PRIVACY POLICY – How We Use Your Personal Data 

 1. Data controller 

Photographer Kati Kalkamo, Katella Mera, Impivaaranraitti 51, 21130 Poikko, Finland 

2. Contact person responsible for the register 

Kati Kalkamo, katella@katella.fi 

+358415221760

3. Name of the register 

Customer register of Photographer Kati Kalkamo 

4. Purpose of processing personal data 

The personal data collected in the course of the transaction will be used: 

• Customer identification and access rights management 

• Customer relationship management 

• Order confirmations 

• Delivery of orders 

• Payments and invoicing 

5. Data content of the register 

• Billing and shipping address 

• Details relating to your purchase (for example the print size) 

• Email address 

• Name 

• Phone number 

6. Regular sources of information 

Personal data are collected from the data subject himself/herself. 

The information stored in the register is obtained from the customer through, for example, online purchases, messages sent via e-mail, telephone, social media services, contracts, requests for  quotations and other situations where the customer voluntarily discloses his/her information. 

The basis for the register is the use of services or voluntary consent. If you do not agree to the  practices in this privacy policy, we do not recommend that you provide your personal data.

7. Regular disclosures and transfers of data outside the EU or EEA 

There is no regular disclosure of data to other parties except to the partners who manufacture  and supply the product purchased by the customer and to the Squarespace, the website platform  providing the online store technology, so that they can provide website services to us and they  can send confirmation and update emails to customer on our behalf. Our payment processor  Stripe will also collect payment information from customer. You can read their privacy policy at  https://stripe.com/en-fi/privacy. 

Data may be published to the extent agreed with the customer. 

Data may also be transferred outside the EU or EEA by the controller. 

8. Principles for the protection of the register 

The register is processed with due care and the data processed by the information systems are  adequately protected. Where the data are stored on Internet servers, the physical and digital  security of the hardware is adequately ensured. The controller shall ensure that stored data, as  well as access rights to servers and other information critical to the security of personal data, are  treated confidentially and only by employees whose job description includes this. 

Personal data is only stored for as long as necessary, e.g. for the duration of the customer  relationship, unless legislation requires a longer retention period. 

9. Right of access and rectification 

Any person in the register has the right to check the data recorded in the register and to request  the correction of any inaccurate data or the completion of incomplete data. If a person wishes to  check or request the rectification of data stored about him or her, the request must be sent in  writing to the controller. The controller may, if necessary, ask the applicant to prove his or her  identity. The controller will reply to the customer within the time limit laid down in the EU General Data Protection Regulation (as a general rule, within one month). 

10. Other rights relating to the processing of personal data 

A data subject has the right to request the erasure of personal data concerning him or her from  the register ("right to be forgotten"). Data subjects also have other rights under the EU General  Data Protection Regulation, such as the restriction of the processing of personal data in certain  circumstances. Requests should be sent in writing to the controller. The controller may, if  

necessary, ask the applicant to prove his or her identity. The controller will reply to the customer  within the time limits set by the EU GDPR (as a general rule, within one month).