PRIVACY NOTICE FOR MARTTIINI ONLINE SERVICES
Last updated on 11.12.2023.
In this privacy notice, we describe how your data is processed when you visit our website, make purchases in our online store, register for the Marttiini Club or want to join our newsletter mailing list. The terms “Marttiini”, “we” and “us” refer to Marttiini Oy that is part of the Finnish public listed company Rapala VMC Oy, and has the Finnish business ID 0192218-9. This privacy notice is also applied by all of Marttiini Oy’s subsidiaries in their business for applicable parts.
If you have any questions about this privacy notice or the processing of your personal data or you wish to exercise your rights, please contact:
Marttiini Oy
Tehtaantie 2
17200 Vääksy
Finland
email: shop@marttiini.fi
Business ID: 0192218-9
1. FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA?
We collect and process your personal for predetermined purposes of use, which include for example visiting our website, ordering products from our online store or contacting us via different communication channels.
CONTRACTUAL OBLIGATIONS
We must process your personal data in order to execute and manage your purchases, orders, payments, returns/exchanges or data requests and to serve you in other ways. For example we cannot provide you with certain services or deliver products to you, without your contact information.
WITH YOUR CONSENT
With your consent, we deliver you advertisements, coupons, newsletters, releases about events and special offers via email or SMS. With your consent, we use cookies and similar technologies on our website to collect statistical data and to send you advertising. You can find more information about cookies and similar technologies from our cookie information.
LEGAL OBLIGATIONS
As a company, we are subject to several legal obligations that require us to process your personal information. For instance, tax and accounting regulations mandate that we retain specific information about your purchases.
LEGITIMATE INTEREST
We process your personal data in our administrative and logistical processes, for analytical and reporting purposes, and to optimize internal business processes within the group to make them more efficient and secure. These actions include, for example, improving customer service processes or delivery schedules for ordered products.
If you have already purchased our products, we may send you advertisements for other products based on our legitimate interests. Analytics, for example, include user interactions across different marketing channels and marketing management. The personal data that is processed for analytical and marketing purposes is based on our legitimate interests related to our customer or similar relationships, as well as our right to conduct business and manage our operations efficiently.
We may also process your personal data to prevent misuse or other criminal activities.
We ensure that processing based on legitimate interests is proportionate to your interests and aligns with reasonable expectations. Please note that you may have the right to object to the processing when we process your information based on legitimate interests.
2. WHAT PERSONAL DATA DO WE PROCESS?
We primarily collect information directly from you. Most of the information is obtained directly from you, for example, when you make purchases in our online store or register for Marttiini Club. We also process technical device and log data that is automatically collected when you use our online services. This data includes, for example, your IP address and the timestamp of your visit.
In general, the processing of your personal information follows the following principle: If we ask you to provide your personal information, you can decide what information you want to share with us. However, in some cases, we may need your personal information to provide our services. For instance, if you make purchases in our online store, we need your name and contact information to deliver the purchased items.
CUSTOMER PROFILE. A customer profile consists of information related to the customer relationship, such as details about loyalty program, purchases made, and areas of your interests. Customer information includes, for example, your email address, name, and contact details.
PURCHASE AND GUARANTEE INFORMATION. Purchase information includes the products you have ordered, dates of order, return and exchange information of the product, payment transactions and delivery information.
MESSAGES AND COMMUNICATIONS DATA refer to data collected from your contacts or when the customer service contacts you. These data may include the contents of the messages you have sent and communications methods. We may also request more information from you if you report an issue on our website.
TECHNICAL DATA. We automatically receive technical data, such as your IP address and device information, when you use our online services. The log files track the Internet protocol (IP) addresses, browser type, Internet service provider (ISP), reference and exit sites, platform type, date/time stamps and numbers of clicks. We use these data to analyze trends, administer the site, prevent fraud, track the navigation of the website as a whole and collect demographic data.
MARKETING DATA. We collect and process various data sets related to our marketing activities. Based on your purchase history, we categorize information to send you advertisements that are interesting and relevant to you. Such information includes, for example, the ads you have viewed or clicked, ads you have interacted with, the marketing messages we have sent you, and your marketing preferences.
COMPETITIONS AND PRIZE DRAWS. At times, we organize competitions, prize draws, campaigns and sponsorship events from which we collect participant information and contact details for delivering the prizes.
COOKIE DATA. We use cookies and similar technologies to collect data about your visit and what you do on our website. These data include individual cookie identifiers, the sites you have visited and the products you have viewed. You can read more about our cookie policy in the cookie statement.
DATA RELATED TO SOCIAL MEDIA. When you use the social media functions or channels on our website, we receive certain information about you, such as your comments, likes, and posts. This includes information based on your activity on social media platforms such as Facebook or YouTube. However, please note that each of our company's pages and applications available through social media sites have their own terms of use and privacy practices.
3. DO WE DISCLOSE YOUR PERSONAL DATA TO THIRD PARTIES?
The primary recipient of your personal information is Marttiini Oy. We also collaborate closely with certain service providers, such as transportation and delivery service providers for product shipments, as well as technical service providers (such as companies offering data center services or providing hosting services for our IT systems). These service providers may, by default, process your data only on our behalf and in specific pre-defined situations.
GROUP COMPANIES. We may disclose personal data to our group company or subsidiaries, as well as companies that manufacture Marttiini Oy’s brands and products that are located within the European Union.
