The body responsible for the collection and processing of personal data is By Pia’s Oy (hereinafter “BYPIAS”). As the body responsible, BYPIAS can be reached by contacting BYPIAS Customer Service:
BYPIAS Customer Service
Address: Lautamiehentie 1C, 02770 Espoo, Finland
Tel.: +358 50 361 4232
When ordering products from BYPIAS web shop, only the necessary data to implement your order is collected in BYPIAS Customer Register.
A customer also can, in connection with an order or otherwise, register as customer of BYPIAS whereby the customer agrees to include his/her personal data in BYPIAS Customer Register. This simplifies processing customer’s further orders and allows customer to follow his/her orders made after such registration.
Customer can also become BYPIAS VIP Customer by expressly providing his/her consent to receive newsletters and information on offers to his/her email. The customer thereby agrees that BYPIAS collects the necessary contact information to its VIP Customer Register and processes the data in accordance with the data processing principles set forth herein.
THE LEGAL BASIS FOR AND PURPOSE OF PROCESSING PERSONAL DATA
The basis for processing personal data are our legitimate interests, such as customer relationship management, performance of contracts and invoicing, consent of customer and/or legal obligation.
Personal data collected in BYPIAS Customer Register is processed in connection with customer orders, billing, mailing, customer contacts, development of services, reporting, marketing and other measures relating to customer relationship management. The purchase and other related data in BYPIAS Customer Register may also be used for profiling and targeting offers, promotions, customer communication and other marketing measures to customers. The personal data collected in BYPIAS VIP Customer Register is processed for the purpose of sending newsletters and in connection with participation in competitions, lotteries or other marketing campaigns.
BYPIAS Customer Register includes customer relationship and contractual management related information, such as first and last name, address, telephone number, e-mail address, purchase information, feedback and other customer communication, username and password as well as optional delivery addresses of the Customer.
BYPIAS VIP Customer Register includes e.g. name, e-mail, information on marketing permissions or prohibitions, information on participation to marketing campaigns (e.g. lotteries) as well as information on ordering of newsletter.
The Company does not collect bank or credit card information of customer.
REGULAR COLLECTION OF DATA
Data is collected on the basis of notifications received from the Customer and on the basis of purchase and customer communication data in the Company Data System.
DISCLOSURE OF DATA OR TRANSFER OF DATA TO OUTSIDE THE EU OR EUROPEAN ECONOMIC AREA
The personal data contained in the Customer Registers is not disclosed outside BYPIAS, unless so required by applicable laws or to such subcontractors who participate e.g. in organizing direct or other marketing, administration of information systems of the Company or in the processing of purchase orders, such as mailing of products or payment processes.
If our operations so require, we may transfer personal data to external third parties and/or outside the EU/ETA. In such case, we will ensure that the personal data is appropriately protected and that privacy legislation in force from time to time is applied.
PRINCIPLES FOR PROTECTING THE REGISTERS
Personal data contained in BYPIAS Customer Registers of BYPIAS are confidential. The Registers are held in electronic form and are appropriately protected with firewalls and by using other technical protection. Only named employees have access to the use and maintaining of the password protected Registers. The operators of the Registers are bound by confidentiality obligations.
We store personal data for the necessary time considering the purpose for which it was collected as well as applicable legislation. We take reasonable measures to ensure that inaccurate and outdated information will be corrected or erased as soon as possible.
RIGHTS OF CUSTOMERS
The customer has a right to request access to his/her personal data recorded in the Customer Registers. If the personal data of the customer is inaccurate, the customer can request that all inaccurate data be either corrected or removed. The Customer also has a right to object processing of his/her personal data on the basis of our legitimate interests, direct marketing and profiling in relation thereto. The customer has also the right, according to the EU’s General Data Protection Regulation, to request restricting of the processing of personal data or request the removal of his/her data.
You can opt-out of direct marketing by following the instructions provided in connection with every newsletter and you can also withdraw your consent. The customer has the right to receive his/her personal data in a machine-readable format and request the transfer of said data to another data controller.
Any requests relating to the rights of customers mentioned above can be delivered in writing to BYPIAS Customer Service (contact information above). BYPIAS will comply with the requests in accordance with applicable legislation and by observing any mandatory provisions of law restricting the scope of such rights. The customer can also file a complaint with or request further information from the relevant Data Privacy Authorities.