Privacy Policy
ELNAF Oy – Privacy Policy
Effective Date: 20.04.2025
1. Definitions
For the purposes of this Privacy Policy, the following terms shall have the following meanings:
- Personal Data: Information that can identify you, directly or indirectly, such as your name, contact details, location data, or online identifiers.
- Processing: Any action we take with your Personal Data, including collecting, recording, organizing, storing, changing, using, sharing, and deleting it.
- Purpose: The reason we collect and use your Personal Data.
- Controller: The entity that decides how and why your Personal Data is processed. In this case, it is ELNAF Oy.
- Recipient: A party to whom your Personal Data is disclosed.
- Processor: A party that processes your Personal Data on behalf of the Controller.
- ELNAF: Refers to ELNAF Oy, a Finnish private limited company.
- Website: Refers to the ELNAF Oy website, elnaf.fi.
2. Data Controller
The Personal Data Processing outlined in section 5 is performed under the responsibility of:
- ELNAF Oy
- Punttelintie 27, 48310 Kotka, Finland
- Business ID: 3477134-8
- Email: sales@elnaf.fi
- Phone: +358 50 313 9854
3. Categories of Personal Data Processed
We may collect and process the following categories of personal data:
- Contact Information: Name, email address, phone number, postal address, and any other contact details you provide.
- Order Information: Details about the products you purchase, order dates, order status, shipping address, billing address, payment method, transaction details, and any other information related to your orders.
- Website Usage Data: IP address, browser type, operating system, referring URLs, pages visited, date and time of access, browsing activity, search queries, and other data related to your interaction with our Website, collected through cookies and similar technologies.
- Communication Data: Records of our communications with you, including emails, chat logs, phone call recordings (where applicable and with consent if required by law), and any other correspondence.
- Marketing Preferences: Your preferences for receiving marketing communications from us, including subscriptions, opt-ins, and opt-outs.
- Business Customer Data: Company name, contact person details, job title, business address, industry, and other information related to your business relationship with ELNAF Oy.
- Product Data: Information related to the products you purchase or inquire about, such as serial numbers, configurations, specifications, and usage information, to the extent it constitutes personal data.
- Support Data: Information you provide when you request customer support, including the nature of your request, any troubleshooting steps taken, and contact details.
- Cookies and Tracking Data: Data collected through cookies, pixel tags, web beacons, and similar technologies, including browsing behavior, preferences, and interactions with our Website, as detailed in our Cookie Policy.
- Survey and Feedback Data: Information you provide when participating in surveys or providing feedback on our products and services.
- Other Information: Any other personal data you voluntarily provide to us.
4. How We Collect Personal Data
We collect personal data in the following ways:
- Directly from You: When you:
- Place an order for our products.
- Subscribe to our newsletter or marketing communications.
- Contact us through email, phone, chat, or contact forms.
- Fill out forms on our Website.
- Participate in surveys, contests, or promotions.
- Provide feedback or reviews.
- Communicate with our customer support.
- Automatically: When you browse our Website, we collect certain information automatically through cookies and similar tracking technologies.
- From Third Parties: We may receive personal data from third-party sources, including:
- Payment processors (to verify and process payments).
- Shipping companies (to obtain delivery status and tracking information).
- Analytics providers (to analyze website traffic and usage).
- Marketing partners (to conduct marketing campaigns, with your consent where required).
- Public sources (such as company registries, to verify business customer information).
- Social media platforms (if you interact with our social media pages).
5. Purposes of Processing Your Personal Data and Legal Basis
We use your personal data for various purposes and according to applicable legal bases, such as contractual necessity, legitimate interests, legal obligation, or consent.
| Processing Activity | Purpose | Legal Basis | Data Retention |
|---|---|---|---|
| Order Fulfillment | To process your orders, arrange for shipping, handle invoicing, verify payments, and provide customer support related to your purchases. | Contractual Necessity | 5 years for accounting purposes |
| Website Operation and Improvement | To ensure the proper functioning of our Website, personalize your experience, analyze website usage to improve our services, and for technical administration. | Legitimate Interests | 2 years |
| Communication | To respond to your inquiries, provide information about our products and services, send you order updates and confirmations, and provide customer service. | Contractual Necessity, Legitimate Interests | 2 years |
| Marketing | With your consent (where required), to send you promotional emails and newsletters about our products, offers, and updates. | Consent | As long as consent is valid |
| Customer Relationship Management | To manage our relationship with you, including providing customer service, handling complaints, and personalizing our communications. | Legitimate Interests | As long as consent is valid |
| Legal Obligations | To comply with applicable laws and regulations, including accounting and tax requirements, and to respond to legal requests. | Legal Obligation | 2 years |
| Fraud Prevention and Security | To detect and prevent fraudulent activities, unauthorized access, and ensure the security of our Website, systems, and transactions. | Legitimate Interests | 1 year |
| Business Customers | To manage our relationship with Corporate Customers, process business orders, verify business information, and facilitate communication. | Contractual Necessity, Legitimate Interests | 2 years |
| Product Improvement | To analyze the use of our products and services and gather feedback to improve and develop new products. | Legitimate Interests | 2 years |
| Surveys and Feedback | To collect and analyze your feedback and opinions on our products and services through surveys and feedback forms. | Consent, Legitimate Interests | As long as consent is valid |
6. Disclosure of Your Personal Data
We may disclose your personal data to the following categories of recipients:
- Service Providers: Third-party companies that provide services on our behalf and help us operate our business, such as:
- Payment processors (e.g., Stripe, PayPal)
- Shipping companies (e.g., Posti, DHL)
- IT service providers (e.g., hosting companies, software providers)
- Marketing agencies
- Analytics providers (e.g., Google Analytics)
- Customer relationship management (CRM) providers
- Email service providers
- Business Partners: Where necessary to fulfill your order or provide services, such as manufacturers or distributors who ship products directly to you.
