Privacy Policy

This is the privacy policy for SuVia Company’s SuVia.life website.

1. General Information

 

This Privacy Policy describes what personal data SuVia Company (the “Company”) collects and processes on the SuVia.life website, the SuVia STORIES online media platform, and other services provided by the Company, how the data is processed, for what purposes the data is used, and to whom the data may be disclosed. The Privacy Policy also provides information about the obligations the Company complies with when processing personal data.

 

The company pays special attention to data protection and complies with the EU General Data Protection Regulation (2016/679) (“GDPR”) as well as other applicable data protection laws and best practices in data processing.

 

This Privacy Policy applies to all services provided by the company. In addition to customers’ personal data, this Privacy Policy also applies to the processing of personal data of potential customers. In addition, this Privacy Policy applies to the processing of personal data of the company’s corporate customers, partners, service providers, and representatives of subcontractors.

 

Personal data refers to any information relating to a natural person (“data subject”) that can be used to identify that person directly or indirectly, as defined in the General Data Protection Regulation. Information that cannot be used to directly or indirectly identify the data subject is not personal data.

 

2. Data Controller and Contact Person

 

Data Controller: SuVia Company
Suvi Sjöblom
Business ID: 1738327-1
Address: Forsbyntie 10,
10300 Karjaa

If you have any questions regarding the processing of personal data or this privacy policy, please contact us by email at info@suvia.life.

3. Purposes and Legal Basis for the Processing of Personal Data

 

Personal data is processed for the following purposes, among others:

  • ordering, maintaining, developing, and ensuring the quality of the company's products and services, as well as providing information about them
  • business planning and product development
  • personalized customer service related to our services, targeted customer communications, and monitoring of service usage
  • marketing and targeting marketing efforts toward customers and potential customers
  • organizer/client of a marketing campaign
  • to ensure the security of services and prevent misuse
  • billing

The legal basis for the processing of the data subject’s personal data is the contractual relationship between the company and the data subject, which is based on the ordering of a product or service provided by the company. The processing of personal data is also based on legal obligations, such as accounting requirements. Processing for the purposes of managing customer relationships and direct marketing is based on the company’s legitimate interest.

 

Electronic direct marketing and subscription to the company’s newsletter are based on the data subject’s consent or a legitimate interest. The data subject has the right to withdraw their consent at any time (see “Rights of the Data Subject” below).

4. Categories of personal data processed, data content, and data sources

 

Personal data is primarily collected from the data subjects themselves, for example, during the course of a customer relationship. Data subjects may also have provided information to the company, for example, by subscribing to an electronic newsletter, through social media services, or on the company’s website.

The personal data processed may include, among other things:
– name
– email address
– phone number
– billing information (address, company name, business ID)
– technical identification data (IP address, device type, cookie and analytics data)
– customer relationship and contract-related data (orders, communication history)
– marketing consents and opt-outs

 

Personal data may also be collected from the organization on whose behalf the data subject is acting. In addition, data may be collected in situations permitted by law.

 

The company’s subcontractors, contractors, and partners provide the company with the personal data of registered individuals in situations required by law and contractual obligations.

 

This website uses cookies and similar technologies to ensure the website functions properly, to track visitor statistics, and, where applicable, to deliver targeted advertising. We use, among other services, Google Analytics.
Users can manage their cookie settings through their browser settings and via the Cookiebot cookie banner. Further information on these can be found in the privacy policies of each service used.

5. Retention of Personal Data

 

The company will retain personal data for as long as necessary to fulfill the purposes specified in the privacy policy, unless required by law to retain the personal data for a longer period (for example, responsibilities and obligations related to specific legislation, accounting requirements, or reporting obligations) or unless the company needs the data to establish, exercise, or defend against a legal claim or to resolve a similar dispute.

 

The data retention period and retention criteria vary by category of personal data, depending on the purpose for which a particular category of personal data is used.

 

Personal data is processed for the duration of the customer and contractual relationship and for as long as necessary after the termination of the customer and contractual relationship. Data concerning potential customers is generally retained for one (1) year.

 

In the case of legal entities, the retention of the legal representative’s personal data is contingent on how long the data subject in question serves as the legal representative of the entity.

 

When personal data is no longer needed for the purposes specified above, it will be deleted within a reasonable time.

6. Entities and Recipients That Process Personal Data

 

SuVia Company is the publisher and distributor of SuVia STORIES.

 

Personal data may be disclosed to public authorities in situations required or authorized by law.

 

The company does not disclose the personal data of data subjects for direct marketing purposes.

 

If the company is involved in a merger, business transaction, or other corporate restructuring, it may be required to disclose registered personal data to third parties.

 

As a general rule, data is disclosed to third parties via electronic data transfer connections, but data may also be disclosed by other means, such as by telephone or by mail.

 

Cookies

 

Cookies are small text files that are stored in your browser's memory. A cookie can be stored in your browser for a specified period of time, or it can be deleted immediately after you finish using the service.

