Privacy Policy
Last updated:
1. Data Controller
Company Name: Quythraxstrkhima
Address: Mannerheimintie 20, 00100 Helsinki, Finland
Email: touch@quythraxstrkhima.world
Website: https://quythraxstrkhima.world
Quythraxstrkhima acts as the data controller for the personal data collected through this website and is responsible for ensuring that data processing complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Finnish Data Protection Act (1050/2018), and other applicable data protection legislation.
2. What Personal Data We Collect
We collect the following personal data when you interact with our website:
2.1 Data Provided by You
- Full name — provided when you submit the order form.
- Email address — provided when you submit the order form.
- Phone number (optional) — provided at your discretion when submitting the order form.
- Message content (optional) — any additional information you choose to include.
- Consent status — your GDPR consent acknowledgment.
2.2 Data Collected Automatically
- Cookie preferences — stored locally in your browser via localStorage.
- Technical data — such as browser type, operating system, screen resolution, and referring URL, collected through analytics cookies (only if you have consented).
- IP address — may be collected through server logs for security and fraud prevention purposes.
3. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
- Consent (Art. 6(1)(a)) — when you provide explicit consent via the order form or cookie consent banner.
- Performance of a contract (Art. 6(1)(b)) — when processing is necessary to fulfill your order or respond to your inquiry.
- Legitimate interests (Art. 6(1)(f)) — for website security, fraud prevention, and improving our services, provided these interests do not override your fundamental rights.
- Legal obligation (Art. 6(1)(c)) — when we are required to retain data under applicable Finnish or EU law (e.g., tax and accounting regulations).
4. Purpose of Data Processing
We use your personal data for the following purposes:
- Processing and fulfilling your orders.
- Communicating with you regarding your order, inquiries, or customer support.
- Sending order confirmation and delivery updates.
- Complying with legal and regulatory obligations.
- Improving our website functionality and user experience (with consent).
- Analyzing website traffic and usage patterns through analytics cookies (with consent).
- Preventing fraud and ensuring website security.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period | Reason |
|---|---|---|
| Order form data | 3 years from submission | Contract fulfillment and legal obligations |
| Email correspondence | 2 years from last communication | Customer support and dispute resolution |
| Cookie consent preferences | 12 months | Compliance with ePrivacy Directive |
| Analytics data | 26 months | Website improvement (anonymized where possible) |
| Accounting records | 6 years | Finnish Accounting Act (1336/1997) |
After the retention period expires, data is securely deleted or anonymized.
6. Data Sharing and Third Parties
We do not sell your personal data. We may share your data with the following categories of recipients only when necessary:
- Payment processors — to process transactions securely.
- Shipping and logistics providers — to deliver your order.
- Analytics providers — to analyze website usage (only with your consent; data is anonymized where possible).
- Legal authorities — when required by Finnish or EU law, or to protect our legitimate interests.
All third-party processors are bound by data processing agreements (DPAs) and are required to comply with GDPR.
7. International Data Transfers
Your data is primarily processed within the European Economic Area (EEA). If any data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses (SCCs).
- Adequacy decisions by the European Commission.
- Other mechanisms approved under GDPR Chapter V.
8. Your Rights Under GDPR
Under the GDPR and Finnish data protection law, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of your personal data.
- Right to rectification (Art. 16) — request correction of inaccurate data.
- Right to erasure (Art. 17) — request deletion of your data ("right to be forgotten").
- Right to restriction (Art. 18) — request limitation of processing.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent — withdraw your consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — file a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) at https://tietosuoja.fi/en/home.
To exercise any of these rights, contact us at: touch@quythraxstrkhima.world. We will respond within 30 days of receiving your request.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- HTTPS encryption for all data transmission.
- Secure storage of personal data with access controls.
- Regular security assessments and updates.
- Employee training on data protection practices.
- Incident response procedures for data breaches.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Finnish Data Protection Ombudsman within 72 hours and inform affected individuals without undue delay, in accordance with GDPR Articles 33 and 34.
10. Cookies
Our website uses cookies and similar technologies. For detailed information about the types of cookies we use, their purposes, and how to manage your preferences, please refer to our Cookie Policy.
11. Children's Privacy
Our website and products are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The updated version will be posted on this page with a revised "Last updated" date. We encourage you to review this policy periodically.
13. Contact Us
If you have any questions or concerns about this Privacy Policy or our data processing practices, please contact us:
Quythraxstrkhima
Mannerheimintie 20, 00100 Helsinki, Finland
Email: touch@quythraxstrkhima.world
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
P.O. Box 800, 00531 Helsinki, Finland
Website: https://tietosuoja.fi/en/home