Privacy policy compliant with the General Data Protection Regulation, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
Sonado Oy, business ID 2654380-4
Sirkkalankatu 13, 20500 Turku
The data are stored in the Shuriken ERP system of Creaction Finland Oy. Creaction Finland Oy is responsible for the implementation and administration of the system, for data protection, and for data backups. All data are stored and processed in the same filing system (i.e. in one database).
Fantasy Nails / Sonado Oy customer, order, invoicing and marketing data filing system.
We comply with the following principles relating to the processing of personal data:
Personal data shall be
a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
Data are processed primarily within the EEA. Data may be transferred outside the EEA when an order is delivered outside the EEA (the delivery details are passed to the transport company) or when a web analytics provider (e.g. Google, Meta) processes data outside the EEA. Such transfers rely on appropriate safeguards, such as the EU-U.S. Data Privacy Framework or the EU standard contractual clauses. Data are stored until the customer asks us to delete them. Data are stored for example for web analytics (statistical reasons) and to make placing new orders easier (the customer's interest).
Customer data are stored for the following purposes: communicating with customers, maintaining and developing the customer and trade relationship, and reporting and statistics. Fantasy Nails / Sonado Oy uses this and other data obtained during the customer relationship to plan and target its products and services.
Personal data are used within the limits allowed and required by data protection legislation (the General Data Protection Regulation and the Finnish Data Protection Act). Data are not disclosed to outside parties except as described in the section Data disclosure and transfer.
The e-mail addresses of those who have subscribed to the newsletter are used for delivering the newsletter. The information given in the contact form is used for replying to the contact request.
The customer register consists of several separate files created based on their main purpose. Together, the data in these files constitute the following customer-specific data sets:
Personal data are deleted at the customer's request.
Data are disclosed to outside parties only to the extent required for fulfilling the order or by a legal obligation. Recipients include, for example, payment service providers, credit information companies, transport companies, and public authorities. Due to data processing arrangements, some of the data may reside with our IT subcontractors.
Contact and customer data are collected at the beginning of and during the customer relationship from what the customer communicates to the controller. The customer relationship begins when the customer registers in the service, places an order, subscribes to direct marketing, or makes a purchase. A customer relationship can also be started at the customer's request, for example based on a telephone conversation.
Consent to electronic direct marketing (e-mail and text message marketing) is asked separately, as required by data protection legislation. Information on the customer's creditworthiness at the moment of ordering is obtained from the system of Paytrail Oyj (business ID 2122839-7), that of Aurajoki Nordic Oy (1998514-5) and/or that of Suomen Asiakastieto Oy (0111027-9).
We use analytics and advertising tools that process personal data about your visit. Depending on your cookie choices, these tools may receive your IP address, browser and device information, cookie identifiers and the pages you view. When you place an order, they may also receive your e-mail address, name, telephone number, postal code and town. Contact details are hashed before they are sent, which hides their content but does not make them anonymous.
The data are used to measure how our marketing performs, to attribute purchases and to target advertising. We may use the following tools and services:
These providers may process the data outside the EEA under appropriate safeguards, such as the EU-U.S. Data Privacy Framework or the EU standard contractual clauses. You can change the choices that control this processing in the cookie settings at the end of this page.
Processing of personal data requires a legal basis. We process personal data on the basis of consent (e.g. subscribing to the newsletter), contract (e.g. placing an order), the controller's legal obligation (e.g. acquisition and possession of products subject to authorisation), protection of vital interests (e.g. participation in a course that requires information on personal health), or the legitimate interest of the controller or a third party (e.g. web analytics).
We use cookies to help us develop our website for you. The purpose of cookies is to improve and speed up the shopping experience. Cookies can also be used to provide better offers and more personal product recommendations. A cookie is a small text file that a web server saves on the user's hard drive. Some website functions may require accepting cookies. The user's web browser probably accepts cookies by default, but the user can also block cookies in the browser settings or remove them from the browser after use. More information on browser-specific settings is available in the browser manufacturer's instructions.
Access to the personal data filing system requires special access rights. Access is limited to the data a person needs in their work, and it requires personal login credentials. The customer register and the hardware processing it are located in closed server rooms. Hardware and software are updated regularly and appropriately, and possible threats are reacted to immediately. To prepare for incidents, the data are backed up regularly. The system is protected against outside connections with a firewall.
Personnel processing customer register data are bound by confidentiality. Data are disclosed only based on a legal notification obligation, such as at the customer's own request or at a public authority's request based on law.
The data subject has the right to:
Requests are addressed to the controller. The data subject also has the right to lodge a complaint with a supervisory authority; in Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi).