differs from the requirements of Finnish law. In this case, we will ensure an adequate level of personal data protection, for example, by making an agreement with the personal data processor.
Data security is ensured by appropriate administrative, technical and physical security measures.
The service we provide is not aimed at minors and we do not collect personal data from minors in particular. We ask minors to obtain parental consent before disclosing their personal data. We recommend that guardians regularly monitor their dependants’ use of the Internet and our website.
Right of inspection
You have the right to inspect what information about you is processed.
Right to rectification
You have the right to demand that incorrect, inaccurate, incomplete, outdated or unnecessary information be corrected or supplemented.
Right to request deletion of data
You can ask us to delete your personal data from our systems. We will take steps to comply with your request, unless we have a legitimate reason to not delete the data. Data may not be immediately deleted from all of our backup or other similar systems.
Right to restrict processing
You can ask us to restrict the processing of certain parts of your personal data. A request to restrict the processing of data may result in more limited access to our websites and services.
Right to object to data processing
You may also request restrictions on the processing of your personal data if your data is processed for purposes other than the performance of our services or to comply with a legal obligation. Objection to the processing of personal data may result in more limited access to our website.
Right to portability
You have the right to receive your personal data from us in a structured and commonly used format so that you can transmit the data to another controller.
Right to withdraw consent
If the processing of your data is based on consent, you have the right to withdraw your consent at any time.
You have the right to object to electronic direct marketing by following the instructions included in all marketing communications by us.
You can exercise your rights by contacting customer service. We may ask you for additional information to verify your identity. Please also note that our operations are subject to legal obligations, for example in relation to data retention, and therefore we may be obliged to process your personal data even if you wish to restrict the processing or deletion of your data.
If you feel that the processing of your personal data to be in conflict with applicable legislation, you may lodge a complaint with your local data protection supervisory authority.
You can contact us in matters concerning data protection by sending an email to firstname.lastname@example.org.