 

If you leave a comment on the site, you can choose to save your name, email address, and URL in a cookie. This feature makes the site more user-friendly, as you won’t have to fill out the form again every time you add a comment. The cookie data will be deleted from your browser after one year.

 

If you have an account and log in to our website, we will set a temporary cookie to determine whether your browser supports cookies. This cookie does not contain any personal information and is deleted when you close your browser window.

 

When you log in, we set several cookies that store your login and display settings. Login cookies are deleted within two days. Cookies related to display settings expire after one year. If you select “Remember Me” when logging in, your login information will be stored for two weeks. If you log out, the cookies related to your login will be deleted at that time.

 

If you want to delete cookies, you can do so through your browser. More information about cookies and how to delete them can be found on the Finnish Communications Regulatory Authority’s website.

 

Embedded content from other sites

 

Articles on this site may contain embedded content (such as videos, images, articles, etc.). Opening embedded content imported from other sites is comparable to a visitor going to a third-party site directly.

 

These sites may collect information about you, use cookies, embed third-party tracking cookies, and monitor your interactions with embedded content, including tracking your interactions if and when you are logged in as a user on the site.

7. Transfer of Personal Data Outside the European Union or the European Economic Area

 

As a general rule, personal data is processed within the EU/EEA.
In some cases, however, data may be transferred outside the EU/EEA if the service providers we use (such as analytics and cloud services) are located or store personal data outside the EU/EEA. In such situations, we ensure that the safeguards required by data protection legislation are in place, such as the use of standard contractual clauses approved by the European Commission.

 

If data is transferred outside the European Union or the European Economic Area, the company will ensure an adequate level of protection for personal data by, among other things, agreeing on matters related to the processing of personal data in accordance with data protection legislation, using standard contractual clauses approved by the European Commission.

8. Principles of Personal Data Protection and Security of Processing

 

The company processes personal data in a manner that aims to ensure, in all circumstances, the appropriate security and protection of personal data, including protection against unauthorized processing and accidental loss, destruction, or damage.

 

Appropriate technical and organizational security measures are used in the processing of personal data to ensure its security, such as firewalls, encryption technologies, secure data centers, appropriate access control and access management, and staff training.

 

Contracts and other documents that must be retained in their original form are kept in locked facilities, access to which is restricted solely to authorized parties. Paper copies are destroyed in a secure manner.

 

All parties that process personal data are bound by a duty of confidentiality regarding matters related to the processing of registered personal data, in accordance with the Employment Contracts Act and the confidentiality clauses in their contracts.

 

In accordance with this Privacy Policy, the company may outsource the processing of personal data to service providers; in such cases, the company will ensure, through adequate contractual obligations, that personal data is processed appropriately and in accordance with the law.

9. Rights of Data Subjects

 

Data subjects have the rights guaranteed by data protection laws.

 

The data subject has the right to obtain confirmation as to whether the data subject’s personal data is being processed. The data subject has the right to review and access the data concerning him or her and, upon request, the right to receive the data in writing or in electronic form.

 

The data subject has the right to request the correction of incorrect or inaccurate information. In addition, the data subject has the right, in accordance with applicable data protection laws, to request the deletion of their data. The company will also, on its own initiative, delete, correct, and supplement any personal data that it determines to be incorrect, unnecessary, incomplete, or outdated in relation to the purpose of processing.

 

In accordance with applicable data protection laws, the data subject has the right to request that their data be transferred to another data controller.

 

In addition, in accordance with the conditions set forth in data protection legislation, the data subject has the right to request that the processing of their personal data be restricted. Furthermore, in situations where personal data suspected of being incorrect cannot be corrected or deleted, or where there is uncertainty regarding a request for deletion, the company will restrict access to the data.

 

The data subject has the right to object to the use of their data for a specific type of processing. The data subject has the right to prohibit the disclosure and processing of their data for direct marketing purposes.

 

Requests regarding the rights of data subjects may be made in person, in writing, or electronically and should be addressed to the contact person listed in Section 2 of this Privacy Policy. Identity will be verified before any information is provided. Requests for access will be responded to within a reasonable time and, where possible, within one month of the request being submitted and identity being verified.

If you have any questions regarding the processing of personal data or this privacy policy, please contact us by email at info@suvia.life.

 

If a data subject’s request cannot be granted, the data subject will be notified of the refusal in writing. The company may refuse a request based on a statutory obligation or the company’s statutory right, such as an obligation or requirement related to its services.

 

You can revoke your consent to electronic direct marketing or opt out of direct marketing by contacting the company’s customer service. In addition, you can unsubscribe from the company’s email list at any time by clicking the “Unsubscribe” link in the email.

10. The Right to File a Complaint with the Supervisory Authority

 

A data subject has the right to file a complaint with the data protection authority if the data subject believes that his or her personal data has been processed in violation of applicable law.

 

Office of the Data Protection Ombudsman

Visiting Address: Ratapihantie 9, 6th Floor, 00520 Helsinki
Mailing Address: P.O. Box 800, 00521 Helsinki
Email: tietosuoja@om.fi
Switchboard: 029 56 66700