Privacy Policy

Last updated: 30 January 2026

This Privacy Policy describes how Asude Oy (“we”, “us”, “our”) processes personal data in accordance with the EU General Data Protection Regulation (GDPR), the Finnish Data Protection Act (Tietosuojalaki 1050/2018), and applicable e-commerce and consumer protection legislation.

1. Data Controller

Company name: Asude Oy
Business ID: 3382246-5
Address: Pyynikintie 5M, 00710 Helsinki, Finland
Email: info@kierratyssankari.fi

Phone: +358 413 146 570

Our Data Protection Officer can be contacted via the same email.

2. Personal Data We Collect

We collect only data necessary for defined and lawful purposes.

2.1 Data You Provide

Name, surname

Personal identity number (for financing or legal verification if applicable)

Email address, phone number

Billing and delivery address

Customer account information: customer number, account creation date

Order and return history, including product, price, discount, and delivery details

Customer service communications (chat, email, phone)

Payment reference data (payments processed via external providers; card numbers are not stored)

Company / business customer details, if applicable: company name, contact person, identifiers

2.2 Data Collected Automatically

IP address (anonymised where possible)

Device and browser information

Website usage data (pages visited, time spent, clicks)

Cookie identifiers

Social login data (Google, Facebook) if used

2.3 User-generated Content

Customer-submitted photos, reviews, or social media tags may be displayed on our website or social channels if consented.

By submitting content, you grant Asude Oy a non-exclusive, royalty-free license to use your content.

3. Legal Bases for Processing (GDPR Article 6)
Purpose Legal Basis
Order processing & delivery Contract (Art. 6(1)(b))
Customer service Legitimate interest (Art. 6(1)(f))
Accounting & tax obligations Legal obligation (Art. 6(1)(c))
Marketing emails and newsletters Consent (Art. 6(1)(a))
Website analytics, personalization Consent (Art. 6(1)(a))
Customer community engagement / social content Consent (Art. 6(1)(a))
4. Cookies and Tracking Technologies

We use cookies only after explicit consent, except for strictly necessary cookies.

4.1 Cookie Categories

Necessary cookies – required for website functionality

Analytics cookies – used to improve our services

Marketing cookies – used only with consent

Personalization cookies – for recommending relevant products

Consent can be withdrawn anytime via cookie settings. Browser-based cookie blocking is possible, but may reduce website functionality.

5. Analytics and Marketing Tools

We may use the following tools only with consent:

Google Analytics (IP anonymization enabled)

Facebook / Meta Pixel

Hotjar (IP anonymized)

We do not transfer data to non-GDPR-compliant jurisdictions unless appropriate safeguards are in place.

6. Data Sharing and Processors

We share data only with trusted processors under GDPR-compliant agreements:

Payment providers (e.g., Paytrail, Visma Pay)

Logistics partners

Hosting and IT service providers

Accounting service providers

Social media platforms (for content sharing)

Data is never sold to third parties. Sharing occurs only when necessary for service delivery, legal obligations, or with explicit consent.

7. International Data Transfers

Personal data is processed within the EU/EEA.

Transfers outside the EU/EEA are allowed only with:

Adequacy decision by the European Commission, or

Standard Contractual Clauses (SCCs) and additional safeguards

8. Data Retention

We retain personal data only as long as necessary:

Orders and invoices: 6–10 years (accounting law)

Customer accounts: until deletion request or prolonged inactivity

Marketing data: until consent is withdrawn

Customer-submitted content: until withdrawal of consent

Long-term warranty or service data: up to 25 years if required to maintain guarantees or service records

Log files and customer service recordings:

Phone recordings: 3 months

Chat logs: 12 months, then automatically deleted

9. Data Security

We apply technical and organisational measures:

SSL/TLS encryption

Role-based access control and unique credentials

Staff trained on GDPR-compliant data handling

Secure EU-based hosting

Firewalls, backups, and intrusion protection

Confidentiality obligations for all employees and contractors

10. Your Rights (GDPR Articles 12–22)

You have the right to:

Access your data and obtain a copy in a commonly used electronic format

Correct inaccurate or incomplete data

Delete personal data (with consideration for legal or warranty obligations)

Restrict processing or object to processing (e.g., for marketing or profiling)

Withdraw consent at any time

Data portability

Annual free access request

Requests must be sent to info@kierratyssankari.fi
. Identity verification may be required. Responses are provided within one month.

11. Right to Lodge a Complaint

You may lodge a complaint with the Finnish supervisory authority:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
www.tietosuoja.fi

12. Updates to This Policy

We may update this Privacy Policy. The latest version is always available on our website.

13. Contact

For privacy-related questions:

Email: info@kierratyssankari.fi

Postal address: Pyynikintie 5M, 00710 Helsinki, Finland