Security and Privacy

Created on 29.08.2024.

The Privacy Policy and Registry Description are updated regularly, so please check it periodically.

1. Data Controller

Niramuchu Art & Design, Business ID: 2963166-6

2. Contact Person Responsible for the Registry

Aliisa Matthews | Peltolantie 3, 04600 Mäntsälä, Finland | info@niramuchuart.com

3. Name of the Registry

Niramuchu Art & Design customer registry

4. Websites Related to the Registry

www.niramuchuart.com

5. Purpose

Personal data is used for selling products, managing and developing customer relationships, and electronic marketing using tools such as Meta Pixel, Google Analytics, and the Shopify Email newsletter application.

The legal basis for processing personal data in accordance with the EU General Data Protection Regulation is the individual's consent or contract (documented, voluntary, specific, informed, and unambiguous).

6. Content of the Registry

The registry consists of information provided by buyers during the purchase of products from the website, data collected via contact forms or customer reviews, and users who have subscribed to the newsletter.

The information stored in the registry includes: name, email address, phone number, delivery and billing address details, IP address of the internet connection, information about ordered products and their changes, and other data related to the customer relationship.

There are two customer registries:

  • The information collected via the website includes the customer's name, email address, phone number, and delivery and billing address details.
  • The registry of newsletter subscribers contains the customer's email address. A newsletter subscriber can unsubscribe at any time through a link in the newsletter.

Information is retained in the website's registry until there are no longer accounting reasons to keep it. Subscribers to the newsletter can request their data to be deleted immediately.

The IP addresses of website visitors and cookies necessary for the service’s functions are processed based on legitimate interest, for example, to ensure security and collect statistics about visitors when they can be considered personal data. Consent is separately requested for third-party cookies, if necessary.

7. Regular Sources of Information

The information stored in the customer registry is obtained from customers during the purchase of products or through contact forms, and from other situations where the customer provides their data. The information in the newsletter subscriber registry is collected when a user subscribes to the newsletter on the website or during the ordering process.

8. Privacy and Data Protection

Customer data on the website is confidential and is never disclosed to third parties. Only the registry administrator has access to the customer registry, and it requires a username and password.

The website processes the user’s payment information when purchasing products. All payment transactions are secure and conducted through an encrypted connection.

9. Regular Data Transfers and Transfers Outside the EU or EEA

The information collected in the registries is not disclosed outside the company for marketing, sales, opinion, or market research purposes. Personal data may, however, be disclosed to authorities in accordance with Finnish law when requested.

The registry is stored in an information system and is protected to prevent unauthorized access to the data.

Visitor information on the website is collected by:

  • Shopify
  • Google Analytics
  • Meta (tracking pixel)

Information of newsletter subscribers is collected by:

  • Shopify

If you would like to review the privacy policies of third parties, please contact us, and we will send you the links via email.

10. Principles of Registry Protection

Care is taken in handling the registry, and the data processed by information systems is appropriately protected. When registry data is stored on internet servers, the physical and digital security of the equipment is properly managed. The data controller ensures that stored information, server access rights, and other critical personal data are handled confidentially.

11. Right to Review and Right to Request Data Correction

Every individual in the registry has the right to review the data stored about them and request correction of any incorrect information or the completion of incomplete data. If a person wants to review the stored data or request a correction, the request must be sent in writing to the data controller. The data controller may request the person making the request to prove their identity. The data controller will respond to the customer within the time specified by the EU General Data Protection Regulation (generally within one month).

12. Other Rights Related to Personal Data Processing

Individuals in the registry have the rights defined by the EU General Data Protection Regulation. An individual has the "right to be forgotten," meaning the right to request the deletion of their personal data from the registry. Please note that you have the right to be forgotten only if the data controller has no legal obligations to continue processing your personal data. Requests must be sent in writing to the data controller. The data controller may request the person making the request to prove their identity. The data controller will respond to the customer within the time specified by the EU General Data Protection Regulation (generally within one month).

13. Cookies

The websites use cookies. A cookie is a small text file that is sent to and stored on the user’s computer. Cookies do not harm users' computers or files.

    The company collects information from visitors to niramuchuart.com. The information is primarily used for targeted advertising and business development. Other websites linked to may collect and use cookies according to their own cookie policies.

    The user must accept the cookies for each site. If the user does not accept the collection of information, the use of the site must be immediately stopped. You can disable cookies in your browser settings. However, note that disabling cookies may affect the efficient use of services. Allowing cookies ensures a smoother experience on the website.

    14. Do not sell or share my personal information (Customers in the U.S)

    As described in our Privacy Policy, we collect personal information from your interactions with us and our website, including through cookies and similar technologies. We may also share this personal information with third parties, including advertising partners. We do this in order to show you ads on other websites that are more relevant to your interests and for other reasons outlined in our privacy policy.

    Sharing of personal information for targeted advertising based on your interaction on different websites may be considered "sales", "sharing", or "targeted advertising" under certain U.S. state privacy laws. Depending on where you live, you may have the right to opt out of these activities. If you would like to exercise this opt-out right, please follow the instructions below.

    If you visit our website with the Global Privacy Control opt-out preference signal enabled, depending on where you are, we will treat this as a request to opt-out of activity that may be considered a “sale” or “sharing” of personal information or other uses that may be considered targeted advertising for the device and browser you used to visit our website.

    15. Additional Information

    For questions related to the Privacy Policy and Registry Description, you can contact the data controller via email at info@niramuchuart.com.