Privacy policy
Allsec Oy’s Privacy Policy
Allsec Oy collects information about its customers and users of its online store in order to provide its customers with the best possible experience when using its services. Customer data is used, for example, to implement a secure service and to improve the quality of customer service and the online store.
Allsec Oy respects the privacy of its customers and will only use the personal data it collects for the purposes stated in this Privacy Policy. Allsec Oy does not sell or disclose its customers’ information other than as described in this Privacy Policy 7. for the purposes set out in the paragraph.
Under the EU General Data Protection Regulation (GDPR), which entered into force in May 2018, the controller of personal data is obliged to inform data subjects about the processing of their personal data. This notice fulfils the information obligation of the GDPR. The customer must accept the terms of this Privacy Policy in order to use Lumisen’s services.
1. The controller
Allsec Oy (business ID 2679420-8)
Contact details:
Rantakallionkatu 3a2
15300 Lahti, Finland
Contact details for matters concerning the register:
Tel. +358 45 6109 115
E-mail: info@allsec.fi
2. Registered persons
The register includes Allsec Oy’s customers who have registered as customers of the online store or placed an order. The register also includes persons who have contacted Allsec Oy’s customer service via the online shop, telephone or e-mail and left their contact details in connection with an order or contact.
The email addresses of newsletter subscribers are collected in another register, which is used for sending newsletters and marketing communications.
3. Grounds for and purposes of keeping the register
The collection and processing of personal data is based on:
- the consent of the customer
- The registered customer relationship between Allsec Oy and the customer
- to meet obligations relating to subscriptions
Purpose of the processing of personal data and use of the register
Personal data will only be processed for the predefined purposes listed below:
- manage your customer relationship and facilitate communication
- order processing, delivery and archiving
- to store purchase history for possible product returns or warranty handling.
- to prevent abuses
- improving the customer experience and the quality of customer service
- developing the company’s own operations and services
- producing targeted content, communications and marketing
- the compilation of statistics
4. Personal data stored in the register
The customer register contains the following information:
- Identifying information, such as first and last name
- Contact information, such as address, email address and phone number
- Purchase history: e.g. products ordered and prices, delivery address, payment method chosen and delivery terms
- Contact history and records of conversations by phone, email or internet
- Data observed from the use of the Services and derived through analytics, such as online browsing and usage data.
5. Rights of the data subject
The data subject has the following rights, the exercise of which should be requested at info@allsec.fi
Right of access
The data subject can check the personal data we have stored.
Right to rectification
The data subject may request the rectification of inaccurate or incomplete data concerning him or her.
Right to object
The data subject may object to the processing of personal data if he or she believes that the personal data have been unlawfully processed.
Direct marketing ban
The data subject has the right to object to the use of the data for direct marketing.
Right of withdrawal
The data subject has the right to request the erasure of data if the processing is not necessary. We will process the request for deletion, after which we will either delete the data or provide a reasoned explanation why the data cannot be deleted.
Please note that the controller may have a legal or other right not to delete the requested data. The registrar is obliged to keep the accounting records for the period specified in the Accounting Act (Chapter 2, Section 10) (10 years). Therefore, the accounting records cannot be deleted before the deadline.
Withdrawal of consent
If the processing of personal data concerning a data subject is based solely on consent, and not, for example, on. to a membership or membership, the registered person may withdraw the consent.
The data subject can appeal against the decision the Data Protection Ombudsman
The data subject has the right to request that we restrict the processing of the disputed data until the matter is resolved.
Right of appeal
The data subject has the right to lodge a complaint with the Data Protection Ombudsman if he or she feels that we are in breach of the applicable data protection legislation when we process personal data.
Contact information for the Data Protection Ombudsman: https://tietosuoja.fi/en/contact-information
6. Regular sources of information
Customer data is obtained on a regular basis:
- On the basis of information provided by the customer when registering as a customer or placing an order.
- On the basis of a contact made by the customer. You can contact us by phone, email, chat, Messenger or any other internet application.
- User experience surveys or interviews with the customer.
- On the basis of information entered by the customer when subscribing to the newsletter
- Based on data observed and derived from analytics on the use of services
7. Regular disclosures of data
We provide some necessary information to third parties to fulfil our obligations in relation to the delivery of orders. These third parties include:
- logistics partners who deliver the consignments to the location of the customer’s choice
- payment intermediary partners
- invoice providers
- product suppliers, in the case of direct deliveries
- customs duty, when products are bought duty-free
- the collection agency, when the invoice becomes due and is transferred for collection
- marketing partners
The partner companies are committed to complying with the requirements of the GDPR.
Where necessary, we will also disclose information at the request of public authorities, if required by law.
8. Duration of processing
- As a general rule, personal data are processed for as long as the customer relationship lasts.
- If you subscribe to our newsletter, you can unsubscribe yourself via a link in each newsletter we send you.
The customer may request the anonymisation or deletion of personal data concerning him/her from our records. For some data, legislation may impose obligations to store the data for longer periods (e.g. the Accounting Act and the Consumer Protection Act).
9. Processors of personal data
Access to personal data is only available to Allsec Oy’s staff who have been trained to handle personal data in a safe and responsible manner. Access to personal data is also available to IT support staff, with whom we have a contractual arrangement to ensure that personal data is processed in accordance with applicable data protection legislation and otherwise appropriately.
All personal data in the register is protected against unauthorised access and the servers are highly secure. Printouts and archives are stored in a locked room with security cameras, accessible only to Allsec Oy’s own employees.
10. Transfer of data outside the EU
Personal data will not be transferred outside the EU or the European Economic Area except in exceptional cases. The only exceptions are orders from outside the EU, in which case the delivery details of the order in question are passed on to the transport company to enable delivery.
11. Use of cookies (“cookies”)
Allsec Oy’s online stores use cookies (small text files placed on the device) to collect information. Cookies can be used to collect information such as the page from which the user has come to the address, the web pages they have browsed, the browser they are using and the IP address of their computer. Cookies are used, for example, for shopping cart functionality, user identification and logging in of registered customers. Cookies allow us, among other things, to display advertisements and content based on your interests and to analyse how well our website and online services are performing. The information collected through cookies is also used for statistical purposes.
Customers of the e-shop have the possibility to prevent the use of cookies by changing their browser settings so that the browser does not allow cookies to be stored. However, refusing the use of cookies may prevent you from using some of the functionality of the online shop.
12. Automatic decision-making
We do not use the information for automated decision-making.
13. Amendments to the Privacy Statement
As our service evolves and as legislation changes or becomes more specific, we reserve the right to amend this Privacy Policy. Significant changes to the Privacy Policy will be notified to customers registered with the service when the Terms are updated.