Privacy Policy
PRIVACY POLICY / Record of processing activities
EU General Data Protection Regulation (2016/679), Articles 13, 14, 15, 16, 17, 18, 20, 21 and 30
Drawn up: 24.05.2018
Updated: 10.06.2026
We may update or amend this privacy policy at any time. This policy is in force from 25 May 2018.
1. Data controller
Northern Art Photos / HK Production (business ID: 2153883-8)
Ulappakatu 1 G LT 20, 02320 Espoo, Finland
tel. 044 2399 856
2. Contact persons responsible for register matters
Contact person Harri Kyllönen
Northern Art Photos / HK Production
Ulappakatu 1 G LT 20
02320 Espoo, Finland
tel. 044 2399 856
Email: asiakaspalvelu@artphotos.fi
3. Name of the register
Northern Art Photos customer and contact information register.
4. Purpose of processing personal data / recipients of personal data (or
categories of recipients) / legal basis for processing personal data
The purpose of the register is to process the information needed to handle Northern Art Photos customers' orders and for customer communication. On a case-by-case basis, we may transfer contact details related to order fulfilment to third parties who, as contract manufacturers, are responsible for producing and delivering the products to the end customer. We may also disclose information to parties that assist in the technical implementation of the processing purposes, such as in storing data or maintaining servers. The data stored in the online store is kept in the server halls of the Finnish company Hostaan Oy in Helsinki. Hostaan Oy stores and processes personal data in accordance with the EU GDPR and the current Personal Data Act (523/1999).
Further information: https://www.hostaan.fi/tietosuojaseloste/
5. Data content of the register
● Full name
● Company (if applicable)
● Phone
● Street address
● Postal code and town
● Business ID (if applicable)
● Consent to marketing communications (yes or no)
● Billing details, where applicable, including e-invoicing or email invoicing address
As well as information stored only in the online store database:
● Registration time (date and time)
● Last login (date and time)
● Newsletter subscription (yes / no)
● Account status (active / blocked)
● Any administrator notes, such as special requests made by the customer
● Communication with the online store
● Order history and purchase statistics
● Coupons
● Any link to a public social media profile
● Shopping carts
● Landing pages and the IP address used
● Customer group
6. Data sources
Information provided by the data subject themselves.
7. Disclosure of data
When a customer orders a product to be shipped (e.g. by post, Matkahuolto, etc.), the order's delivery details (recipient's name, address, phone number and possibly email address) are passed on to the order's transport company (Posti / Matkahuolto) and to the contract manufacturer of the ordered product, who delivers the product directly to the customer. The phone number is used for advance notification of the delivery and for arranging a possible delivery time. This applies only to those manufacturers whose products are included in the order. All of our manufacturers also meet the GDPR data protection requirements. See more detailed information about the contract manufacturers' products in the table below:
Contract manufacturers:
|
Products |
contract manufacturer |
Business ID |
|
Premium canvas prints |
Artshop Finland Oy |
2093601-7 |
|
HP wallpapers, stickers, picture elements and other special products |
Mainoste Print Oy |
1885625-3 |
|
Most photo gift products |
Color-Kolmio Oy |
0140082-3 |
|
Jigsaw puzzles |
Palmulahti Oy |
2406991-8 |
The contract manufacturers have committed to complying with the terms of this register. The manufacturers do not disclose or use the customer's data for any marketing purposes, nor do they pass the data on to others. The manufacturers also do not store or collect customer data.
Transport companies:
Oy Matkahuolto Ab (0111393-9)
Policy:
https://www.matkahuolto.fi/fi/hyva-tietaa/rekisteriselosteet/pakettipalvelujen-lahetystiedot/
Posti (1531864-4)
Policy:
https://www.posti.fi/henkiloasiakkaat/apu-ja-tuki/tietosuoja.html
8. Transfer of data outside the EU or the EEA and the principles of data
protection
Northern Art Photos does not transfer data outside the EU or the EEA.
