Privacy Policy
This privacy policy provides information exclusively about the customer register of Yritys Oy's Johku store and the principles governing the processing of data contained therein.
We may occasionally change our data protection practices and this privacy policy. We recommend that you review our data protection practices regularly.
1. Data controller
Sauna Borealis
Isolehdonkatu 6, 98120 Kemijärvi
+358407683410
3511650-5
2. Person responsible for register matters and/or contact person
Mervi Lukkarinen
Sauna Borealis
+358407683410
3. Name of the register
Sauna Borealis Ltd's online store customer register
4. Legal basis and purpose of processing personal data / purpose of use of the register
The legal basis for the processing of personal data in accordance with the EU General Data Protection Regulation is the agreement that is created when a customer orders products and/or services from Company Ltd's online store. The purpose of the register is to enable online commerce through Company Ltd's online store, such as the transmission of order information, billing information, payment confirmation information, or processing information between Company Ltd and the customer. In addition, the register is used to enable customer service contacts, maintain customer relationships, and send electronic marketing communications when the customer has given their consent.
Company Ltd does not in any way store orders placed for other merchants' products or related information in its customer register.
The information is not used for automated decision-making. The information may be used for profiling.
5. Data content of the register
• First and last name
• Address
• Postal code
• Country
• Phone number
• Email address
• Personal identification number (private billing customer)
• Order source page
The following information is also registered for companies:
• Company name
• Business ID
• E-invoice address
• Intermediary ID
• Reference
• Brand
In addition, the process provides the customer with the opportunity to freely provide other information they deem relevant in the additional information field.
Data retention period
The data will be retained for as long as the user and Company Ltd have a valid mutual agreement and/or consent.
The data may be stored for longer if necessary to fulfill obligations imposed by applicable legislation, such as accounting and consumer trade responsibilities, and to demonstrate their proper implementation.
6. Regular sources of information
Information is collected using electronic forms on the Johku online service. Customers enter the information themselves when placing orders on Yritys Oy's Johku online store.
7. Regular disclosure of data and transfer of data outside the EU or the European Economic Area
Data is not disclosed separately and remains solely with the controller. Data may be technically processed outside the EU or the European Economic Area.
8. Principles of register protection
The register is processed with care and the data processed using information systems is protected appropriately. When register data is stored on Internet servers, the physical and digital security of the equipment is ensured in an appropriate manner. The controller ensures that stored data, server access rights, and other information critical to the security of personal data are treated confidentially and only by employees whose job description includes such tasks.
Electronically stored data
The register is located on the Johku service, and Aptual Commerce Oy acts as the data processor. Only the controller and the technical maintenance staff of Aptual Commerce Oy have access to the complete register data.Laajemmin Johku-palvelun tietosuojaperiaatteista: johku.fi/fi/tietosuoja
Manual material
As a rule, we avoid printing out information from the register as manual material. If, in certain situations, manual material is printed out from the register, the material is stored in a locked space and only the controller has access to it.
9. Right of access and exercising the right of access
Every person in the register has the right to check their data stored in the register and correct any incorrect or incomplete data. This right is automated by the Johku system used by Yritys Oy in the following way:
Johku communicates with the user via the Oma Johku service regarding the processing of their personal data in connection with the merchant's confirmation messages. The messages contain a link to the Oma Johku service.
In Oma Johku, the user can check the data stored about themselves and make corrections if necessary. The service also has a feature that allows users to download their data in a structured format for transfer from one system to another. The Oma Johku service is available at any time at johku.com/customer.
Oma Johku also offers the option to terminate the Oma Johku agreement and delete data from Oma Johku. If the user stops using Oma Johku and terminates their agreement with Johku, all automatic functions related to the management of their own data will cease.
After the termination of the agreement, the user must manage their own data (verification, correction, right to be forgotten, restriction, right to transfer from one system to another) in writing directly with Company Ltd. Yritys Oy may, if necessary, ask the person making the request to prove their identity. Yritys Oy will respond to written requests within the time limit specified in the EU Data Protection Regulation (usually within one month).
The Oma Johku service is free of charge.
10. Other rights related to the processing of personal data
A person included in the register has the right to request the removal of personal data concerning them from the register ("right to be forgotten"). Data subjects also have other rights under the EU General Data Protection Regulation, such as the right to restrict the processing of personal data in certain situations.
However, it should be noted that the data stored in Company Ltd's customer register is always generated when a customer purchases products and/or services. In such cases, Company Ltd is also bound by the obligations set out in accounting and tax legislation regarding the storage of data.
Requests must be sent in writing to the controller. If necessary, the controller may ask the person making the request to prove their identity. The controller will respond to the customer within the time limit specified in the EU General Data Protection Regulation (usually within one month).
11. Cookies
This website uses cookies. The website sends a small file to your browser, which is stored on your computer's hard drive. Both (temporary) session cookies, which are closed when you close your Internet browser, and permanent cookies, which are stored on your computer's hard drive, are used. The purpose of cookies is to improve the user experience on the website. If you are a registered user, the cookie also manages your login and access to pages that are only intended for registered users. Cookies can be used to track and view the user's interests and thereby influence the usability of the service. Internet browsers generally accept cookies automatically. If necessary, you can disable cookies in your browser settings, but this will remove some functionality.
Advertising cookies can be used to help optimize the advertising experience for the user of the service. Some third-party providers, including Google, may also use cookies or web beacons (1-pixel image files) to improve the advertising experience.
The information collected by cookies and web beacons does not contain any personal information about the user. It cannot be used to link online activities to a specific person.
Created: 11/11/2025