- Legal Authorities: When required by law or in response to a valid legal request, such as a court order, government inquiry, or to comply with legal obligations.
- In Connection with Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity, subject to applicable confidentiality agreements.
- Affiliated Companies: We may share your data with our subsidiaries or affiliates for internal business purposes, subject to this Privacy Policy.
7. International Transfers of Your Personal Data
If we transfer your personal data to recipients located outside the European Economic Area (EEA) in countries that do not provide an adequate level of data protection, we will ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection laws. These safeguards may include:
- Standard Contractual Clauses: Using Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy Decisions: Transferring data to countries that the European Commission has determined to provide an adequate level of protection.
- Explicit Consent: In specific situations, we may transfer data based on your explicit consent.
We will provide you with information about the specific safeguards used upon request.
8. Data Security
We have implemented appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized access, disclosure, or use. These measures include:
- Access Controls: Limiting access to personal data to authorized personnel on a need-to-know basis.
- Regular Security Assessments: Conducting regular security assessments and audits to ensure the effectiveness of our security measures.
- Employee Training: Our employees receive regular training on data protection and secure handling of personal data.
- Data Breach Procedures: We have procedures in place to detect, report, and respond to any data breaches, including notifying the appropriate authorities and affected individuals where required by law.
9. Data Retention
We will retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including for the duration of our business relationship, to comply with our legal obligations, to resolve disputes, and to enforce our agreements.
The specific retention periods are determined based on the following criteria:
- Type of Data: Different categories of data have different retention needs.
- Purpose of Processing: Data collected for specific purposes will be retained for the duration of that purpose.
- Legal Requirements: We will retain data as long as required by applicable laws and regulations.
- Limitation Periods: We will retain data as long as necessary to establish, exercise, or defend legal claims.
- Business Needs: We may retain data for a reasonable period to manage our business operations.
After the retention period expires, we will securely delete or anonymize your personal data.
10. Your Rights
You have the following rights regarding your personal data:
- Right of access: You may obtain a copy of the Personal Data processed by ELNAF Oy.
- Right to rectification: If you believe that your Personal Data are incorrect or incomplete, you may request a rectification.
- Right to erasure: In certain cases, provided for by law, you may request that your Personal Data be erased, in particular where the Processing operation is exceptionally based on your consent and you wish to withdraw that consent or where it appears that your Personal Data are no longer necessary in relation to the Purposes for which they were collected or processed. However, this right is not unconditional and ELNAF Oy may have a legal basis or legitimate reason to keep your Personal Data.
- Right to object: In certain cases, you may object to the Processing of your Personal Data on grounds relating to your personal situation. However, this right is not unconditional and ELNAF Oy may reject your request for compelling legitimate reasons.
- Right to restrict Processing: You may also request that the Processing of your Personal Data be restricted (for example, suspended) if (i) your Personal Data are incorrect, (ii) you have exercised your right to object or (iii) the data are no longer needed for the processing operation but are still required to establish, exercise or defend your legal rights.
- Right to data portability: When this right applies, you have the right to receive the Personal Data that you have provided or, where technically feasible, to transmit those data to a third party.
- Right to give instructions regarding the use of your Personal Data after your death: You have the right to give ELNAF Oy instructions regarding the use of your Personal Data after your death.
- Right to withdraw your consent: if the personal data processing is based on your consent.
You can exercise your rights by contacting us at the details in Section 2.
11. Cookies and Similar Technologies
Our Website uses cookies and similar technologies to collect information about your browsing activity, preferences, and interactions with our Website. We use cookies to:
- Enable the basic functionality of the Website
- Personalize your experience
- Analyze website traffic and usage
- Target our marketing and advertising
We use session cookies (which expire when you close your browser) only. The following categories of cookies are used on our Website:
- Strictly Necessary Cookies: These cookies are essential for the operation of our Website and enable you to use its features. They do not require your consent.
- Performance Cookies: These cookies collect information about how you use our Website, such as which pages you visit and any errors you encounter. This information helps us improve our Website. We use Google Analytics for this purpose. Google Analytics collects data on the number of times a user has visited the website, as well as data for the first and most recent visit. Google processes this data in Europe if you are a user connected from a European IP address.
- Functionality Cookies: These cookies allow our Website to remember your preferences (e.g., language settings, login information) and provide enhanced features.
- Targeting/Advertising Cookies: These cookies are used to deliver advertisements that are more relevant to you and your interests. They may also be used to measure the effectiveness of our advertising campaigns. We use:
- Remarketing with Google: This service links tracking activity performed by Google Analytics and its cookies to the Google Ads advertising network and the DoubleClick cookie. Google assigns an ID to the website visitor, stored in a cookie, to personalize advertisements. Data processing takes place in Europe if you are a user connected from a European IP address.
You can manage your cookie preferences through your browser settings. Most browsers allow you to block or delete cookies. However, please note that blocking certain cookies may affect your ability to use some features of our Website.
For more information about the specific cookies we use, their purposes, and how you can manage your cookie preferences, please refer to our separate Cookie Policy.
12. Links to Third-Party Websites
Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of these websites. We encourage you to review the privacy policies of any third-party websites you visit.
13. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices or legal requirements. We will post any changes on our Website and update the "Effective Date" at the top of this policy. We encourage you to review this Privacy Policy periodically. If we make significant changes, we will also provide a more prominent notice, such as an email notification or a website banner.