In accordance with Section 10§ of the Finnish Personal Data Act (523/1999)

Data Controller:
Théhuone
Eerikinkatu 10
00100 Helsinki
0442696601
Y-tunnus: 1992517-7

Contact Person for Register Matters:
Nina Lindgrén
Eerikinkatu 10
00100 Helsinki
0442696601
thehuone@thehuone.com

Register Name:
Théhuone Customer Register

1. Personal data is processed for the following purposes:
- processing and delivering orders
- managing and maintaining customer relationships
- invoicing and accounting
- customer service and communication
- service development and analytics
- direct marketing (only with the customer’s explicit consent, e.g. newsletter subscription, or where permitted by law)

2. The processing of personal data is based on:
- contract (order placement and fulfillment)
- legal obligations (e.g. accounting legislation)
- legitimate interest (customer relationship management and development)
- consent (e.g. marketing communications)

3. The register may include the following information:
- first and last name
- delivery and billing address
- email address
- phone number
- consent to direct marketing
- order and purchase history

4. Personal data is collected directly from the customer, for example:
- when placing an order
- when subscribing to a newsletter
- when registering as a user in the online store

5. Personal data may be disclosed to third parties for the purpose of providing services, such as:
- payment service providers
- delivery and logistics partners
- IT and system service providers

Data is disclosed only to the extent necessary for service implementation. Personal data may also be disclosed to authorities where required by law.

6. Transfers Outside the EU/EEA
Personal data is not generally transferred outside the European Union or the European Economic Area. If such transfers occur, they will be carried out in accordance with applicable data protection laws and appropriate safeguards.

7. Data Protection Principles
- Personal data is stored in secure databases
- Data transmission is protected (e.g. SSL encryption)
- Servers are located in controlled and secure environments
- Access to personal data is restricted to authorized personnel only

8. Data Retention
Personal data is retained only for as long as necessary for the purposes defined above or as required by law. For example, accounting-related data is retained in accordance with applicable accounting legislation.

9. The customer has the right to:
- access their personal data
- request correction or deletion of their data
- restrict the processing of their data
- object to the processing of their data (e.g. marketing)
- withdraw consent (e.g. unsubscribe from marketing communications)

These rights can be exercised by contacting the person responsible for data protection matters.

10. Right to Lodge a Complaint
The data subject has the right to lodge a complaint with a supervisory authority if they believe that their personal data has been processed in violation of applicable data protection laws.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.

11. Changes to This Privacy Policy
We reserve the right to update this privacy policy. The latest version is always available on our website.