Northern Art Photos / HK Production is responsible for maintaining the register. Access to the maintenance of the data is granted only to the company's employees where their duties so require. Northern Art Photos / HK Production is responsible for and centrally manages the rights of access to the register in accordance with its data security guidelines.
9. Retention period of personal data
The data controller retains personal data until further notice and for the duration of the customer relationship. At a minimum, however, for as long as it takes to deliver the order's shipments, or for the time required for invoicing and for verifying payment of the invoice.
10. Principles of register protection
A. Manual material
Manual material is stored carefully so that outsiders have no access to it. Manual material is destroyed when it is no longer needed.
B. Electronically stored data
The data is protected technically and physically so that, apart from the register administrators, outsiders have no access to the data. Each user of the system has their own username and password.
Manual material and the means of accessing electronically stored data are located in premises with continuous remotely monitored camera surveillance, motion detectors and alarm systems.
11. Right of access and its implementation, the right to transfer data
from one system to another
Having stated the particulars necessary for locating the information, the data subject has the right to be told what information concerning them has been stored in this register, or that the register contains no information concerning them. At the same time, the data controller must inform the data subject of the register's data sources and of the purposes for which the register's information is used and to whom it is disclosed.
A data subject who wishes to inspect information concerning them in the manner described in the previous paragraph must submit a request to this effect to the person responsible for this register at Northern Art Photos / HK Production, in a document signed in their own hand or otherwise authenticated in an equivalent manner. Northern Art Photos / HK Production may charge a service fee for compiling the information, as this requires considerable work.
The data subject has the right to receive the personal data concerning them that they have provided to the data controller, in a commonly used and machine-readable format, and the right to transmit that data to another data controller, where the processing is based on consent or on a contract between the data controller and the data subject, and the processing is carried out automatically.
12. Rectification, erasure and restriction of processing of data
The data subject has the option of changing the information they have provided themselves, by logging in to the online store or by requesting it in writing (by email or letter to customer service).
The data controller must, without undue delay, on its own initiative or at the data subject's request, rectify, erase or supplement any personal data in the register that is inaccurate, unnecessary, incomplete or out of date with regard to the purpose of the processing. The data controller must also prevent the spread of such data if it could endanger the data subject's right to privacy or their rights.
The data controller must also, at the data subject's request, restrict processing if the data subject has contested the accuracy of their personal data, if the data subject has alleged that the processing is unlawful and has opposed the erasure of the personal data and instead requested that its use be restricted, or if the data controller no longer needs the personal data in question for the purposes of the processing but the data subject states that they need it for the establishment, exercise or defence of a legal claim, or if the data subject has objected to the processing of personal data under the Data Protection Regulation pending verification of whether the data controller's legitimate grounds override those put forward by the data subject. If the data controller has restricted processing on the grounds mentioned, the data controller must notify the data subject before the restriction on processing is lifted.
If the data controller does not accept the data subject's request for the correction of data, it must provide a written certificate of the matter. The certificate must also state the reasons for which the request was not accepted. The data subject may refer the matter to the Data Protection Ombudsman.
The data controller must notify of the correction of data the party to whom the data controller has disclosed or from whom the data controller has received the erroneous personal data.
There is, however, no obligation to notify if doing so is impossible or requires unreasonable effort.
Requests for correction must be addressed to the representative designated by the data controller in section 2, see contact details above.
It should be noted that the data controller may have a statutory or other right not to erase the requested data. The data controller has an obligation to retain accounting material for the period (10 years) specified in the Accounting Act (Chapter 2, section 10). For this reason, accounting-related material cannot be erased before that period has expired.
13. Marketing
The customer's information is not used or disclosed for marketing purposes. If they wish, the customer can subscribe to a newsletter, which is sent once or twice a month. The newsletter contains information about current products, offers, news and information about upcoming products. The newsletter can be cancelled at any time.
14. Policies of the online store's payment intermediaries
The online store uses payment intermediaries that safeguard the payment transaction for the customer (consumer/business) and for the seller (the online store). Once the payment method has been selected, the personal data is transmitted securely to the service provider in order to confirm the payment transaction. The payment intermediary stores the basic details in its system to secure the order and the financial transaction. Read the detailed description in section 14.1.
