PRIVACY POLICY – How We Use Your Personal Data
1. Data controller
Photographer Kati Kalkamo, Katella Mera, Impivaaranraitti 51, 21130 Poikko, Finland
2. Contact person responsible for the register
Kati Kalkamo, katella@katella.fi
+358415221760
3. Name of the register
Customer register of Photographer Kati Kalkamo
4. Purpose of processing personal data
The personal data collected in the course of the transaction will be used:
• Customer identification and access rights management
• Customer relationship management
• Order confirmations
• Delivery of orders
• Payments and invoicing
5. Data content of the register
• Billing and shipping address
• Details relating to your purchase (for example the print size)
• Email address
• Name
• Phone number
6. Regular sources of information
Personal data are collected from the data subject himself/herself.
The information stored in the register is obtained from the customer through, for example, online purchases, messages sent via e-mail, telephone, social media services, contracts, requests for quotations and other situations where the customer voluntarily discloses his/her information.
The basis for the register is the use of services or voluntary consent. If you do not agree to the practices in this privacy policy, we do not recommend that you provide your personal data.
7. Regular disclosures and transfers of data outside the EU or EEA
There is no regular disclosure of data to other parties except to the partners who manufacture and supply the product purchased by the customer and to the Squarespace, the website platform providing the online store technology, so that they can provide website services to us and they can send confirmation and update emails to customer on our behalf. Our payment processor Stripe will also collect payment information from customer. You can read their privacy policy at https://stripe.com/en-fi/privacy.
Data may be published to the extent agreed with the customer.
Data may also be transferred outside the EU or EEA by the controller.
8. Principles for the protection of the register
The register is processed with due care and the data processed by the information systems are adequately protected. Where the data are stored on Internet servers, the physical and digital security of the hardware is adequately ensured. The controller shall ensure that stored data, as well as access rights to servers and other information critical to the security of personal data, are treated confidentially and only by employees whose job description includes this.
Personal data is only stored for as long as necessary, e.g. for the duration of the customer relationship, unless legislation requires a longer retention period.
9. Right of access and rectification
Any person in the register has the right to check the data recorded in the register and to request the correction of any inaccurate data or the completion of incomplete data. If a person wishes to check or request the rectification of data stored about him or her, the request must be sent in writing to the controller. The controller may, if necessary, ask the applicant to prove his or her identity. The controller will reply to the customer within the time limit laid down in the EU General Data Protection Regulation (as a general rule, within one month).
10. Other rights relating to the processing of personal data
A data subject has the right to request the erasure of personal data concerning him or her from the register ("right to be forgotten"). Data subjects also have other rights under the EU General Data Protection Regulation, such as the restriction of the processing of personal data in certain circumstances. Requests should be sent in writing to the controller. The controller may, if
necessary, ask the applicant to prove his or her identity. The controller will reply to the customer within the time limits set by the EU GDPR (as a general rule, within one month).