This is Nordic Hair’n Beauty Oy’s register and data protection statement in accordance with the Personal Data Act (Sections 10 and 24) and the EU’s General Data Protection Regulation (GDPR). Prepared on 06.03.2018. Latest change 04.02.2021.

1. Registrar

Nordic Hair’n Beauty Oy, Santaradantie 10, 01370 Vantaa
customerservice@nhbeauty.eu

The contact person responsible for the register

Customer register: Rami Virta. 

2. Register name

Nordic Hair’n Beauty Oy customer register

3. Legal basis and purpose of personal data processing

According to the EU’s General Data Protection Regulation, the legal basis for processing personal data is the
controller’s legitimate interest (customer relationship).
Personal data is processed for the maintenance, care and development of service-related customer relationships, analysis, statistics, as well as service production, offering, development, marketing and market research of Nordic Hair’n Beauty and its partners.
The information is not used for automated decision-making or profiling.

4. Data content of the register

Information to be stored in the register is: person’s name, username, password, company/organization, company Y-ID, contact information (phone number, e-mail address, address), information about ordered services and their changes, billing information, other information related to the customer relationship and ordered services. Information is stored as long as required by accounting legislation or other legislation.

5. Regular sources of information

The information to be saved in the register is obtained from the customer, e.g. From messages sent via web forms, by e-mail, by phone, via social media services, contracts, customer meetings and other situations where the customer gives out their information.

6. Regular transfers of data and transfer of data outside the EU or EEA

Information is not regularly disclosed to other parties. Information can be published to the extent agreed with the customer.
Data can also be transferred by the controller outside the EU or EEA. This comes into play when email address data is collected in the MailChimp application and IP address data in the Google Analytics service.

7. Principles of registry protection

Care is taken when processing the register and the information processed with the help of information systems is properly protected. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that stored data as well as server access rights and other data critical to the security of personal data are handled confidentially and only by those employees whose job description it is.

8. Right of inspection and right to demand correction of information

Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

9. Other rights related to the processing of personal data

A person in the register has the right to request the removal of personal data about him from the register (“right to be forgotten”). Those registered also have other rights according to the EU’s General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests must be sent in writing to the controller. If necessary, the registrar can ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).

10. Klarna

We use Klarna as the provider for the checkout process in our store. This means that we may transfer your personal information to Klarna in the form of contact and order details once the checkout transaction is initiated, allowing Klarna to manage your purchase. The transferred personal information will be processed in accordance with Klarna’s own privacy notice.