Privacy and Data Protection Statement

1. Data Controller and Name of the Register

Name of the register: Customer and Marketing Register

Company: LAKE & HIKE OY
Business ID: 3606782-1
Address: Kuhmontie 160
Postal code: 88600
City: Sotkamo, Finland
Telephone: +358 400 635 941
Email: lakeandhike@gmail.com

2. Contact Person Responsible for Register Matters

Company: LAKE & HIKE OY
Name: Jesperi Heino
Address: Kuhmontie 160
Postal code: 88600
City: Sotkamo, Finland
Telephone: +358 400 635 941
Email: lakeandhike@gmail.com

3. Data Protection Officer

Company: LAKE & HIKE OY
Name: Jesperi Heino
Address: Kuhmontie 160
Postal code: 88600
City: Sotkamo, Finland
Telephone: +358 400 635 941
Email: lakeandhike@gmail.com

4. Purpose of Processing Personal Data

Personal data is processed for managing customer relationships, invoicing and marketing.

5. Legal Basis for Collecting and Processing Personal Data

Personal data is collected and processed with the customer's consent or where processing is necessary for the performance of a contract with the customer.

6. Personal Data Stored in the Register

The customer's first name, last name, telephone number and/or email address.

Depending on the method of ordering, the following information may also be collected:

For invoiced customers:

  • Business ID, if applicable

  • Telephone number

  • Email address

  • Street address

  • City

  • Postal code

  • Nationality

For customers using the online store:

  • Telephone number

  • Email address

  • Nationality

7. Retention Period

Personal data is retained for as long as it is necessary to fulfil the contract with the customer or to develop customer service.

8. Regular Sources of Personal Data

Personal data is collected from:

  • The individual themselves

  • Registers maintained by public authorities, within the limits permitted by law (e.g. ytj.fi)

  • For visitor tracking and statistics, anonymised or pseudonymised data is collected using Google Analytics.

9. Regular Disclosures of Personal Data and Transfers Outside the EU or EEA

Personal data is not routinely disclosed outside the company.

Some third-party service or software providers used by the company may store data outside the European Union (EU) or the European Economic Area (EEA).

10. Use of Cookies

Our website uses cookies. A cookie is a small text file that is sent to and stored on the user's computer or other device. Cookies enable the website operator to recognise returning visitors, facilitate the use of the website and collect statistical information about visitors.

This information helps us continuously improve the content and functionality of our website.

Cookies do not damage users' computers or files. We use cookies to provide our customers with information and services that are better suited to their needs.

If a visitor does not wish to allow the use of cookies, most web browsers provide the option to disable cookies through the browser settings.

Please note, however, that some cookies may be necessary for certain parts of our website and services to function properly.

11. Data Security

Data is transmitted over an SSL-secured connection. Electronic data is protected by firewalls, usernames and passwords.

Access to personal data is restricted to persons working for the data controller who require access to the data in order to perform their duties.

12. Automated Decision-Making

No automated individual decision-making within the meaning of Article 22 of the EU General Data Protection Regulation (GDPR) is carried out.

13. Rights of the Data Subject

The data subject has the right to access the personal data concerning them that is stored in the personal data register. A written request for access should be sent, signed, to the person responsible for register matters.

The right of access is free of charge once per year.

The data subject has the right to request the correction or deletion of inaccurate or outdated personal data, as well as the right to data portability.

The data subject also has the right to request restriction of the processing of their personal data or to object to processing in accordance with Articles 18 and 21 of the EU General Data Protection Regulation (GDPR).

The data subject has the right to withdraw previously given consent to the processing of their personal data. They also have the right to lodge a complaint with the competent supervisory authority concerning the processing of their personal data.

The data subject also has the right to prohibit the use of their personal data for direct marketing purposes.