Privacy Policy

1. Data Controller

Vastnicon Oy Business ID: 3414053-8 Hietastentie 6 A4, 33480 Ylöjärvi, Finland Email: niko.vastamaki@vastnicon.com

2. Personal Data Processed

We process the following personal data: name, email address, postal address, phone number, order and payment details, and website usage data (after cookie consent).

3. Purposes and Legal Bases for Processing

Order processing and delivery: legal basis is the performance of a contract (GDPR Art. 6(1)(b)). Accounting and legal obligations: legal basis is a legal obligation (GDPR Art. 6(1)(c)). Website analytics (Google Analytics GA4): legal basis is consent (GDPR Art. 6(1)(a)) — only activated after cookie acceptance.

4. Recipients of Personal Data

Personal data may be shared with: • Paytrail Oyj (Innopay Oy) — payment processing • Courier services — order delivery • Google LLC — website analytics (only after cookie consent) Data is not shared with any other third parties without your consent.

5. Transfers Outside the EU/EEA

Google Analytics GA4 may transfer data outside the European Economic Area to the United States. Google LLC complies with the EU–US Data Privacy Framework. Data transfer only occurs if you have accepted analytics cookies.

6. Data Retention

Order and invoicing data is retained for the period required by Finnish accounting law (6 years from the end of the financial year). Analytics data is retained according to Google Analytics default settings (14 months). Other personal data is deleted when there is no longer a legal basis for its processing.

7. Data Security

Vastnicon Oy applies technical and organizational measures to protect personal data. Website traffic is encrypted using TLS. Access to personal data is restricted to those who need it.

8. Your Rights

You have the following rights: • Right of access — right to know what data we hold about you • Right to rectification — right to have inaccurate data corrected • Right to erasure — right to request deletion of your data • Right to restriction — right to request restriction of processing • Right to data portability — right to receive your data in machine-readable format • Right to object — right to object to processing • Right to withdraw consent — you can withdraw your consent at any time Requests can be sent to: niko.vastamaki@vastnicon.com

9. Right to Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority if you believe that the processing of your personal data violates the GDPR. Office of the Data Protection Ombudsman (Finland) Ratapihantie 9, 00521 Helsinki tietosuoja.fi +358 29 566 6700

10. Cookies

The online store uses necessary cookies to ensure the website functions correctly. Analytics cookies (Google Analytics GA4) are only activated when you accept them in the cookie banner. You can change your cookie preferences at any time via the cookie banner on the website.

11. Automated Decision-Making

We do not carry out automated decision-making or profiling that would have legal or similarly significant effects on you.

12. Updates to This Privacy Policy

We reserve the right to update this privacy policy. Significant changes will be announced on the website. Last updated: May 2025.