14.1 Visma Pay
Information on the processing of personal data for Visma Pay users
Visma Pay (Paybyway Oy), business ID 2486559-4, part of the Visma group (hereinafter "Visma Pay"), processes your personal data (hereinafter "Data") in order to carry out the payment transaction you have requested (hereinafter the "Purpose"). The processing of the Data is governed by the EU General Data Protection Regulation (the "General Data Protection Regulation"). Visma Pay is a payment institution supervised by the Finnish Financial Supervisory Authority (Fiva). Visma Pay acts as the data controller for the Data.
The Data consists of the information needed to carry out your payment transaction, e.g. credit card details, if you chose a credit card as the payment method. You must provide the Data to Visma Pay so that Visma Pay can process the payment transaction in the manner you have requested. The legal basis for processing the Data for this Purpose is that the processing is necessary in order to realise Visma Pay's legitimate interest in processing the payment, and so that you can thereby pay for the goods and/or services you have purchased. In addition, Visma Pay is subject to a number of other laws and regulations concerning, among other things, the prevention of money laundering. These laws also oblige Visma Pay to process the Data, in which case the legal basis for processing is the necessity of complying with a statutory obligation to which Visma Pay is subject. If you do not provide the Data, Visma Pay may not be able to process your payment transaction.
Visma Pay may disclose data to other companies in the Visma group in order to process the Data for the same Purpose. The Data may also be disclosed to other companies needed to fulfil the Purpose, for example to your own bank, depending on the payment method you have chosen. These other companies may be located outside the EU/EEA area. If, according to the European Commission, the country in question does not provide an adequate level of data protection, the transfer of personal data is based on the standard contractual clauses on data protection approved by the European Commission for the transfer of personal data outside the EU/EEA area, see Articles 45–46 of the General Data Protection Regulation. A copy of these standard contractual clauses can be read at
ec.europa.eu/info/law/law-topic/data-protection_fi
Visma Pay processes the Data for as long as the laws and regulations that Visma Pay complies with require it to continue the processing. In some cases, where the data is no longer needed for this purpose, the processing may cease earlier. In that case, the Data is deleted from all of the Visma group's databases.
You can read a more comprehensive privacy policy on Visma's website: www.visma.fi/yksityisyydensuoja/etusivu
If you have any questions about how Visma Pay processes the Data, please contact us by email at helpdesk@vismapay.com or by phone at 09 315 42 037 (weekdays 9 a.m.-5 p.m.). You can also contact Visma Pay's Data Protection Officer by email at helpdesk@vismapay.com. You can use these contact details if you wish to exercise the rights afforded to you as a data subject under the General Data Protection Regulation. Please note that the rights based on the General Data Protection Regulation are not absolute. For this reason, invoking a particular right does not necessarily result in action being taken. Under the General Data Protection Regulation you have, among others, the following rights:
- Right of access – Under Article 15 of the General Data Protection Regulation, you have the right to obtain access to the Data as well as certain information about the processing. This information is included in this document.
- Right to rectification – Under Article 16 of the General Data Protection Regulation, you have the right to have inaccurate Data concerning you rectified and incomplete data completed.
- Right to erasure – In certain situations, under Article 17 of the General Data Protection Regulation, you have the right to have the Data erased. This is known as the "right to be forgotten".
- Right to restriction of processing – In certain situations, under Article 18 of the General Data Protection Regulation, you have the right to restrict the processing of the Data carried out by Visma Pay.
- Right to data portability – Under Article 20 of the General Data Protection Regulation, you have the right to receive the Data from Visma Pay in a structured, commonly used and machine-readable format (or the right to transfer it to another data controller).
- Right to object – Under Article 21 of the General Data Protection Regulation, you have the right to object to certain data processing operations carried out by Visma Pay, for example processing operations based on Visma Pay's legitimate interest. In addition, you have the right to lodge a complaint with a supervisory authority, in Finland the Office of the Data Protection Ombudsman.