IT AND DATA CENTER SERVICE PROVIDERS. We cooperate with different IT service providers in order to offer our services to you. These service providers include IT system, cloud-based service and server room service providers.
WAREHOUSE AND LOGISTICS SERVICE PROVIDERS. We disclose your personal and purchase data to our warehousing partners and logistics services providers that deliver your products.
MARKETING PARTNERS. We may, with your consent, share your data with social media platforms (such as Facebook and YouTube) in connection with our marketing activities. We may also share your data with other third parties in order to administer and display advertisements on our website and to adapt your online experience based on your interests.
PRODUCT SUPPLIERS, DISTRIBUTORS AND MANUFACTURERS.
We disclose your personal data to our suppliers and service providers that we use to support our business operations. For instance, we use a credit card handling company to invoice you or a logistics partner to deliver your order.
PAYMENT SERVICE PROVIDERS. If you pay with a credit card or online banking credentials, your personal data will be disclosed to the payment service provider to enable the payment process.
SOCIAL MEDIA COMPANIES. Our website allows you to use third-party social media network platforms, such as Facebook. It is possible that these services may collect information about you, including details about your activities. Please note that these activities are subject to the privacy practices of the respective services, and we advise to review their privacy policies.
OTHERS. In addition, we may disclose your personal data to third parties to comply with a court decision or legal obligation, to enforce or apply our terms and conditions of use or to protect the rights, property or safety of Marttiini, our customers or other parties. This can include data disclose with other companies or organizations to prevent misconduct and decrease credit risks. In connection with a merger, acquisition or any other partial or full sales of our assets, the personal data related to our customers in our possession may belong to the assets to be transferred to the buyer.
4. DO WE TRANSFER YOUR PERSONAL DATA OUTSIDE OF THE EUROPEAN ECONOMIC AREA?
Marttiini Oy may receive and transfer personal data to the United States in order to perform the online store services executed on the website in cooperation with our contractual partners located in the United States.
All contractual relationships are protected with necessary privacy agreements, and we do everything in our power to ensure that our international partners comply with the applicable legislation.
In situations where your personal data is transferred to a third country, the level of protection may decrease from the level guaranteed by the EU General Data Protection Regulation. Therefore, before each transfer, we implement the necessary measures to ensure the high-level protection of your personal data under the EU General Data Protection Regulation requirements. Some of the measures we implement include ensuring that the recipient of personal data is certified under the EU-US Data Privacy Framework and using the standard contractual clauses approved and published by the European Commission as part of agreements we make with those entities to whom we transfer personal data to third countries. More information about the EU-US Data Privacy Framework can be found here: https://www.dataprivacyframework.gov/s/ and about the standard contractual clauses here: https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_fi"
5. FOR HOW LONG DO WE STORE YOUR DATA?
Your personal data may not be stored in a format that would allow identifying them for longer than is necessary for the purposes of processing personal data. Thus we must delete the data or alter it so that individuals can no longer be identified once the data is no longer necessary. Marttiini Oy complies with strict procedures with data storage, and we do our best to ensure that we delete all unnecessary data.
As the purpose for processing personal data (see section FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA?) may vary, also the storing time of your personal data varies. For instance, we never store credit card numbers in full due to safety issues.
As long as we have your consent, we are happy to deliver you our marketing materials. But we want to remind you that even if your customer relationship with us is over, we may still process your personal data for as long as we have a legal base to do so. This means, for instance, that we store data for safeguarding our legal rights. In these cases we will store the data until the legal issues in question has been resolved in full.
6. HOW DO WE PROTECT YOUR DATA?
Marttiini applies strict information security methods to protect your personal data. It is important for us to protect the confidentiality and integrity of your personal data when processing them. We have executed measures aimed at protecting your personal data from accidentally going missing or to protect from unlawful access, use, editing or disclosure.
Your personal data is protected with physical, organisational and technological methods. Data are stored on servers located in safe server rooms behind firewalls, and when we use our partners to process your personal data, we insist that they comply with the same rules we comply with. Only authorized persons may use the data, and we maintain several different technical procedures to protect the data and to supervise access. All payment transactions are protected with SSL technology. We do all this to decrease the risk of misplacement, misconduct or unauthorized use, disclosure or altering of your personal data in our possession.
7. YOUR RIGHTS AS A DATA SUBJECT
Pursuant to the European Union General Data Protection Regulation, you have certain rights that you may exercise to limit the use of your personal data and to supervise and protect your personal data.
You have the right to request access to your personal data, the right to rectify or delete data and the right to transfer data from one system to another. In addition, you may request us to limit the processing of your personal data or object to the processing. If the processing of your personal data is based on your consent, you have the right to withdraw your consent at any time.
When you are exercising your rights, please be prepared to verify your identity.
On our website, you can view and update your personal data or withdraw your consent for marketing communications by logging into our website, visiting the My account site and by making changes whenever you see fit. If you have forgotten your password (as you have tried to register and have failed), you can click the “Did you forget your password?” link. That leads you to a website where you can provide your email address. You will receive your username and password in the email address you have entered. If you wish to delete your entire account, please contact us a shop@marttiini.fi
If you have given your consent for using your personal data for marketing purposes, we ensure that you will not receive repetitive marketing messages or other information from us if you wish so: each marketing message from us contains information on how to let us know that you no longer wish to receive these messages. Please remember that you can also withdraw your consent from the service’s My account site at any time.
Also keep in mind that you have the right to file a complaint with the supervisory authority if you believe that we have not complied with the applicable data privacy requirements.