General
Our website address is https://mandraki.fi/en/
All content, information and services available on the https://mandraki.fi/en/ website are the exclusive property of Mandraki Finland Oy, Business ID 3474816-4, Kahvipavunkuja 4 B 44, 00990 Helsinki, Finland.
This Privacy Policy and Register Statement, together with the Terms and Conditions, govern the https://mandraki.fi/en/ website and its services.
The website owner is referred to as “Mandraki Finland Oy”.
Customers must accept the terms of this Privacy Policy in order to use the services of Mandraki Finland Oy.
At Mandraki Finland Oy, we are committed to protecting the privacy of our customers and other visitors to our website. This Privacy Policy explains how Mandraki Finland Oy processes personal data.
We use SSL encryption, a well-known and widely used encryption method. This technology ensures that no unauthorised third party can read, modify or interfere with the data transferred between Mandraki Finland Oy and the customer.
Register and Privacy Policy
This is the register and privacy statement of Mandraki Finland Oy in accordance with Sections 10 and 24 of the Finnish Personal Data Act and the EU General Data Protection Regulation (GDPR). Prepared on 24 May 2018.
1. Data Controller
Mandraki Finland Oy
Kahvipavunkuja 4 B 44, 00990 Helsinki
mandraki.helsinki@gmail.com
2. Contact Person Responsible for the Register
Ioannis Chatzinikolakis, mandraki.helsinki@gmail.com, +358 45 1037137.
3. Name of the Register
Mandraki Finland Oy’s customer register.
4. Legal Basis and Purpose of Processing Personal Data
The legal bases for processing personal data under the EU General Data Protection Regulation are:
- the consent of the data subject (documented, voluntary, specific, informed and unambiguous);
- a contract to which the data subject is a party.
The purpose of processing personal data is to process and deliver orders to customers, communicate with customers, maintain customer relationships, conduct marketing activities, etc.
The data is not used for automated decision-making or profiling.
5. Contents of the Register and Information That May Be Collected
Information provided by the user or information that identifies the individual:
- Identification information, such as name
- Contact information, such as address, email address and telephone number
- Payment and other billing information
Contact Form
When a user provides information electronically via the contact form, we collect the following information:
- User’s name. We need to know who is contacting us.
- User’s email address. We need to know where to send our response.
- User’s IP address, for spam detection.
- Email content. This content is checked by Akismet (owned by Automattic) for spam.
Information submitted through the contact form is retained for one (1) year unless the user requests its deletion earlier.
In addition, Mandraki uses reCAPTCHA by Google to verify that the sender is a human and not a bot. The sender’s IP address is shared with this service. You can read Google’s Privacy Policy here.
Information Observed from the Use of Services
- Purchase history, including ordered products and their prices
- Delivery information, such as the selected delivery method and delivery address
- Product reviews
- Online store usage and browsing information, as well as device identification information
Providing identification, contact and payment information is mandatory when purchasing from Mandraki online.
6. What Is My Personal Data Used For?
Personal data is used for:
- Maintaining customer relationships
- Delivering, processing and archiving orders
- Developing Mandraki’s operations and services
- Improving the customer experience
- Providing more personalised and targeted content and marketing
- Preventing misuse and abuse
- Providing better customer service
We aim to be transparent about how we process your personal data. This document provides more detailed information about why we collect, store and process your personal data.
7. Regular Sources of Information
The information stored in the register is obtained from the customer when creating a customer account and placing an order, based on the name and contact details provided by the customer.
8. Regular Disclosures of Information and Transfers Outside the EU or EEA
Personal data is not regularly disclosed to other parties. Information may be published to the extent agreed with the customer.
Data may also be transferred by the data controller outside the EU or EEA. Only Mandraki Finland Oy processes your data.
9. How Is My Data Stored and Protected?
Care is taken in processing the register, and information processed using information systems is appropriately protected. When register information is stored on Internet servers, appropriate measures are taken to ensure the physical and digital security of the hardware. The data controller ensures that stored information, server access rights and other information critical to the security of personal data are handled confidentially and only by employees whose duties require access to such information.
The servers are protected against data breaches and denial-of-service attacks.
We use SSL protection. SSL stands for Secure Sockets Layer and is a standard security method for Internet traffic that creates a secure connection between two computers. An SSL-secured connection ensures that data and information sent from your browser to a web server remain protected from hackers or other parties who may attempt to spy on or steal the information. SSL is an industry standard used by millions of websites to protect sensitive or private information when it is transmitted over the Internet between websites and users’ browsers.
We follow good data protection practices in the processing of personal data and in our technical solutions. The requirements of the EU General Data Protection Regulation, applicable from 25 May 2018, have been taken into account in the processing of personal data.
10. How Long Is My Data Stored?
We retain your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy. In addition, some information may be retained for longer where necessary to fulfil statutory obligations, such as accounting and consumer trade requirements, and to demonstrate proper compliance with such obligations.
At the customer’s request, personal data concerning them may be deleted or anonymised from the systems of https://mandraki.fi/en/. Deletion and anonymisation are irreversible, and deleted customer accounts cannot be restored.
For some information, legislation requires longer retention periods, including for the following purposes:
- The Accounting Act specifies longer retention periods for information regardless of whether the material contains personal data.
- Fulfilling obligations related to consumer trade.
- System log data is collected and retained as required by law in order to provide customers with a lawful and secure online store.
- Maintaining sufficient backups of the store’s databases and systems to protect data, correct errors and ensure information security and business continuity.
Retention Periods for Different Types of Data
- Inactive customer accounts: 12 months
- Open orders: 1 day
- Failed orders: 1 day
- Cancelled orders: 1 day
- Completed orders: 10 years
11. Right of Access and Right to Request Correction of Information
Every person registered in the register has the right to inspect the information stored about them and to request correction of inaccurate information or completion of incomplete information.
If a person wishes to inspect the information stored about them or request its correction, the request must be submitted in writing to the data controller.
The data controller will respond to the customer within the time period specified by the EU General Data Protection Regulation (generally within one month).
12. Other Rights Relating to the Processing of Personal Data
A person registered in the register has the right to request the deletion of their personal data from the register (“the right to be forgotten”).
Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain circumstances.
Requests must be submitted in writing to the data controller. The data controller will respond to the customer within the time period specified by the EU General Data Protection Regulation (generally within one month).
13. Cookies
We use cookies on our website. A cookie is a small text file stored in an Internet browser (for example, Internet Explorer) when using an online store. Cookies enable us to track customers visiting our online store.
The information collected through cookies is anonymous.
The use of cookies is safe and does not damage users’ computers or files. If desired, cookies can be disabled in the settings of your Internet browser. However, disabling cookies may affect the proper functioning of our online store services.
We recommend allowing cookies on the https://mandraki.fi/en/ website for the best possible experience.
Contact Us
If you have any questions regarding this Privacy Policy, please contact us at:
or
Mandraki Finland Oy
Laivalahden puistotie 7 LT5
00810 Helsinki
Finland
